Your website says not secure because it is missing a valid SSL certificate, the connection is not fully encrypted, or a certificate that used to work has expired. Chrome, Safari, and every modern browser check for this automatically, and any gap shows up as a warning right next to your web address, even on a simple five-page site. I build custom websites for service businesses, and this is one of the fastest, cheapest problems to fix once you know what is actually causing it.
I have been doing this for over 20 years, and the not secure warning is one of the most common panic calls I get. It looks alarming, sitting right in the address bar where every visitor sees it, but it is rarely the disaster it appears to be. Let me walk through what causes it and exactly what fixes it.
Why Does My Website Say Not Secure?
Three things cause this warning, in order of how often I actually see them:
- No SSL certificate installed at all. The site is running on plain HTTP instead of HTTPS, so nothing between the visitor and your server is encrypted.
- An expired certificate. SSL certificates have a renewal date, and if hosting is not set up to auto-renew, the certificate quietly lapses and the warning reappears even though the site worked fine yesterday.
- Mixed content. The page itself is secure, but it is still pulling in an image, a script, or an embedded widget from an old unencrypted address, so the browser flags the whole page as only partially secure.
All three are fixable, usually without touching a single line of your actual content. None of them mean your business did anything wrong, they mean whoever set up your hosting either skipped this step or did not build in automatic renewal.
What Exactly Triggers the Not Secure Warning in Chrome?
Chrome made a deliberate change here. Starting in 2018, Chrome began marking every plain HTTP page as "Not Secure," rather than only flagging pages that collect sensitive information like passwords or credit cards. That single change is why so many small business owners who never noticed a problem before suddenly saw a warning on a site that had not changed at all. The site did not get worse, the browser's standard got stricter.
The warning itself is Chrome doing exactly what it is supposed to do: telling a visitor that any data passed between their browser and your server, even something as basic as filling out a contact form, is not encrypted. It is not a judgment on your business, it is a technical fact about how the page is served.
Does a Not Secure Website Hurt Your Google Rankings?
Yes, and this has been true for over a decade. Google confirmed HTTPS as a ranking signal back in 2014, and it has only mattered more since. An unencrypted site is competing against every HTTPS competitor with one hand tied behind its back, on a factor that costs nothing to fix.
The ranking hit is only half the problem. The other half happens before Google ever gets involved: a visitor lands on your page, sees "Not Secure" sitting next to your domain, and leaves before reading a word of your content. You paid for that click, through SEO effort or an ad, and the warning talks them out of trusting you in the time it takes to glance at the address bar.
How Do You Fix a Not Secure Website?
The fix depends on which of the three causes above applies, but none of them are expensive or complicated once you know what you are looking for.
| Approach | Typical cost | What it actually fixes |
|---|---|---|
| Free certificate (Let's Encrypt) through your host | $0 | Basic encryption, but usually requires manual renewal every 90 days unless auto-renew is configured |
| Purchased certificate from a certificate authority | $10 to $200/year | Same encryption, sometimes with extended validation branding, rarely necessary for a small service business |
| Hosting included in an all-inclusive plan | Included | Certificate issued and auto-renewed as part of the hosting, so it never lapses without you noticing |
For most small businesses, the purchased certificate tier is unnecessary spending. A properly configured free certificate does the same job for a five-page service business site. The real risk is not the certificate itself, it is a renewal that nobody is watching. That is why every site I build, whether on my $150-a-month plan or the $3,500 one-time option, has hosting and certificate renewal handled as part of the build instead of something the client has to track on a calendar.
Mixed content is a different fix. It means going through the page's images, embedded videos, and third-party scripts and updating any that still point to an old http:// address instead of https://. On a static, custom-coded site this is usually a quick find-and-replace. On an older WordPress site with plugins pulling in resources from all over, it can take longer to track down every source.
Does Not Secure Mean Your Website Got Hacked?
Almost never. A not secure warning and a hacked website look completely different to a browser. A hacked site usually triggers a Google Safe Browsing warning with red, full-page text like "Deceptive site ahead," or shows unfamiliar content, redirects, or pop-ups that nobody on your team added. The not secure warning, on its own, is just a missing or expired certificate. It is worth checking your site for those hacked-site symptoms anyway, but do not assume the worst from an address bar warning alone.
One reason I build static, custom-coded sites instead of stacking plugins on a CMS is that there is simply less surface area for either problem. Fewer moving parts means fewer things that can silently break, whether that is a lapsed certificate or an outdated plugin with a known vulnerability. I cover more of this in what website maintenance actually costs and covers, including why security patching is part of a real maintenance plan and not an afterthought.
What Should You Do Next?
- Check your site right now. Type your web address into a browser and look at what shows up next to it. A padlock means you are fine. Any warning icon or "Not Secure" text means one of the three causes above applies.
- Ask your current host or designer who owns certificate renewal. If nobody can give you a straight answer, that is exactly how sites end up with an expired certificate and no one watching for it.
- Run a full site check. My free speed test also flags security and best-practices issues alongside load time, so you can see the whole picture in one pass.
- See what a properly maintained site looks like. Browse real client sites in my portfolio to see examples where hosting, SSL, and speed are all handled as one package instead of three separate headaches.
- Get a free mockup. If you are dealing with a not secure warning on an old site and considering a rebuild anyway, I will put together a free homepage mockup with no cost and no obligation.
A not secure warning looks like a five-alarm problem the first time you notice it, but it is almost always a quick, cheap fix, not a sign your business or your website did anything wrong. The bigger mistake is leaving it up for weeks while it quietly costs you rankings and visitors who bail before they ever see what you actually offer.
