What the warning means, why it is about to get louder, and how to make it go away for good.
Resources / Chrome says my website is not secure. What does that mean?
It means your website is loading without HTTPS, so anything a visitor types into it travels unprotected. It does not mean your site has been hacked. The fix is usually a free certificate and a redirect. It matters more this month: from Chrome 154 in October 2026, Chrome will ask visitors' permission before it opens a public site without HTTPS at all.2 That is a warning page in front of your homepage, not a small label.
Chrome asks permission before opening non-HTTPS sites
What a trusted certificate costs
What the warning does not mean
Chrome shows Not secure in the address bar when a page loads over plain HTTP instead of HTTPS. It has done this for every HTTP page since Chrome 68 in July 2018.1 Without HTTPS, the connection between the visitor and your site is not encrypted, so a contact form, a login or a quote request can be read or changed by anyone sitting on the same network, such as a public wifi hotspot.
It is a statement about the connection, not about your business. It does not mean the site has been hacked or has a virus. But visitors do not read it that carefully. To most people, Not secure next to your name reads as a reason not to fill in the form.
If you see a full-page warning instead, such as Your connection is not private, that is a different problem: the site has a certificate, but it is expired or does not match the address. That one stops most visitors completely and needs fixing today.
Google announced in October 2025 that Chrome 154, due in October 2026, turns on a setting called Always Use Secure Connections for everyone. From then, Chrome will ask the visitor's permission before the first visit to any public site without HTTPS.2 Users who opted into Chrome's Enhanced Safe Browsing have had this since Chrome 147 in April 2026.
In practice that means a site without HTTPS stops being a site with a small grey label and becomes a site behind a warning screen. Some visitors will click through. Many, especially people who found you on Google and have three other options open, will not.
If your site already loads on an https address with no Not secure label, none of this affects you. If it does not, this is the month to fix it.
The most common reason is that the site simply has no certificate. That is typical of older sites, very cheap hosting, and sites that were moved to a new host without anyone setting HTTPS up again.
The next most common is that the certificate exists but the site does not use it everywhere. The https version works, but the http version still loads without redirecting, so anyone following an old link or typing the address gets the insecure version. A close relative is mixed content: the page itself is https, but an image, script or form on it still loads over http, so the browser no longer treats the page as fully secure.
Less often, the certificate only covers one version of the name, say the address with www but not without it, or it has expired because automatic renewal quietly stopped working.
Get a certificate. For a normal small business site it should be free: Let's Encrypt issues trusted certificates at no cost, and most decent hosts can switch one on in a few minutes. If your host wants to charge a yearly fee for a basic certificate, or cannot provide one at all, that tells you something about the host.
Then make sure it renews itself. Let's Encrypt certificates currently last 90 days, and that is being cut to 45 days by 2028.3 Manual renewal is not a realistic plan at that pace, so automatic renewal has to be set up and working.
Finally, redirect every http address to https, fix any mixed content, and update the links you control, such as your Google Business Profile and social profiles, to the https address. Then check the result with a tool rather than by eye, since some mixed content only shows on particular pages.
Yes. The warning is not only about card numbers. A contact form carries a name, a phone number and a description of someone's problem, and a quote request often carries an address. That is personal information, and it deserves the same protection.
It also matters for being found and trusted. Chrome is the browser most of your visitors use, and from October it will show a warning before people open a public site without HTTPS, whatever the site does. A plumber's brochure site gets the same screen as an online shop.
Use hosting that includes certificates and renews them automatically, so it is not a job anyone has to remember. Our own hosting includes SSL certificates as standard, as good hosting should.
Then watch the expiry date anyway. Automatic renewal is reliable until the day it is not, for example after a change to your domain settings or a move between hosts. Our free SSL Expiry Checker shows when your certificate runs out, and a monitoring service can warn you before it does.
And whenever the site moves, is rebuilt or changes address, open a few pages afterwards and check they load on https with no warning. That is when HTTPS most often gets lost, and it takes a minute to confirm.
Website Security Checker: Check your HTTPS, certificate and security headers in one go.
SSL Expiry Checker: See exactly when your certificate runs out.
How do I check if a website is safe before I buy from it?: The other side of the padlock: why it proves encryption, not honesty.
Because the page is loading over plain HTTP rather than HTTPS, usually because the site has no certificate or is not redirecting to the secure version. Chrome has labelled every HTTP page Not secure since Chrome 68 in July 2018.
No. It means the connection is not encrypted, so information typed into the site could be read or changed in transit. It is a warning about the connection, not a sign of a virus or a break-in.
Google has said that Chrome 154, due in October 2026, will turn on Always Use Secure Connections by default. Chrome will then ask visitors' permission before the first visit to any public site without HTTPS, so those sites sit behind a warning screen.
For a normal small business site, nothing. Let's Encrypt issues trusted certificates free and most hosts can turn one on in minutes. What matters is that it renews automatically, since Let's Encrypt certificates last 90 days and are moving to 45.
Usually mixed content: the page is HTTPS but an image, script or form on it still loads over HTTP. It can also be a missing redirect from the http address. A website security checker will show which it is.
Send us the address. We will look at what is causing it and tell you what it takes to fix, before Chrome's October change puts a warning screen in front of it. Free, no obligation.
Prefer to talk? Call (02) 9053 8789.