RunCabin Blog · Fix-it guide

Why does my website say "Not Secure"?

August 13, 2026 · 7 min read

You almost certainly were not hacked. That is the first thing to get off your chest, because the wording is alarming and the actual meaning is dull. "Not secure" means the connection between your website and the person looking at it is not encrypted, or the certificate that does the encrypting has lapsed or does not match the address they typed. Nobody broke in. A renewal did not happen, or it was never set up.

The second thing: this is a hosting problem, not a website problem. You do not need to rewrite a page, redo your photos or hire anybody to "clean" the site. Somebody needs to fix one setting on the machine your site lives on, and for a normal local-business site the part everyone worries about paying for is free.

What the customer actually sees

There are three flavors, and they are wildly different in how much they cost you.

Owners tend to discover the third one from a customer, weeks in. Nobody calls to tell you about the first two. They just leave.

The part that makes this urgent in 2026

This has been drifting from cosmetic to serious for a decade, and there is now a date on the calendar. Google has announced it is turning on the Chrome setting called Always Use Secure Connections by default: for the roughly one billion people on Enhanced Safe Browsing in Chrome 147 in April 2026, and for everybody in Chrome 154 in October 2026.

What that means in practice, in Google's own words, is that "Chrome will ask for the user's permission before the first access to any public site without HTTPS," in a dialog telling them the site "does not support a secure connection" and that "attackers could view or change information." Local addresses and intranet sites are excluded, and users can still switch the warnings off. But for a public business site, the default behavior shifts from a small label to a question the visitor has to answer before your homepage loads.

Put that next to what a local trade's website is for. A homeowner heard your name, looked you up, and is deciding whether to let you into their house. We have written before about how fast that check happens. A browser asking them to grant permission to view your site is not a detail they will interpret charitably.

The five causes, and how to tell which one you have

Open your site on a phone and a laptop, try both the plain and the www version of your address, and match what you see to this list.

  1. No certificate at all. The address stays on http:// and every page is labeled not secure. Common on older sites built before this mattered and never touched since. Fix: the host enables HTTPS and redirects HTTP traffic to it.
  2. The certificate expired. The site worked in the spring and throws a full-page warning now. Certificates are short-lived on purpose, so something has to renew them automatically. When a site is abandoned, this is usually the first visible symptom. If that sounds like your situation, start with getting control of your domain and hosting rather than chasing the warning.
  3. The certificate does not cover the address people typed. yourbusiness.com loads fine, www.yourbusiness.com throws a warning, or the other way around. Both should be covered and one should redirect to the other. This one hides for months because you always type it the way that works.
  4. Mixed content. The page itself loads over HTTPS but pulls in an image, font or script over insecure HTTP. Browsers block or upgrade a lot of this now, so the usual result is a broken photo or a padlock that never goes fully clean. Typically leftover hard-coded links after a site moved.
  5. The domain points somewhere stale. You switched website companies, or a subscription ended, and the domain still resolves to a host with no certificate for it. See also: what actually happens to a site and domain when you cancel.

All five live with whoever runs your hosting. None require you to learn anything about certificates.

What this should cost: nothing

Here is the part worth knowing before anybody quotes you. Let's Encrypt is a nonprofit certificate authority that states outright that it does not charge a fee for its certificates. It is designed around automation: standard certificates are valid for 90 days, subscribers can opt into six-day certificates, and the whole model assumes software renews them on a schedule without a human involved. Modern hosting issues and renews these silently. Nobody should be reminding you about it annually.

So if there is a line item on your website bill for SSL, that is packaging, not a cost being passed on to you. Paid certificates are real and have real uses in banking and enterprise, where the certificate authority verifies the legal organization behind the site. A three-truck landscaping company does not need one, and no browser gives you a better padlock for buying one. If a proposal shows an annual SSL charge, that is a fair question to ask about, in the same spirit as the rest of the fine print in website pricing.

If somebody called to tell you about this

Worth naming, because the timing is rarely a coincidence. An expired certificate is a gift to cold callers: it is real, it is visible to anyone, and it sounds catastrophic when described over the phone. The script is that Google is about to delist you, that your customers' information is exposed, and that their team can secure it today for a monthly fee.

Owners in the trades know this pattern well. As one poster on an HVAC forum put it, "about 10 minutes after your business site goes live people will start calling and emailing about SEO services." The security version is the same call with different vocabulary. Two rules hold up: never buy a fix for a problem you have not personally seen in your own browser, and never authorize anything about your website, domain or Google listing on an inbound call. Go look at your site, then call whoever actually runs your hosting. There is more on the genre in why these calls flood a new business.

Does it hurt your Google ranking?

A little, and it is the least interesting part. Google has said for years that HTTPS is a lightweight ranking signal, so it is a nudge rather than a penalty. Chasing the ranking angle misreads where the money leaks.

The real loss is human and invisible. The person who sees a warning does not report it, ask a follow-up question or come back later. They tap the back button and call the next contractor in the results, and you never learn that it happened. It shows up in your books as a slow month with no obvious cause, which is exactly how a website quietly stops producing work.

Worth one extra thought if you take deposits or run a quote form: the form is where a customer types their name, address, phone and a description of what is wrong with their house. That should never travel unencrypted, and the browser is right to say so.

A five-minute check

  1. Open your site on your phone. Does the address bar say "Not secure" anywhere?
  2. Type both versions by hand: yourbusiness.com and www.yourbusiness.com. Do both load cleanly?
  3. Click into an interior page, a service page and your contact page. The warning can be page-specific.
  4. Start typing in your own quote form. Does anything change in the address bar?
  5. Check the link on your Google Business Profile, your Facebook page and your email signature. If any of them still say http://, update them to https://.
  6. Ask your host or whoever runs the site one question: is HTTPS on, and does the certificate renew automatically? Those are the only two answers you need.

Do this on the first of the month, quarterly, or any time you change hosts. A silent renewal failure looks exactly like a normal site until it does not.

Where RunCabin fits

RunCabin builds and runs the site for $39.99/mo, flat, and this whole category of problem is on our side of the line. HTTPS is on from the first minute your site goes live, the certificate renews itself, both the plain and www versions of your domain resolve to the same secure site, and your quote form is encrypted end to end. There is no SSL line item, because there is no SSL bill. Your domain, professional email and a logo are included, with no setup fee and no contract.

That is the honest pitch here: not that certificates are hard, but that nobody starting a painting or plumbing business should be the person responsible for remembering them. When something on the site needs to change you ask for it in plain English and it changes in moments. The site is yours, and so is the domain, whenever you want to take them elsewhere.

See your site before you pay a cent

No sales call, no card. We build a real preview with your name, your trade and your service area, secure and live from the first minute.

See your free site preview →

Related reading: my web guy disappeared, how do I get control of my website · why you get so many website and SEO sales calls · how much a small-business website should cost