Short answer: use HTTPS, always. Here every domain gets a free SSL certificate automatically, so the real question is almost never “do I have to buy one?” but “is my site actually using it?” Because http:// and https:// are two different addresses, and a site can answer on both at once.
What changes, point by point
|
HTTP |
HTTPS |
| What travels |
Everything in the clear: the page, what you type into a form, passwords, the session cookie. |
Everything encrypted. Whoever is on the path cannot read the content, though they can still see which domain you connect to. |
| Tampering on the way |
The content can be changed on the way without anyone noticing. |
Any change is detected and the connection is refused. |
| What the browser shows |
A “not secure” warning, especially on pages with forms. |
The padlock. |
| Services that call your site |
Many refuse the address. Webhooks and payment notifications usually require HTTPS. |
Accepted. It is the normal requirement. |
| Search |
At a disadvantage. |
Google treats HTTPS as a ranking signal in your favour. |
The fourth row deserves a note. For services that call your site, the practical rule is simple: if the callback address is http://, many will not even try. One example is the WhatsApp Cloud API webhooks, which according to Meta’s documentation require an HTTPS address: Meta webhooks. And the padlock only appears if everything the page loads also comes over HTTPS: a single image at an http:// address is enough to spoil it.
How to tell whether your site is really on HTTPS
| 1 |
Confirm the certificate exists. In cPanel, open SSL/TLS Status: it lists each domain’s certificate and the date it renews. If a new domain does not have one yet, it can take from a few minutes to an hour.
|
|
| 2 |
Type the address with http:// in the browser. It should move to https:// by itself. If it stays on HTTP, the redirect is missing.
|
|
| 3 |
Look at the code the server returns. In a terminal, curl -I http://yourcompany.com should show a 301 and a location line with the https:// address. More on reading this in 301 or 302.
|
|
| 5 |
On WordPress, set both addresses (the WordPress one and the site one, under Settings › General) to the https version, and fix whatever stayed mixed: changing the site address and mixed content.
|
|
|
Do not force HTTPS before the certificate is valid. If you do, the browser shows an insecure-connection warning instead of your site. And if the padlock does not appear once everything is right, follow the causes, in order.
|
|
Once everything has been stable for a while, you can go further and tell browsers to always use HTTPS (HSTS). It is a hard decision to undo, though: read HSTS explained first.
|
|
The padlock is missing or the site still opens on HTTP? Tell us the address and what you see.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |