glimanaDocs Open Glimana →

Issue guide · Security

Page is not on HTTPS

SeverityCritical
CategorySecurity
ScopePer page
EffortSmall
Verified byRe-crawl after you mark the task done
Rule keyhttp_not_https

Short answer

This page is served over http:// and returns 200 without redirecting to an https:// address. Modern browsers label it "Not secure", Google treats HTTPS as a lightweight ranking signal and uses the HTTPS version as canonical whenever both exist, and many features (service workers, geolocation, HTTP/2) are HTTPS-only. Move the whole site to HTTPS and redirect every HTTP URL to its HTTPS equivalent with a 301.

Why it matters

This issue affects connection security: anything sent over HTTP can be read or altered on the way. For search, Google indexes the HTTPS version by default and HTTP pages can be shown with a warning. Chrome also blocks or downgrades certain downloads and form submissions on HTTP pages.

How Glimana detects it

The rule fires when a crawled URL starts with http://, returns 200 and does not redirect to an https:// address. (Pages that redirect correctly are not flagged; the site-level rule No HTTP → HTTPS redirect covers the case where the home page itself is missing the redirect.)

How to fix it

  1. Get a certificate. Let's Encrypt is free and automated on most hosts; Cloudflare provides one at the edge.
  2. Serve the site on HTTPS. Enable the certificate in the host panel or web server and confirm https:// loads without warnings.
  3. Redirect HTTP to HTTPS. A server-wide 301 rule, so every old link lands on the secure version.
  4. Update internal references. Site URL settings, hard-coded http:// links in content, canonical tags and sitemap entries.
  5. Fix mixed content. Resources still loaded over HTTP will be blocked; see Mixed content.

Change both URLs under Settings › General to https://, then use Really Simple SSL or a search-replace tool (WP-CLI wp search-replace 'http://example.com' 'https://example.com') to update content links. Add the redirect in .htaccess or let the plugin do it.

Shopify stores are HTTPS by default. This rule can only fire for a custom domain whose SSL certificate has not been issued yet; check Settings › Domains and wait for "SSL certificate: Active" or fix the DNS records it asks for.

Terminate TLS at the load balancer or web server, redirect HTTP at that layer (Nginx: return 301 https://$host$request_uri;), and set APP_URL/base URLs to HTTPS so generated links are correct.

How the fix is verified

Re-crawl; the task closes when the HTTP URL redirects to HTTPS or is no longer in the crawl.

Sources