SECURITY FINDING
Self-signed SSL certificate
What it is
The certificate isn't signed by a certificate authority browsers trust (self-signed, or issued by an unknown authority), so visitors see a security warning even though the connection is technically encrypted.
How to fix it
Replace it with a certificate from a trusted CA — Let's Encrypt issues them for free.
In depth
Your website is using an SSL certificate that browsers don't recognize as legitimate, so visitors see a scary security warning when they visit your site even though their connection is actually encrypted and safe. This happens because your certificate wasn't issued by an authority that web browsers have been programmed to trust, like the major certificate companies. It's like having a real lock on your door, but the key was made by someone unknown, so people don't trust it. The fix is straightforward: you need to replace your current certificate with one from a trusted certificate authority, and the good news is that Let's Encrypt provides these certificates completely free. Your web hosting provider or your WordPress security plugin can usually do this replacement automatically in just a few clicks, and once it's done, visitors will see a green lock icon and won't get any warnings.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.