All fix guides

Site basics (D8)

HTTPS

What this check means

This guide helps you act on one scan finding. It is not legal advice or a compliance verdict.

What to fix

Serve the scanned URL over HTTPS end-to-end with a clean redirect from HTTP.

Step-by-step fix

  1. In the host panel, install/force a TLS certificate for the domain.
  2. In Settings → General, set WordPress Address and Site Address to https://.
  3. Add a single HTTP→HTTPS redirect at the host or Cloudflare (301).
  4. Fix mixed-content assets (http:// images/scripts) so the page stays on HTTPS.

Confirm it is fixed

Re-scan the https URL and confirm D8 reports HTTPS.

Rescan this check on your site

Scan the same URL again, then compare this check with your previous report.

Run a free leak scan