For most WordPress sites, the easiest way to get free HTTPS is to enable your host’s built-in Let’s Encrypt option. The host’s ACME client requests the certificate, installs it, and renews it. If your host does not offer managed SSL, you can use Certbot on your own Apache or Nginx server, or use DNS-01 validation when port 80 is unavailable or you need a wildcard certificate.
What a free SSL certificate means
Let’s Encrypt is a free certificate authority that issues TLS certificates through the automated ACME protocol. Certbot is free, open-source software that can request Let’s Encrypt certificates and, with the appropriate plugin, configure Apache or Nginx.
The certificate itself costs nothing, but you still pay for any domain registration, hosting, DNS service, administration, premium support, or managed certificate product you choose. A free certificate also needs successful renewal; an expired certificate can make a working WordPress site appear offline or unsafe.
WordPress is compatible with HTTPS once a TLS certificate is installed and available to the web server. WordPress.org’s current requirements baseline lists HTTPS as required for every installation (page accessed September 30, 2026).
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Choose the right installation path
| Option | Access needed | Validation and renewal | Best for |
|---|---|---|---|
| Hosting-managed HTTPS | Hosting dashboard or support ticket | Usually automatic ACME validation and renewal | Most site owners who want the least maintenance |
| Certbot on Apache or Nginx | SSH plus administrative server access | HTTP, DNS, or standalone challenge; you must verify the renewal job | Self-managed virtual servers and dedicated servers |
| DNS-01 validation | Ability to edit authoritative DNS | TXT record under _acme-challenge; supports automated DNS plugins or manual hooks |
Blocked port 80, off-server issuance, and wildcard certificates |
Path A: Enable HTTPS in managed WordPress hosting
- Point the domain to the WordPress host. Confirm that the apex domain and any hostname you will use, such as
www, resolve to the correct server. - Find the SSL control. In the host dashboard, look for labels such as SSL/TLS, HTTPS, Let’s Encrypt, or Security certificate. Some hosts enable it automatically after DNS is correct.
- Request or enable the certificate. Select every hostname that serves your site. If the option is missing, ask support whether the plan includes Let’s Encrypt issuance and automatic renewal. If it does not, use a host that provides full HTTPS support.
- Wait for issuance and installation. The host’s ACME client performs domain validation and places the certificate on the web server. Do not change WordPress URLs until the HTTPS virtual host responds correctly.
- Turn on the HTTP-to-HTTPS redirect. Use the host’s redirect control when available. This sends visitors from
http://tohttps://and prevents two address versions from being indexed or cached separately. - Set WordPress URLs to HTTPS. In the dashboard, open Settings > General and change both WordPress Address (URL) and Site Address (URL) to the HTTPS versions. Save only after the secure site works.
- Check renewal. Confirm that the panel shows an active renewal schedule. For a business-critical site, also use an independent certificate-expiry monitor and record who owns renewal failures.
Path B: Use Certbot on Apache or Nginx
Use this route only when you control the server and its web configuration. You need administrative access, a functioning Apache or Nginx installation, DNS pointing to that server, and firewall rules that permit the chosen validation method.
Request and install a certificate
Install Certbot using the method recommended for your server’s operating system. Then request certificates for the exact names that serve traffic, commonly the apex domain and www. Certbot can obtain and install a certificate in one operation, or you can use certonly when you intend to edit the virtual host yourself.
Rank #2
A typical web-server flow is conceptually:
certbot --apache -d example.com -d www.example.com
certbot --nginx -d example.com -d www.example.com
Use the plugin matching your server, and replace the example names with your domains. The command may alter the virtual host and offer to add an HTTP-to-HTTPS redirect; review the proposed changes before accepting them.
When HTTP validation is appropriate
Webroot, Apache, Nginx, and standalone HTTP-01 flows generally require Let’s Encrypt to reach your site through public TCP port 80. Ensure DNS, firewall rules, load balancers, and proxy settings allow that connection. A server that only accepts HTTPS on port 443 can fail HTTP-01 validation.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
Test and schedule renewal
- Open the HTTPS site and verify that the expected virtual host and certificate are returned.
- Reload Apache or Nginx after configuration changes.
- Run Certbot’s renewal simulation, commonly
certbot renew --dry-run, and inspect the system timer or scheduled job that will run renewal. - Check that the web server reloads after a successful renewal so it begins using the new certificate.
Manual HTTP or DNS challenges do not renew by themselves unless you add deploy or authentication hooks. Choose an auto-renewing plugin or deliberately repeat the challenge before expiry.
Use DNS-01 when port 80 is blocked or you need a wildcard
DNS-01 proves control by requiring a TXT record at a name such as _acme-challenge.example.com. Certbot provides the value; create it at the authoritative DNS provider, wait for propagation, and let validation complete. This method does not require Let’s Encrypt to connect to the web server on port 80.
Rank #4
DNS-01 is also the validation method that supports wildcard certificates, such as *.example.com. A DNS plugin can create and remove TXT records automatically, but it requires narrowly scoped API credentials. If you use a manual DNS challenge, document the procedure and add hooks or repeat it for every renewal.
Finish the WordPress HTTPS configuration
Force secure administrator sessions when appropriate
After the secure virtual host is working, you can add define('FORCE_SSL_ADMIN', true); to wp-config.php. WordPress advises configuring SSL on the server first; enabling this constant before HTTPS works can lock you out of the dashboard.
Best Value
Fix mixed content
Open the browser developer console and identify images, scripts, stylesheets, fonts, API calls, canonical tags, or embedded frames still loaded over http://. Update the responsible WordPress setting, theme, plugin, or database URL to HTTPS. Do not blindly replace every database value without a backup, because serialized plugin data can be corrupted by unsafe search-and-replace operations.
Test the whole site
- Log in and log out of WordPress.
- Submit contact, search, membership, and checkout forms.
- Check redirects for both the apex and
wwwhostnames. - Verify caching, CDN, reverse-proxy, and image-optimization layers use HTTPS at every hop.
- Confirm that the certificate’s subject or SAN list covers every hostname visitors actually use.
- Inspect payment and other sensitive pages for secure requests and correct return URLs.
Common problems and the practical fix
The host has no SSL button
Ask support whether Let’s Encrypt is available on your plan and whether renewal is automatic. If the answer is no, either manage the server with Certbot or move the site to hosting that includes complete HTTPS support.
HTTP-01 validation fails
Check that the domain resolves to the requesting server, port 80 is publicly reachable, no firewall or proxy intercepts the challenge path, and another web server is not answering for the hostname. Use DNS-01 when the architecture cannot expose port 80.
The certificate is valid but the browser still warns
Confirm that the certificate covers the exact hostname in the address bar, that the server sends the correct certificate chain, and that the page is not loading active resources over HTTP. Clear cached redirects only after correcting the server configuration.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRenewal failed
Read the ACME client log, then check DNS, firewall access, challenge records, rate-limit messages, and the renewal timer. Restore the original validation path or add the required DNS or deploy hook. Renew before the current certificate expires and verify the web server reload afterward.
Quick Recap
How to keep a free certificate reliable
- Keep DNS records, server access, and ACME credentials documented.
- Limit DNS API keys to the required zone and permissions.
- Monitor certificate expiry independently of the host dashboard.
- Test renewal after moving hosts, changing proxies, or modifying firewall rules.
- Keep WordPress, themes, plugins, and the operating system updated so HTTPS configuration is not undermined by vulnerable software.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




