To add SSL to WordPress, first enable a valid SSL/TLS certificate for your domain through your hosting provider or WordPress.com. Then change WordPress’s WordPress Address and Site Address to https://, remove mixed-content references, configure HTTP-to-HTTPS redirects, and verify renewal. A plugin or WordPress setting cannot install a certificate on the web server by itself.
First identify your WordPress setup
The correct procedure depends on where HTTPS is terminated and who manages your domain.
| Setup | Where the certificate is enabled | Who controls the process |
|---|---|---|
| Self-hosted WordPress | Your web host, server, control panel, proxy or CDN | You and your hosting/server administrator |
| WordPress.com | WordPress.com’s domain and hosting infrastructure | WordPress.com, subject to your DNS configuration |
Confirm the exact hostname visitors use, such as example.com or www.example.com. The certificate and redirect configuration must cover that hostname. If you do not know whether a proxy, CDN or separate server handles HTTPS, ask your host before changing WordPress settings.
Self-hosted WordPress: add SSL step by step
1. Provision a certificate at the host
Follow your host’s instructions to provision or install a certificate for the domain. WordPress is compatible with HTTPS when an SSL/TLS certificate is installed and available for the web server (WordPress HTTPS administration guidance).
#1 Best Overall
A common automated option is an ACME client using Let’s Encrypt. The client proves that you control the domain, for example with a DNS record or an HTTP resource, and then requests and manages the certificate (Let’s Encrypt: How It Works). Your host may perform these steps for you.
Do not change the WordPress URLs yet. First make sure the HTTPS version of the domain loads successfully with a valid certificate.
2. Test HTTPS before touching WordPress
- Open
https://your-domain.examplein a private browser window. - Check that the certificate is valid for the hostname you entered, is not expired, and does not produce a browser certificate warning.
- Test both the public site and
https://your-domain.example/wp-admin/. - In WordPress, open Tools > Site Health and review the HTTPS/environment status.
WordPress 5.7 introduced HTTPS detection and a Site Health migration action that can switch both site URLs when the server supports HTTPS (WordPress 5.7 HTTPS migration details).
3. Change both WordPress URLs
When HTTPS works, go to Settings > General and change both fields below from http:// to https://:
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #2
- WordPress Address (URL) — where the WordPress core files are located.
- Site Address (URL) — the public address visitors use.
Save the changes, sign in again if WordPress logs you out, and test the front end and administration area. If Site Health offers its HTTPS switch, use that supported migration action instead of editing the fields manually.
Sites that define WP_HOME or WP_SITEURL in wp-config.php may not allow these values to be changed from the dashboard. In that case, update the configuration constants through your normal deployment or hosting process, using the exact HTTPS hostname.
4. Find and fix mixed content
A certificate can be valid while a page still displays a browser warning because images, scripts, stylesheets, fonts, embeds or form actions are requested over http://. Check the home page, key landing pages, forms, checkout pages and the admin area.
- Open the browser developer tools and inspect the Console for mixed-content errors.
- Identify the specific URL and the plugin, theme, widget or database field that generated it.
- Update hard-coded links in theme and plugin settings, custom HTML and menus.
- Replace old media URLs in content only after confirming the replacement points to the same resource.
- Clear page, object and CDN caches, then retest the affected page.
Do not blindly replace every database string or install a plugin as a substitute for finding the source. A plugin may help rewrite known URLs, but it cannot repair an incorrectly configured server certificate.
5. Redirect HTTP to HTTPS
Configure a permanent HTTP-to-HTTPS redirect at the layer that serves your site: the hosting control panel, web server, reverse proxy, CDN or WordPress.com platform. Use the instructions for your actual stack rather than copying a generic .htaccess rule. Keep one canonical hostname, including your chosen www or non-www version.
Test an old HTTP URL, a deep page and a URL with query parameters. Each should reach the corresponding HTTPS URL without a redirect chain or loop. Your host should also confirm that certificate renewal is automated and monitored; ACME clients must repeatedly complete domain validation and certificate management for renewal (Let’s Encrypt: How It Works).
WordPress.com sites use a different workflow
WordPress.com users should not follow self-hosted server instructions. In the WordPress.com Hosting Dashboard, open the domain security section, check the certificate status and follow the platform’s provisioning and DNS guidance (WordPress.com: Secure Your WordPress Site Domain with SSL).
If provisioning is blocked, WordPress.com identifies issues such as incorrect DNS or CAA records, mixed nameservers and DNSSEC configuration as possible causes. Resolve the listed domain problem, then allow the platform to retry certificate issuance. Do not add server-level rules that you cannot control on WordPress.com.
Recommended Free Tools
Rank #4
Reverse proxies and CDNs: avoid redirect loops
In a proxy or CDN arrangement, the proxy may terminate TLS while the origin server receives an ordinary HTTP connection. WordPress must still be told which forwarded protocol represents the visitor’s request. If the proxy does not forward the HTTPS scheme correctly, forcing HTTPS in the admin can create an infinite redirect loop.
- Ask the proxy or hosting administrator which header carries the original scheme.
- Confirm the proxy is configured to send that header securely and consistently.
- Confirm WordPress is configured to interpret the forwarded HTTPS state for that specific proxy.
- Test both
/wp-admin/and the public site after purging proxy caches.
Use the proxy provider’s documented configuration and WordPress’s HTTPS guidance rather than pasting code intended for a different CDN or server (WordPress HTTPS administration guidance).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot the most common failures
HTTPS shows a certificate warning or will not load
Contact the host and verify that the certificate covers the exact hostname, DNS points to the intended server, the certificate is installed on the active server, and the server is presenting the current certificate. On WordPress.com, review DNS, CAA, nameserver and DNSSEC settings in the domain security instructions.
Site Health has no HTTPS switch
The environment check may still be failing, or WP_HOME/WP_SITEURL may be fixed in wp-config.php. Resolve the certificate, DNS, server or proxy condition first. WordPress’s Site Health documentation notes that server configuration changes may require the hosting provider (WordPress Site Health screen).
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
The site is HTTPS but pages have no padlock
Inspect the browser Console on the specific page. Mixed content is page-specific: one template may contain an old image URL while another is clean. Correct the reported HTTP resource, clear caches and test again.
The dashboard redirects endlessly
This usually indicates a mismatch between the proxy’s forwarded protocol and WordPress’s HTTPS detection. Have the host verify TLS termination, forwarded headers and any admin-HTTPS forcing rule before changing URL settings again.
Choosing an SSL workflow or host
When comparing providers or setups, evaluate the operational responsibilities rather than the certificate label alone:
- Who provisions the certificate and handles failed validation?
- Is renewal automatic, and who receives expiry alerts?
- Can support diagnose DNS, CAA, mixed-content and redirect problems?
- Does the setup use direct server termination or a proxy/CDN, and is forwarded HTTPS documented?
- Can you access the controls needed to test and repair the configuration?
For a self-hosted site, a host-managed certificate is often simpler when it includes renewal and support. An ACME/client-managed setup offers control but makes validation, renewal and proxy configuration your responsibility.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

