How to Install an SSL Certificate on WordPress? Step-by-Step Guide
· Guide
Getting an SSL certificate for your WordPress site is only half the job. Once the certificate is installed on the server, WordPress itself needs to be reconfigured too — otherwise visitors may still see a broken padlock or a "partially secure" warning. Here's the complete process:
1. Install the Certificate on Your Server
If your host uses cPanel/Plesk, a free Let's Encrypt certificate may already be installed automatically via AutoSSL (check cPanel's SSL/TLS Status page to confirm). If you purchased a paid certificate from PekiSSL, you'll need to manually upload the certificate, private key, and CA bundle through your hosting panel's SSL/TLS section.
2. Update WordPress Address Settings
In your admin dashboard, go to Settings > General. Change the "WordPress Address (URL)" and "Site Address (URL)" fields from http:// to https:// and save. Skipping this step means WordPress will keep generating many links — including the login page — over HTTP.
3. Fix Mixed Content Issues
Old posts, database entries, or theme settings may still reference images, scripts, or CSS over http://. Browsers block these, showing a broken padlock. The easiest fix is a plugin like "Really Simple SSL," which automatically rewrites existing HTTP links to HTTPS. For a more hands-on approach, run `wp search-replace 'http://yoursite.com' 'https://yoursite.com'` via WP-CLI (back up your database first).
4. Add an Automatic Redirect via .htaccess
On an Apache server, add this rule to the top of your .htaccess file to redirect all HTTP traffic to HTTPS:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
On Nginx, a similar 301 redirect needs to be defined in your server block — often available as a one-click toggle in your hosting panel.
5. If You Use Cloudflare or Another CDN
If a CDN/proxy like Cloudflare sits in front of your site, make sure the SSL/TLS encryption mode is set to "Full" or "Full (Strict)," not "Flexible." Flexible mode doesn't encrypt the connection between Cloudflare and your server, and can conflict with WordPress's own HTTPS redirect, causing an infinite redirect loop (ERR_TOO_MANY_REDIRECTS).
6. Verify the Installation
Once everything is in place, run ssllabs.com/ssltest to check your server-side configuration, and open your browser's developer console (F12 > Console) to confirm no mixed content warnings remain.
Visit the PekiSSL product page to find the right certificate for your needs.