How to Install an SSL Certificate on WordPress (Free HTTPS Setup)

On this page
An SSL certificate encrypts the connection between your visitors and your website, turning http:// into https:// and showing the padlock in the browser. Without it, browsers label your site "Not secure", which scares visitors away from forms and checkouts. This guide shows how to install a free SSL certificate on WordPress and switch over cleanly.
Step 1: Activate the free certificate at your host
- Hostinger: hPanel > Security > SSL, then install or check the free certificate for your domain.
- cPanel hosts: look for SSL/TLS Status or "Let's Encrypt" and run AutoSSL for your domain.
- Managed WordPress hosts usually enable SSL automatically.
Make sure the certificate covers both yourdomain.com and www.yourdomain.com. Then visit https://yourdomain.com; if it loads without a certificate warning, SSL is working.
Step 2: Switch WordPress to HTTPS
- Take a backup first.
- Go to Settings > General.
- Change both WordPress Address (URL) and Site Address (URL) to start with
https://. - Save and log in again.
Step 3: Redirect all HTTP traffic to HTTPS
Turn on your host's "Force HTTPS" option, or add one redirect rule to .htaccess on Apache/LiteSpeed hosts, above the WordPress block:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Use only one method. Two different force-HTTPS rules are a classic cause of redirect loops.
Step 4: Fix mixed content
Old posts and theme settings may still load images over http://, which removes the padlock. Open the browser console (right-click > Inspect > Console) to see "Mixed Content" warnings, then update those links. Our guide to fixing "Not secure" and redirect loops covers search-and-replace and a one-click fix.
Step 5: Tell Google
- In Google Search Console, use a Domain property (covers http and https) or add the https URL-prefix property.
- Submit your sitemap again.
- Update your site address in Google Analytics and anywhere else you link to it.
See how to set up Google Search Console for WordPress.
Troubleshooting
- "Your connection is not private": the certificate is missing, expired or does not cover www. Re-run the installation at your host.
- "This site can't provide a secure connection": see our ERR_SSL_PROTOCOL_ERROR guide.
- Too many redirects: remove duplicate HTTPS rules and check CDN SSL settings.
Frequently asked questions
Do I need to pay for an SSL certificate?
Usually not. Most hosts include free SSL certificates (often from Let's Encrypt) that renew automatically. Paid certificates mainly add organization validation, which most small sites do not need.
Does SSL help SEO?
HTTPS is a light Google ranking signal and, more importantly, browsers mark non-HTTPS sites as Not secure, which drives visitors away.
How long does SSL installation take?
Activating a free certificate in your hosting panel typically takes a few minutes, though it can take longer right after you point a new domain to your host.
Will I lose Google rankings when moving to HTTPS?
Not if you redirect every HTTP URL to its HTTPS version with a 301 redirect and update your Search Console property and sitemap.


