SSL Certificates and HTTPS: What Can Go Wrong
By CodexierPublished 6 min read
Every business website should load over HTTPS, and most do. The trouble starts when the certificate behind the padlock expires on a Saturday, when a new plugin loads an image over plain HTTP, or when a redirect rule sends visitors in circles. Each of these produces a browser warning that costs you visitors and, for a webshop, orders. This guide explains what the certificate does, the difference between free and paid ones, and the four failures we see most often, with the fix for each.
What a certificate does
A certificate is a small file issued by a certificate authority that binds your domain name to a cryptographic key. When a browser connects, the server presents the certificate, the browser checks that a trusted authority signed it, that it matches the domain and that it has not expired, and then sets up an encrypted connection. That is the S in HTTPS. Without it, anyone on the same network can read or alter what passes between the visitor and your site, and browsers say so with a warning. Google also treats HTTPS as a baseline for ranking, and payment providers require it.
Free vs paid certificates
Let's Encrypt and similar authorities issue free certificates that are valid for ninety days and renew automatically through the hosting provider or a small program on the server. Paid certificates typically last a year and come in validation levels: domain validated, which checks only that you control the domain, and organisation or extended validation, which checks the company as well. Browsers no longer display any visible difference, so for a normal company site or webshop a free, automatically renewed certificate is the right choice. Paid certificates make sense when your platform cannot automate renewal, when you need a wildcard your host does not offer free, or when a corporate policy requires organisation validation.
| Aspect | Free (Let's Encrypt) | Paid |
|---|---|---|
| Encryption strength | Same | Same |
| Validity | Ninety days, renews automatically | Usually one year, manual or semi-automatic renewal |
| Validation | Domain only | Domain, organisation or extended |
| Visible difference in browsers | None | None for modern browsers |
| Best for | Almost every business site | Legacy platforms, corporate policy, some wildcard needs |
Expired certificates and renewals
An expired certificate is the most common cause of a sudden full-page warning, and it nearly always happens because renewal depended on a person or on a process nobody monitored. Free certificates renew themselves, but the renewal can silently fail when DNS changes, when the site moves host, or when a firewall blocks the validation request. Paid certificates expire on a date someone once wrote in a calendar that no longer exists. The fix is the same in both cases: make renewal automatic, and set up an external monitor that checks the certificate daily and emails two people when fewer than fourteen days remain. That way a failed renewal is a ticket, not an outage.
- Confirm with your host how renewal happens and what breaks it.
- Add an uptime or certificate monitor that checks expiry from outside the server.
- Send alerts to a shared address, not to the developer who left last year.
- After any host or DNS change, check that the next renewal actually succeeds.
Mixed content warnings
Mixed content is when a page loaded over HTTPS includes something over plain HTTP: an image with a hard-coded old address, a font, a script or an embedded map. Browsers block the insecure scripts outright and mark the page as not fully secure, which turns the padlock into a warning. It appears most often after a site migration, when old content still references the http address, or after a plugin or theme adds a resource from an outdated source. The browser's developer console lists every mixed resource by address, so the diagnosis takes minutes; the fix is a search-and-replace in the database for old addresses and updating or removing the offending plugin.
Redirects and HSTS
Having a certificate is not enough; every plain http address must redirect to https, and the www and bare-domain versions must agree on one canonical form, or visitors and Google see two sites. Redirect loops happen when the CMS, the server and a proxy or CDN each try to redirect and disagree; the symptom is a browser error about too many redirects. HSTS is a header that tells browsers to use HTTPS for your domain for a set period, which closes the window where a first visit could be intercepted. Turn it on only after redirects work everywhere, because it cannot be quickly undone. Certificates, redirects and headers are a standard part of a performance and security optimisation; the price is on our pricing page.
When you do not need this: if your site runs on a managed platform such as Shopify, Squarespace or a hosted CMS, certificates and redirects are handled for you, and the only thing to check is that your custom domain shows a padlock on both www and bare versions. If your host provides automatic certificates with monitoring and your site was built HTTPS-first, there is nothing to fix. If you have seen a warning once and are not sure why, book a short call and we will check the certificate chain, redirects and headers with you.
Frequently asked questions
Why does my site show 'not secure' even though I bought a certificate?
Usually because the certificate is installed but the site still serves pages over http, includes mixed content, or the certificate covers only the bare domain while visitors use www. The browser's padlock menu or developer console shows which one.
Does a certificate protect my website from being hacked?
No. It protects data in transit between visitor and server. Outdated software, weak passwords and vulnerable plugins are separate risks that HTTPS does nothing about, which is why security headers and updates matter alongside it.
Do I need a wildcard certificate?
Only if you run many subdomains that change often, such as customer portals on separate subdomains. For a site with www and perhaps a shop subdomain, separate free certificates or a multi-domain certificate is simpler.
Seen a security warning on your site and not sure why?
Fifteen minutes with a developer: give us your domain and we check the certificate, renewal setup, redirects and mixed content while you watch, then tell you what to fix and whether it needs a developer.
Book a free 15-minute call