|
Read this before installing anything: the certificate is already ours and already there. Domains hosted with us get a certificate issued and renewed automatically, with no request, no cost and no plugin. You do not need any software to have https: what an SSL certificate is and why it matters.
|
So what is the plugin for? Something else, and the difference is worth understanding. The certificate is the lock, and that is already fitted. What is missing, on older sites, is WordPress no longer asking for its own images, stylesheets and links over http://. That is what keeps the padlock away, even with a valid certificate.
First, work out where you stand
| 1 |
Open the site typing https:// in front of the address. If the browser does not complain about the certificate, it is there and valid.
|
|
| 3 |
If it does not complain about the certificate but the padlock still is not closed, it is mixed content: the page came over https and something inside it came over http. This is where the plugin helps.
|
|
Three routes, and which one is yours
| Your situation |
What to do |
| A new site, built in https already |
Install nothing. Check in Settings › General that both addresses start with https:// and you are done. |
| An old site with hundreds of http addresses saved in the database |
This is the plugin’s case. It rewrites the content as the page is served, without touching the database, and settles in an afternoon what would otherwise take a week. |
| You want the permanent fix |
Swap the addresses inside the database itself, in one go, plus a redirect in .htaccess: redirecting HTTP to HTTPS with .htaccess. After that you can uninstall the plugin. |
Installing and setting it up
| 2 |
In the dashboard, Plugins › Add New, search for Really Simple SSL and install.
|
|
| 3 |
Activate. It detects the certificate by itself and shows a button to switch https on. Press it.
|
|
| 4 |
You will be signed out, because the site address changed. That is normal. Sign back in, now on the https:// address.
|
|
| 5 |
Walk through the site: home page, an inner page, a form, and the shop if you have one. Check the padlock on each.
|
|
| 6 |
In the settings, choose the .htaccess redirect rather than the code-based one. It is faster and does not depend on WordPress starting.
|
|
|
If the site becomes unreachable after activating. That happens when the certificate was not actually good. The way out is the usual one: in cPanel’s File Manager, rename the plugin folder in wp-content/plugins, adding -off. The site goes back to http. Then sort out the certificate.
|
The Cloudflare trap
If the domain goes through Cloudflare and the SSL mode there is Flexible, Cloudflare talks to our server over http. Ours redirects to https. Cloudflare asks again over http. The result is an infinite loop and the site stops opening.
The cure is to set the mode to Full or Full (strict), which is the correct one given we have a valid certificate. More on this in Cloudflare: when it helps and the cache that fools you.
Once it is working
| What to do |
Why |
| Clear the cache |
Pages stored as http keep being served that way. Clear the plugin cache and, if you use Cloudflare, theirs too: installing and tuning a page cache. |
| Update whatever points at the site |
Analytics tools, sitemaps submitted to search engines, and links in campaigns. |
| Check the forms and the payments |
They are the first to break with mixed content, and the most expensive if nobody notices. |
| Plan the permanent fix |
The plugin rewrites on every visit, which costs something on every page. Once the content is swapped in the database, it can step aside. |
|
Padlock missing and you cannot see why? Send us the page address.
Open a request
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $9.99/mo See plans |