Website Says “Not Secure” on Squarespace, Wix or GoDaddy — Fix It

unflagdomain Team·UPDATED August 21, 2026

Your Squarespace, Wix, or GoDaddy site says "Not Secure" because it's loading over HTTP instead of HTTPS — almost always a missing or unfinished SSL certificate. The fix is usually a single free toggle in your platform settings, not a virus or hack. Over 95% of browsing time in Chrome happens over HTTPS, so unencrypted sites now stand out as a warning.

TL;DR: A "Not Secure" label means your site loads over HTTP, not HTTPS — usually because free SSL isn't switched on yet. Each platform (Squarespace, Wix, GoDaddy, Shopify) includes a built-in free certificate; flipping one setting fixes it within minutes to a day. This is different from a security blocklist warning, which involves malware. With over 95% of Chrome traffic encrypted, missing SSL is the most common cause.

If you've just seen that grey "Not Secure" text in the address bar, take a breath. It's one of the most common and most fixable website issues out there. Let me walk you through what it means, why it's showing, and exactly which switch to flip on your platform.

What does "Not Secure" actually mean?

"Not Secure" means the connection between your visitor's browser and your website isn't encrypted — it's running on HTTP instead of HTTPS. Chrome has labeled all plain HTTP pages this way since July 2018, per Google's Chromium security team. It is not a hacking alert. It usually just means your SSL certificate isn't active yet.

Chrome began marking every HTTP page as "Not Secure" in version 68, released July 2018, according to Google's Chromium blog. The label flags an unencrypted connection — not malware — and disappears once a valid SSL/TLS certificate serves the site over HTTPS.

SSL (now technically TLS) creates an encrypted tunnel so passwords, card numbers, and form data can't be read in transit. When that certificate is missing, expired, or not yet provisioned, the browser warns visitors. The good news: every major site builder now hands you a free certificate. You usually just have to turn it on.

Is "Not Secure" the same as a hacked or blocklisted site?

No — and this distinction matters. "Not Secure" is about encryption. A "Deceptive site ahead" or "The site ahead contains malware" red full-screen warning is something else entirely: that comes from Google Safe Browsing, which protects billions of devices and flags sites distributing malware or phishing.

Owners often conflate these two because both feel like "my site is broken." In our experience running unflag, the website warnings people actually face split across two very different worlds: a single missing certificate on one side, and a sprawl of security vendors on the other. When we scan a domain we check it across 124 active vendors — antivirus engines, web blocklists, and a handful of RBL and search-engine sources — and an SSL warning never shows up in any of them, because it isn't a reputation flag at all. The fix for "Not Secure" is a free toggle. The fix for a blocklist warning is cleaning the actual hack, then requesting removal from the security blacklist. We cover the broader picture in our guide on why your website says "Not Secure" and what to do about it.

Why does my Squarespace website say "Not Secure"?

Your Squarespace site shows "Not Secure" almost always because the free built-in SSL certificate is toggled off or hasn't finished provisioning after a domain change. Squarespace includes free SSL on every plan and provisions certificates automatically, per Squarespace's own documentation. Flip the setting to "Secure" and wait for it to issue.

Squarespace provides a free SSL certificate on all plans and enables it by default, according to Squarespace support documentation. If a site shows "Not Secure," the SSL setting is usually disabled or still provisioning after a recent domain connection — a process that can take up to 72 hours.

How to enable SSL on Squarespace

Here's the path. It takes about a minute.

  1. Open your Squarespace dashboard and go to Settings.
  2. Click Developer Tools, then SSL (newer accounts: Settings → Advanced → SSL).
  3. Set the security preference to Secure (Preferred).
  4. Make sure HSTS Secure is checked to force HTTPS for every visitor.
  5. Save and wait — new certificates can take a few hours to a couple of days to provision.

If you recently pointed a domain to Squarespace, the certificate has to be issued before the warning clears. That delay is normal. Don't panic if it's still showing an hour later.

Why does my Wix site say "Not Secure"?

Your Wix site says "Not Secure" usually because it hasn't been published since SSL was enabled, or the certificate is still provisioning on a newly connected domain. Wix enables free SSL automatically on all sites and redirects HTTP to HTTPS, per Wix's support center. Republishing the site and confirming the SSL toggle resolves most cases.

Wix automatically issues a free SSL certificate to every site and redirects traffic to HTTPS, according to Wix support. A persistent "Not Secure" label typically means the site needs republishing after SSL activation, or a custom-connected domain's certificate is still being issued.

How to fix "Not Secure" on Wix

Try these steps in order.

  1. In your Wix dashboard, go to Settings, then SSL Certificate (or Domains → your domain → advanced settings).
  2. Confirm SSL is enabled and the HTTP to HTTPS redirect is on.
  3. Republish your site — changes don't go live until you do.
  4. If you connected a domain via pointing rather than nameservers, allow up to 24–48 hours for the certificate.

In our experience helping owners untangle these warnings, the single most common Wix fix is embarrassingly simple: the SSL toggle was already on, but the site had never been republished since. One click of Publish and the warning vanished. We see the same pattern of "the setting was right, the action was missing" with the blocklist removals we handle — which is exactly why our process leaves nothing to chance. Once a site is cleaned and paid for, unflag generates a unique removal request for each flagging vendor and dispatches them for you, rather than hoping an owner remembers to chase every one.

What about mixed content warnings on Wix?

Sometimes SSL is active but a page still shows "Not Secure" because of mixed content — an image, font, or embed loading over HTTP on an otherwise HTTPS page. Browsers flag the whole page when even one resource is unencrypted. Replace any hardcoded http:// links in custom embeds or HTML widgets with https:// and republish.

Why does my website say "Not Secure" on GoDaddy?

Your GoDaddy site says "Not Secure" usually because the SSL certificate isn't installed, isn't yet provisioned, or HTTPS forwarding isn't switched on. GoDaddy Websites + Marketing plans include SSL, and managed WordPress plans bundle it too, per GoDaddy's help center. For other setups you may need to install the certificate or enable a redirect.

GoDaddy includes SSL with Websites + Marketing and Managed WordPress plans, according to GoDaddy's help documentation. Sites still showing "Not Secure" often need the certificate manually installed, HTTPS forced through a redirect, or simply more provisioning time after setup.

How to enable HTTPS on GoDaddy

The exact steps depend on your product, but the core idea is the same.

  1. Websites + Marketing: SSL is automatic. If it's not showing, go to your site's Settings → Domains and confirm the domain is fully connected. Allow up to 72 hours after connecting.
  2. Managed WordPress: SSL is included. In the hosting dashboard, find Settings, locate the SSL option, and enable Force HTTPS / HTTPS redirect.
  3. cPanel / other hosting: You may need to install the certificate through the SSL manager, then add an HTTP-to-HTTPS redirect in your settings or .htaccess.

If you bought a standalone SSL certificate from GoDaddy, it still has to be installed and assigned to your domain. Buying it isn't the same as activating it — a step that trips up a lot of owners.

What about Shopify and other platforms?

Shopify issues a free TLS/SSL certificate to every store automatically and forces HTTPS across the storefront, per Shopify's help center. If a store shows "Not Secure," the certificate is usually still provisioning after a domain change, or a theme has mixed content. Most hosted platforms today follow this same free-and-automatic SSL model.

Shopify automatically provides a free TLS certificate and enforces HTTPS for all stores, according to Shopify documentation. Provisioning can take up to 48 hours after connecting a custom domain, during which a temporary "Not Secure" warning is normal and resolves on its own.

The broader trend backs this up. W3Techs reports that the vast majority of websites it surveys now use HTTPS by default, so an unencrypted site is increasingly the exception. Whatever your platform, the pattern is the same: find the SSL or security setting, enable it, force HTTPS, and give it time to provision.

When the warning won't go away

If you've enabled SSL and waited a full 72 hours and it still says "Not Secure," check for mixed content first using your browser's developer console. Then confirm your DNS actually points to the right host. Persistent issues usually trace back to mixed content or an incomplete domain connection — not a deeper problem.

When "Not Secure" is actually a different problem

If your visitors see a red full-screen warning rather than a grey "Not Secure" label, that's a blocklist flag, not an SSL issue — and SSL settings won't fix it. These come from Safe Browsing and antivirus vendors after detecting malware. Safe Browsing alone shows warnings to users on billions of devices, and clearing one requires cleanup plus a review request.

A grey "Not Secure" label signals a missing SSL certificate; a red full-screen "Deceptive site ahead" page signals a malware or phishing blocklist flag from Google Safe Browsing, which guards billions of devices. The two have completely different fixes — encryption settings versus malware cleanup and vendor review requests.

Across the domain checks we run, a meaningful share of owners who arrive convinced their site is "blocklisted" actually just have an SSL toggle switched off — no malware at all. The reverse also happens: people enable SSL repeatedly while a real malware flag sits untouched, because the two warnings feel identical to a non-technical owner. One thing we want to be honest about: unflag doesn't scan or clean malware for you. We trust that the cleanup is done, then clear the residual blocklist flags that linger afterward. And when those flags involve vendors that only accept a web form — like AVG or ESET — or a manual review like Google Safe Browsing, we don't pretend to automate them. Those become guided dashboard cards that walk you through the submission yourself.

If it turns out your site really is flagged, the path is different. First clean the hack (or confirm it's a false positive). Then submit a Google Safe Browsing review in Search Console — that step is manual and can't be automated by anyone. For the dozens of antivirus and security vendors that may also flag you, our guide to removing a website from a security blacklist explains how to reach each one. And if you're still unsure which warning you're facing, start with why your website says "Not Secure".

The bottom line

Nine times out of ten, "Not Secure" on Squarespace, Wix, GoDaddy, or Shopify is just SSL waiting to be switched on — and every one of those platforms gives you a free certificate. Enable SSL, force HTTPS, and wait up to 72 hours for provisioning. With over 95% of Chrome traffic now encrypted, this is table stakes, and the fix is genuinely fast.

The only time it's something more serious is a red full-screen warning, which signals a malware blocklist flag rather than an encryption gap. Those need a real cleanup followed by removal requests to each flagging vendor. If that's where you've landed, read our walkthrough on getting your website off security blocklists for the next steps.

// FAQ
  • Squarespace includes free SSL on every plan, so a "Not Secure" label usually means the SSL setting is off or still provisioning after a domain change. Go to Settings, find SSL, choose "Secure (Preferred)," enable HSTS, and save. New certificates can take up to 72 hours to issue.

  • Wix activates free SSL automatically, but changes only go live after you republish your site. If the warning persists, the cause is often mixed content — an image or embed loading over HTTP. Confirm SSL is enabled, replace any http:// links with https://, then click Publish to apply everything.

  • GoDaddy includes SSL with Websites + Marketing and Managed WordPress plans. Confirm your domain is fully connected, then enable Force HTTPS. If you bought a standalone certificate, it must be installed and assigned to your domain — purchasing alone doesn't activate it. Allow up to 72 hours for provisioning.

  • No. A grey "Not Secure" label means your connection isn't encrypted — a missing SSL certificate, not malware. A red full-screen warning like "Deceptive site ahead" comes from Google Safe Browsing after detecting an actual hack. SSL settings fix the first; only cleanup and a review request fix the second.

  • After you enable SSL, the warning usually clears within minutes to a few hours, but certificate provisioning can take up to 72 hours — especially right after connecting a new domain. If it remains past that window, check for mixed content or confirm your DNS points to the correct host.