Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
When WordPress says it “could not establish a secure connection to WordPress.org,” start with Tools > Site Health and your hosting error log. The warning normally means the server cannot reach api.wordpress.org—the endpoint WordPress uses for version checks and core, theme and plugin updates—not that your public website certificate is necessarily broken. Record the exact cURL or HTTP error before changing anything.
First, identify which secure connection is failing
There are two different problems that are often described with the same words:
| Symptom | Connection path | What to investigate |
|---|---|---|
| Site Health reports “Could not reach WordPress.org” | Your web server to api.wordpress.org |
DNS resolution, outbound firewall rules, host policy, PHP/cURL and WordPress HTTP configuration |
| A browser warns about HTTPS, a certificate, or redirects on your site | Visitor or administrator browser to your web server or reverse proxy | Certificate installation, TLS settings, redirects and proxy headers |
WordPress defines the Site Health finding as an inability to reach WordPress.org at api.wordpress.org. See the Site Health screen documentation. Public HTTPS is a separate server configuration described in WordPress’s HTTPS administration guide.
Capture the exact error before applying a fix
- Open Tools > Site Health > Status.
- Expand the WordPress.org connectivity result and copy the complete message, destination, cURL or HTTP code, and any linked REST API or loopback failures.
- Open the Info tab and note the PHP version, cURL version and server details. This screen reports configuration; it does not change server settings.
- Check the hosting control panel’s PHP and web-server error logs for the same timestamp. Include the server’s time zone when recording it.
The error code is diagnostic evidence. A generic “secure connection” label is not enough to select a remedy.
#1 Best Overall
Match the error to the right troubleshooting branch
DNS or getaddrinfo failure
If the message explicitly reports name resolution—for example, cURL error 6 or a getaddrinfo failure—ask the host to test DNS resolution from the web server for the destination shown. One WordPress.org support case reported cURL error 6 for both the WordPress.org check and a REST request; a forum reply treated that particular pattern as a host-side DNS problem. It is a case example, not a rule for every error 6 report.
Timeout, connection refusal, or outbound firewall block
For timeouts, refused connections or messages saying access is blocked, have the host or network administrator inspect outbound rules for the exact hostname and port. A separate support thread describes firewall or access rules causing a plugins-page request to fail, but that anecdote does not establish a universal cause.
PHP, cURL, certificate trust, or other server configuration
Use the Site Health Info details and logs to show the host what needs changing. Missing or misconfigured PHP/cURL components, trust stores, TLS libraries and server policies are commonly host-managed. WordPress notes that some server-level settings require provider intervention; do not guess at values from the dashboard warning.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Requests blocked by WordPress configuration
Check whether WP_HTTP_BLOCK_EXTERNAL is enabled in wp-config.php. Site Health documents that this setting can block HTTP requests when allowed hosts are not configured. Change it only when you understand the site’s intended security policy and have a backup or deployment path.
Browser certificate or reverse-proxy symptoms
If the browser—not Site Health—shows an expired, mismatched or untrusted certificate, inspect the certificate served by the web server or proxy, TLS configuration and redirect chain. WordPress’s HTTPS documentation makes clear that SSL/TLS must already be configured before using settings such as FORCE_SSL_ADMIN.
With a proxy that terminates TLS, WordPress may need a correctly supplied HTTP_X_FORWARDED_PROTO value so it knows the original request was HTTPS. Incorrect handling can produce redirect loops. Fix the proxy and web-server configuration rather than treating an outbound WordPress.org warning as proof that your public certificate needs replacement.
Rank #4
Plugin or theme involvement
Do not assume a plugin or theme caused a WordPress.org connectivity warning. If logs show that a recent extension change is involved, isolate it carefully—preferably on staging or during a maintenance window. WordPress’s common-errors guide recommends deactivating plugins, reactivating them one at a time, and testing a default theme for the classes of failures covered there.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What to send your hosting provider
- The complete Site Health message and the affected hostname.
- The cURL or HTTP code and any REST API or loopback result.
- Date, exact time and time zone of the failure.
- A sanitized, relevant excerpt from the PHP or web-server log.
- PHP and cURL versions shown under Tools > Site Health > Info.
Ask support to test DNS resolution and outbound network access from the web server, then review the applicable PHP/cURL/TLS and proxy settings. Remove passwords, authentication headers, API keys and other secrets before sharing logs.
Best Value
Retest safely after a targeted change
- Have the host or administrator make one documented change that matches the observed error.
- Run Tools > Site Health > Status again.
- Repeat the affected update, plugin page or REST request.
- Confirm that HTTPS access in a browser still presents the expected certificate and redirect behavior.
Do not disable firewalls broadly, turn off TLS verification, or replace a certificate solely because the dashboard uses the word “secure.” The correct fix depends on whether the failing path is server-to-WordPress.org or browser-to-your site.
Useful official references
- WordPress Site Health screen
- WordPress HTTPS – Advanced Administration Handbook
- WordPress common errors
- WordPress requirements
The Bottom Line
Capture the exact Site Health cURL/HTTP error, determine whether the failing path is outbound access to api.wordpress.org or inbound HTTPS to your own site, and give the evidence to the person who controls DNS, firewall, PHP/cURL, web-server or proxy settings. There is no single certificate or plugin fix for the generic warning.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

