How to Improve WordPress Website Speed
Why WordPress sites are slow and how to fix it, in order of what actually helps. Images first, then plugins, caching and…
Paul Fletcher · 25 Aug 2026
Development
Your SSL certificate has expired and visitors are seeing a security warning. What has happened, how to fix it today, what it costs, and how to stop it happening again.
Your website was fine yesterday. Today visitors are hitting a full screen warning telling them the connection is not private, and the phone has stopped ringing. Almost always, the cause is an SSL certificate that has expired.
It looks alarming and it is bad for business while it lasts, but it is one of the simpler website problems to fix. Here is what has actually happened, how to fix it today, and how to make sure it never happens again.
An SSL certificate is what puts the padlock in the address bar and the s in https. It does two jobs: it encrypts what passes between your website and the person using it, and it proves your site is really your site.
Certificates are issued for a fixed period, and since 2020 that period has been about 13 months at most. Many are now issued for 90 days and renewed automatically. When one reaches its end date without being renewed, browsers stop trusting it and put a warning in front of your visitors.
The wording differs by browser, which is why the same problem gets searched in several ways.
| Browser | What your visitor sees |
|---|---|
| Chrome | Your connection is not private, with a code like NET::ERR_CERT_DATE_INVALID |
| Safari | This connection is not private |
| Firefox | Warning: potential security risk ahead, with SEC_ERROR_EXPIRED_CERTIFICATE |
| Edge | Your connection isn’t private |
If the code mentions a date, the certificate has expired. If it mentions the name, the certificate is for a different address than the one being visited, which is a related but different problem covered further down.
Most visitors will not click through the warning, and they should not. To someone who does not build websites, that screen looks like your business has been hacked. They leave, and a good number of them will not come back.
Click the padlock or the warning icon in the address bar and look at the certificate details. There will be a valid from and valid to date. If the valid to date has passed, that is your answer.
Certificates come from one of three places, and which one decides how you fix it.
With most hosting control panels this is a button. Find the SSL or security section, and look for renew, reissue, or install certificate. If the free automatic certificate is available, switch to it: it renews itself and costs nothing.
Load your site in a private browsing window, because your normal browser may cache the old certificate and keep showing the warning after the fix. Check the padlock is back and the new expiry date is roughly three months or a year away.
Test a service page, the contact page, and if you have one, the checkout. Also check both with and without www, because they can behave differently.
| What you see | What it usually means | Fix |
|---|---|---|
| Invalid SSL certificate, name mismatch | The certificate covers one address and the visitor is on another, often www versus non-www | Reissue covering both, and set one to redirect to the other |
| Not trusted, or self-signed | The certificate was generated locally rather than issued by a recognised authority | Replace it with a proper issued certificate |
| Mixed content warning | The certificate is fine, but the page loads an image or script over an insecure connection | Update those links to https |
| Certificate chain incomplete | An intermediate certificate was not installed with the main one | Reinstall including the full chain your provider supplies |
Not immediately, and not directly in the way people fear. Google has treated https as a lightweight ranking signal since 2014, so losing it does not wipe you out overnight. The real damage is behavioural: people arrive, see a warning, and leave straight away. Sustained over weeks, that is the thing worth worrying about, not the certificate itself.
Fix it quickly and there is usually nothing lasting to recover from.
For most small business websites, nothing. Free certificates from Let’s Encrypt are issued automatically by nearly every reputable host, they renew themselves, and they give exactly the same padlock and the same encryption as a paid one.
Paid certificates exist mainly for organisations needing extended validation or a warranty, which is rarely a small business. If you are being charged for a basic certificate, it is worth asking your host whether the free automatic option is available instead.
All of that is part of what a website maintenance plan covers, which is the honest reason we rarely see this on sites we look after. It is not clever work, it is just work somebody has to remember to do.
The practical difference monitoring makes is who finds out first. On the sites we look after, an expiring certificate, a security warning or an indexing problem reaches us as an automated alert. On the sites nobody watches, it reaches the owner as a customer saying they could not get through.
If you have gone through the steps above and the warning is still there, the usual causes are a cached certificate, a missing intermediate certificate, or a certificate installed on one server while your domain points at another. All three are quick for someone who does this often.
Worth running our website audit checklist while you are in there, because a lapsed certificate is often the visible symptom of a site nobody has looked at in a while. If nobody is looking after yours, tell us about it and we will give you a straight answer about what it needs.
Every SSL certificate is issued for a fixed period, usually 90 days or about a year. When it reaches its end date without being renewed, browsers stop trusting it and show visitors a full screen warning saying the connection is not private. The website itself is fine, it is the certificate that has lapsed.
Find out who issues it, which is usually your hosting company, then renew or reissue it from the SSL section of your hosting control panel. If a free automatic certificate is available, switch to it because it renews itself. Afterwards, check the site in a private browsing window, since your normal browser may cache the old certificate.
For most small business websites, nothing. Free certificates from Let's Encrypt are issued automatically by nearly every reputable host and give exactly the same padlock and encryption as a paid one. Paid certificates mainly exist for organisations needing extended validation, which is rarely a small business.
Not immediately or directly. Google has treated https as a lightweight ranking signal since 2014, so losing it does not wipe out your rankings overnight. The real damage is behavioural: people arrive from search, see a security warning and leave. Sustained over weeks that matters, so fix it quickly and there is usually nothing lasting to recover from.
That usually means a name mismatch, where the certificate covers one address and the visitor is on another, most often www versus non-www. The fix is to reissue the certificate covering both and set one to redirect to the other. Other causes are a self-signed certificate or a missing intermediate certificate in the chain.
Move to a certificate that renews automatically, check the payment card on file with your host has not expired, put the expiry date in your calendar with a month's notice, and set up uptime monitoring so you hear about it before a customer does. Check your domain renewal date at the same time.
Free quote
Tell us what you do and we will come back with clear, honest next steps.
Why WordPress sites are slow and how to fix it, in order of what actually helps. Images first, then plugins, caching and…
Paul Fletcher · 25 Aug 2026
What a WordPress backup must include, the four realistic ways to take one, how often, and the restore test almost everybody skips.
Charlie Dean · 25 Aug 2026
An honest answer, plus what speeds a website project up and what slows it down. Most small business sites go live in…
Paul Fletcher · 25 Aug 2026