HTTP (Hypertext Transfer Protocol) is the set of rules browsers and servers use to request and deliver web pages. HTTPS (HTTP Secure) is the same protocol running over an encrypted connection secured by TLS (Transport Layer Security). With HTTPS, the data passing between a visitor’s browser and your server, including form submissions, passwords, and payment details, cannot be read or altered by anyone in between. Every website should use HTTPS today, and browsers, search engines, and customers all treat sites that do not as untrustworthy.
You can tell which one a page uses from its address: https:// at the start of the URL, and a padlock or similar indicator in the browser’s address bar. Pages served over plain HTTP are labeled “Not secure” in Chrome and other major browsers.
How HTTPS works
When a browser connects to a site over HTTPS, the two first perform a TLS handshake. The server presents its SSL/TLS certificate, a digital document issued by a trusted certificate authority that proves the server really belongs to the domain the visitor asked for. The browser checks the certificate, and the two agree on encryption keys for the session. From then on, everything they exchange is encrypted.
HTTPS provides three protections. Encryption keeps the content private from anyone watching the network, such as another user on public Wi-Fi. Integrity prevents the content from being modified in transit, for example by injected ads or malicious scripts. Authentication assures the visitor they are talking to the real site and not an impostor.
“SSL” is still commonly used to describe all of this, but SSL is the older, now-retired predecessor of TLS. Modern HTTPS uses TLS 1.2 or TLS 1.3.
Why HTTPS matters
Trust and conversion
Browsers warn visitors about sites that are not secure. Chrome began marking all HTTP pages as “Not secure” in 2018, and browsers show more prominent warnings on HTTP pages with forms. Few prospects will enter their details into a form their browser has just told them is insecure. For any business that collects leads, HTTPS is a conversion requirement, not a technical nicety.
SEO
Google announced HTTPS as a ranking signal in 2014 and includes it among its page experience considerations. On its own it is a light signal, but it is also a prerequisite for other things that matter: modern performance protocols, many browser features, and accurate referral data in analytics. When traffic moves from an HTTPS site to an HTTP site, the referrer information is typically stripped, which can make traffic sources harder to attribute.
Performance
HTTPS used to carry a reputation for slowing sites down. That is no longer true in practice. The fastest modern protocols, HTTP/2 and HTTP/3, are used by browsers over encrypted connections, and TLS 1.3 reduces handshake overhead. A properly configured HTTPS site is usually faster than the same site on plain HTTP.
Security and compliance
Any site that handles personal data, logins, or payments needs encryption in transit. Payment card rules, privacy regulations, and many industry frameworks expect it. Even a simple brochure site benefits, because HTTPS prevents third parties from injecting content into your pages.
HTTP versions: HTTP/1.1, HTTP/2, and HTTP/3
HTTP itself has evolved. HTTP/1.1 handles requests largely one at a time per connection, which slowed pages with many assets. HTTP/2 allows many requests to share a single connection at once and compresses headers, which substantially improves load times for asset-heavy pages. HTTP/3 runs over QUIC, a transport built on UDP, and further reduces delays on unreliable or mobile networks. Most managed hosts and CDNs now support HTTP/2 and HTTP/3 automatically for HTTPS sites, and it is worth confirming yours does as part of any page speed review.
Moving a site from HTTP to HTTPS
Most sites made this move years ago, but older sites, subdomains, and neglected microsites still turn up on HTTP. A clean migration involves several steps:
1. Install a certificate. Most managed WordPress hosts, including WP Engine, provide free certificates through Let’s Encrypt and renew them automatically.
2. Update internal URLs. Change the site address in WordPress settings and update links, images, scripts, and stylesheets in the database and theme to use HTTPS, so pages do not load insecure resources.
3. Redirect HTTP to HTTPS. Add server-level 301 redirects from every HTTP URL to its HTTPS equivalent, one hop, with no chains.
4. Fix mixed content. A page served over HTTPS that loads any resource over HTTP triggers mixed content warnings, and browsers may block the insecure resource. Check every template.
5. Update canonicals, sitemaps, and structured data. Canonical tags, the XML sitemap, hreflang tags, and schema should all reference HTTPS URLs.
6. Update external references. Google Search Console (add the HTTPS property or use a domain property), Google Analytics, Google Business Profile, ad accounts, social profiles, and directory listings.
7. Add HSTS once everything works. HTTP Strict Transport Security tells browsers to use HTTPS for your domain automatically, even if someone types or clicks an HTTP link.
HSTS and security headers
HSTS is sent as a response header, Strict-Transport-Security, with a duration and optional settings for subdomains and inclusion in browsers’ preload lists. It closes a gap: without it, the very first request to your site can still be made over HTTP before the redirect happens, which is a small window an attacker on the same network could exploit. HSTS should be introduced carefully, with a short duration first, because once browsers have cached it, reverting to HTTP is difficult.
HSTS is one of several HTTP security headers worth setting. Our guides to HTTPS, HSTS and SSL certificates and WordPress security headers cover the configuration in detail, including how to set them on WP Engine.
HTTPS on WordPress
On WordPress, the site address and WordPress address under Settings, General should both use HTTPS, and the database should not contain hard-coded HTTP links to your own domain in post content, widgets, theme options, or page builder data. A search-and-replace tool that handles serialized data safely is the reliable way to update old URLs. Caching and CDN layers should be purged after the change so they stop serving copies with insecure references. Plugins that force HTTPS by rewriting URLs on every page load are a stopgap; fixing the stored URLs and redirecting at the server is cleaner and faster. Managed hosts such as WP Engine handle the certificate and can enforce the redirect at the platform level, which is where it belongs.
Common HTTPS problems
Expired certificates. Browsers show a full-page warning when a certificate expires, which effectively takes the site offline for most visitors. Automatic renewal prevents this, but it should still be monitored.
Mixed content. Hard-coded HTTP image or script URLs in old posts, theme files, or plugin settings.
Redirect chains. HTTP to HTTPS, then non-www to www, then a trailing slash redirect, each a separate hop. Consolidate them into one redirect.
Duplicate versions indexed. Both HTTP and HTTPS, or www and non-www, versions of pages appearing in search. Consistent redirects and canonicals fix this.
Certificate name mismatches. A certificate that covers the www domain but not the bare domain, or not a subdomain in use.
Forgotten subdomains. Old landing pages, email marketing domains, and staging sites left on HTTP, still linked from somewhere and still indexed.
HTTPS as part of technical SEO and site care
HTTPS configuration is one of the first things we check in every audit, because problems with it affect security, trust, indexing, and performance at once. It is included in our technical SEO services, and certificate renewal, redirects, and security headers are maintained as part of our WordPress care plans. If you are not sure your site is configured correctly, book a discovery call.