Site basics (D8)
HTTPS
This guide helps you act on one scan finding. It is not legal advice or a compliance verdict.
What to fix
Serve the scanned URL over HTTPS end-to-end with a clean redirect from HTTP.
Step-by-step fix
- In the host panel, install/force a TLS certificate for the domain.
- In Settings → General, set WordPress Address and Site Address to https://.
- Add a single HTTP→HTTPS redirect at the host or Cloudflare (301).
- Fix mixed-content assets (http:// images/scripts) so the page stays on HTTPS.
Confirm it is fixed
Re-scan the https URL and confirm D8 reports HTTPS.
Rescan this check on your site
Scan the same URL again, then compare this check with your previous report.
Run a free leak scan