Site Not Served Over HTTPS: What It Means and How to Fix It
Your BadgerScan report flagged that the site loads over plain HTTP, or has a certificate but does not force visitors onto HTTPS. That means logins, form entries and admin sessions can travel in cleartext and be read by anyone on the same network. This page walks you through installing a certificate, forcing the redirect, and locking it in so browsers never downgrade.
One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.
What this finding actually means
HTTPS is HTTP with encryption layered on top, using a TLS certificate to scramble the connection between a visitor's browser and your server. When a page loads over plain HTTP instead, everything sent back and forth (passwords, contact form details, session cookies for your admin area) moves as readable text that anyone sharing the network, such as public Wi-Fi or an internet provider, can see (Cloudflare, What is HTTPS?).
This finding fires in one of two ways. Either your site has no certificate at all and answers on http://, or it does have a certificate but still lets people reach the plain http:// version because there is no rule sending them to the secure one. From the outside view, BadgerScan simply requested your pages and saw an unencrypted response served, or an http:// URL that was never redirected.
In short, having a certificate is only half the job. HTTPS is not truly enforced until every http:// request is automatically sent to https://.
Why it is worth fixing
Encryption protects the moments that matter most: someone logging into your store, a customer submitting a form, or you signing into your own dashboard. Without it, those details can be quietly read in transit, and that is the kind of exposure worth closing calmly and promptly.
There is a visible cost too. Modern browsers label plain HTTP pages as 'Not secure' in the address bar, which erodes trust, and search engines favor secure sites. Fixing this improves both safety and how your business looks to visitors.
How to fix it, step by step
The goal is a certificate installed, every request forced to HTTPS with a permanent redirect, and a header that tells browsers to stay secure. Most hosts make the first part a one-click job, and certificates are free.
- Get a TLS certificate. Check your hosting control panel first, since most hosts offer a free certificate you can enable with one click. If yours does not, Let's Encrypt, Getting Started issues them at no cost.
- Confirm the secure version loads. Visit
https://yourdomain.comdirectly and check that the padlock appears with no certificate warnings before you force any redirects. - Redirect all HTTP to HTTPS with a
301(permanent) redirect at your web server or CDN. Many hosts and CDNs have a single 'Always Use HTTPS' or 'Force HTTPS' toggle that does this for you. - If you run WordPress, go to Settings then General and set both the
WordPress Address (URL)andSite Address (URL)to thehttps://version so the site stops linking to its own insecure pages. - Once HTTPS is enforced everywhere, add an HSTS response header so browsers refuse to downgrade, starting with a value like
Strict-Transport-Security: max-age=31536000; includeSubDomains.
One thing to check before you finish
Only add the HSTS header after HTTPS works flawlessly on every part of your site, including any subdomains you name in includeSubDomains. HSTS tells browsers to remember the rule, so if a section is still broken over HTTPS when you switch it on, visitors can be locked out until it is fixed and the remembered policy expires.
To verify, load a few key pages over http:// and confirm each one lands on https://, then check for 'mixed content' warnings caused by images or scripts still pointing at http://. You can re-run the free scan or use the security headers checker to confirm the redirect and HSTS header are both in place.
Check whether your site enforces HTTPS in under a minute
Run the free BadgerScan scan to see the outside view of your site, including whether HTTP redirects to HTTPS and whether an HSTS header is set. No login and nothing to install. Run the free scan and get a clear, plain-language report.
Run a free security scanFrequently asked questions
Is a free certificate as safe as a paid one?
Yes. A free certificate from your host or from Let's Encrypt provides the same encryption strength as a paid one. Paid certificates mainly add things like extended validation or warranties, not stronger security for a typical small-business site.
I already have a certificate, so why did BadgerScan still flag me?
Because having a certificate and enforcing HTTPS are different things. If people can still reach the http:// version of your pages, the site is not protected. You need a 301 redirect sending all HTTP traffic to HTTPS to clear this finding.
Will switching to HTTPS break my site?
It rarely breaks anything, but you may see 'mixed content' warnings if some images or scripts are still linked over http://. Update those links to https://, and in WordPress set both URLs under Settings then General to the secure address.
How do I confirm the fix worked?
Load your pages over http:// and check that they redirect to https://, then run the free scan again. BadgerScan will re-check from the outside view and confirm that HTTPS is now enforced and the HSTS header is present.
Sources
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.