Saurabh Web Solutions Subscribe
WordPress Fixes

WordPress Still "Not Secure" After SSL? Fix Mixed Content and Too Many Redirects

1 free file — jump to downloads
WordPress Still "Not Secure" After SSL? Fix Mixed Content and Too Many Redirects - cover image
On this page
  1. Part 1: The padlock is missing
  2. Step 1: Check the certificate is actually active
  3. Step 2: Set WordPress to use https://
  4. Step 3: Fix mixed content
  5. Step 4: Redirect all traffic to HTTPS
  6. Part 2: ERR_TOO_MANY_REDIRECTS
  7. Step 1: Clear cookies and try a private window
  8. Step 2: Set the site address in wp-config.php
  9. Step 3: Remove duplicate redirect rules
  10. Step 4: Check redirect plugins and caching
  11. After the fix: tell Google
  12. Quick checklist
  13. Download the files

You installed an SSL certificate, but Chrome still shows "Not secure" or a broken padlock. Or worse, after switching on HTTPS the site now refuses to load with "This page isn't working: redirected you too many times" (ERR_TOO_MANY_REDIRECTS). Both problems are common after moving a WordPress site to HTTPS, and both have a short list of causes.

Part 1: The padlock is missing

Step 1: Check the certificate is actually active

In your hosting panel, open the SSL section (in Hostinger hPanel: Security > SSL) and confirm the certificate is installed and active for your domain, including the www version if you use it. Then visit https://yourdomain.com directly. If the browser shows a certificate error rather than "Not secure", the certificate is missing or still installing; wait a few minutes or ask your host.

Step 2: Set WordPress to use https://

  1. Go to Settings > General.
  2. Change both WordPress Address (URL) and Site Address (URL) from http:// to https://.
  3. Save. You will be logged out; log in again over https.

Step 3: Fix mixed content

Even with the right addresses, old posts and theme settings often still contain http:// links to images and files. The browser sees insecure files on a secure page and drops the padlock.

Find it: open the page, right-click and choose Inspect > Console. Warnings starting with "Mixed Content" list each insecure file.

Fix it the quick way: the free SWS Site Fixer plugin (download below) has a Speed & SSL > Fix mixed content switch that rewrites old http:// links to your own site as https:// on the fly.

Fix it permanently: use a reputable search-and-replace tool to change http://yourdomain.com to https://yourdomain.com in the database. Always take a full backup first, and never edit serialized data by hand.

Also check these places for hard-coded http links:

  • Theme customizer and page builder global settings (logos, background images).
  • Custom CSS with url(http://...).
  • Widgets and menus with full URLs.
  • Third-party embeds or scripts that still use http (replace them with https versions).

Step 4: Redirect all traffic to HTTPS

Visitors and Google may still reach the old http address. Most hosts have a "Force HTTPS" switch; turn it on. Otherwise add a redirect rule in .htaccess (Apache and LiteSpeed hosts), above the WordPress block:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Use only one method. Two different force-HTTPS mechanisms are a classic cause of redirect loops.

Part 2: ERR_TOO_MANY_REDIRECTS

A redirect loop means two rules send the browser back and forth forever, for example the server forcing HTTPS while WordPress insists on HTTP, or www and non-www rules fighting each other.

Step 1: Clear cookies and try a private window

Old redirect cookies can keep the loop going in your browser even after it is fixed. Clear cookies for your site, or test in a private window.

Step 2: Set the site address in wp-config.php

If you cannot reach the dashboard, force the correct addresses in wp-config.php (back it up first), above "That's all, stop editing!":

define( 'WP_HOME', 'https://yourdomain.com' );
define( 'WP_SITEURL', 'https://yourdomain.com' );

Use exactly the version you want visitors to see: with or without www, and with https.

Step 3: Remove duplicate redirect rules

  • Open .htaccess and look for more than one HTTPS or www rule; keep a single one.
  • Disable any "really simple SSL" style plugin temporarily if your host already forces HTTPS.
  • If you use Cloudflare or another CDN, set its SSL mode to Full or Full (strict), not Flexible. Flexible SSL combined with a server HTTPS redirect is one of the most common loop causes.

Step 4: Check redirect plugins and caching

A redirect plugin with a rule pointing a URL to itself, or a cached redirect, can also loop. Deactivate redirect and caching plugins one at a time (via File Manager if needed) and clear all caches.

After the fix: tell Google

  • Make sure every http URL redirects with a 301 to its https version.
  • In Google Search Console, use a Domain property, or add the https URL-prefix property.
  • Resubmit your sitemap and check the Pages report for redirect errors. See getting your WordPress site indexed.

Quick checklist

  • Certificate active for both www and non-www.
  • Both WordPress addresses start with https://.
  • No mixed content warnings in the browser console.
  • Exactly one force-HTTPS mechanism.
  • CDN SSL mode set to Full, not Flexible.

Download the free plugin below for the one-click mixed content fix. Moving to a new host at the same time? Our domain, hosting, DNS and SSL guide explains how the pieces connect.

Download the files

Free to use in your own and client projects · no sign-up · tested before upload. Always try files on a staging site first and keep a backup.

Download not working? Tell me and I'll fix it.

Frequently asked questions

Why does my site say Not secure even though SSL is installed?

Usually because WordPress is still set to http:// addresses, or the page loads images, scripts or fonts over http://. Browsers treat any insecure resource on a secure page as mixed content and remove or downgrade the padlock.

What is mixed content?

A page loaded over HTTPS that includes some files, such as images or scripts, over plain HTTP. Browsers block or warn about these files because they could be tampered with.

What causes ERR_TOO_MANY_REDIRECTS in WordPress?

Two settings sending visitors back and forth, for example a force-HTTPS rule on the server combined with WordPress set to http://, or conflicting redirect rules in .htaccess, a CDN and a plugin.

How do I fix WordPress if I cannot log in because of the redirect loop?

Set the correct addresses in wp-config.php with the WP_HOME and WP_SITEURL constants, clear your browser cookies for the site, and remove duplicate redirect rules. Then log in and save the correct addresses in Settings > General.

Is SSL free?

For most sites, yes. Most hosts include free SSL certificates that renew automatically, and you only need to switch them on in the hosting panel.