A customer types your address into Chrome, and instead of a padlock they see the words “Not secure” sitting right next to your business name. Some keep going. Many do not. In a market where people are careful about scams and online payments, that one label quietly turns visitors away before they read a single word.
The frustrating part is that your site is not hacked and nothing is broken. A Not Secure warning is a trust label, not a crash. It simply tells the world the connection is not encrypted, and browsers now show it on every page that still loads over HTTP.
The good news is that this is one of the most fixable problems a website has. At ZenWeb, we clear this warning for Malaysian business sites most weeks, and the cause sits on a short list every time. This guide shows you what the warning means, why it appears, and how to remove it for good. The short video below walks through spotting the insecure content and fixing it.
Source video: Kori Ashton on YouTube
Quick Answer: The Not Secure warning means the page is loading over HTTP, so the connection between the visitor and your site is not encrypted. It is not a virus alert and it does not mean you were hacked. It is the browser telling users that data typed on this page could be read by others in transit.
Every modern browser checks one thing before it draws the address bar: is this page served over HTTPS with a valid certificate? If yes, you get the padlock. If not, you get the words “Not secure”. It is a statement about encryption, nothing more.
This matters because a warning about safety is very different from a site that will not open. If your pages do not load at all, that is a separate fault covered in our guide on a website that is down and not loading. And a Not Secure label is also different from the red full-screen “Deceptive site” screen that points to a real hack, which we cover in cleaning malware off a hacked website.
Quick Answer: A Not Secure warning on your website comes from one of five things. Common causes are no SSL certificate, a site that never redirects HTTP to HTTPS, mixed content where files still load over HTTP, an expired certificate, or a certificate for the wrong domain. The chart below shows how often we see each.
When we open up a Malaysian business site showing this warning, the cause is rarely a surprise. Here is the rough breakdown of what we find.
| Root cause | Share of cases |
|---|---|
| No SSL certificate installed | 38% |
| Site never redirects HTTP to HTTPS | 24% |
| Mixed content (some files still load over HTTP) | 18% |
| Expired or lapsed SSL certificate | 12% |
| Certificate issued for the wrong domain or www | 8% |
Source: ZenWeb client tracking across Malaysian SME sites, 2024–2026. Shares rounded.
The top cause is the plainest one: no certificate was ever installed, so the whole site runs on HTTP. Close behind is a certificate that exists but is not enforced, meaning visitors can still reach the old HTTP version. Both are quick fixes handled by our web design and maintenance team or by you, following the steps below.
Quick Answer: Every visitor who sees “Not secure” and leaves is a lead you never counted. For a Malaysian SME with steady traffic, a warning left up for a month can quietly cost thousands of ringgit in missed enquiries. It also drags on search rankings, because Google treats HTTPS as a ranking signal.
The damage is easy to miss because nobody emails to say “your padlock scared me off”. They just close the tab. The table below models how the loss builds for a site that would otherwise pick up around eighteen enquiries a month from organic visitors.
| Warning left up for | Enquiries missed | Estimated value lost |
|---|---|---|
| 1 week | ~4 | ~RM 2,000 |
| 2 weeks | ~9 | ~RM 4,500 |
| 1 month | ~18 | ~RM 9,000 |
| 3 months | ~54 | ~RM 27,000 |
Source: Illustrative scenario modeled on ZenWeb client averages (about 18 lost enquiries/month, RM 500 average lead value), Malaysia, 2024–2026. Your figures will vary.
Paid traffic makes it worse. Point ads at a page marked Not Secure and you pay for clicks that bounce on sight, and the same neglect can even get your Google Ads disapproved for a poor landing page. On top of that, Google has treated HTTPS as a ranking signal since its 2014 announcement, so an HTTP site quietly gives up a small edge in search.
Not sure how many visitors that warning has cost you?
We install the certificate, force HTTPS site-wide, and check nothing else is leaking. See our web design and maintenance service →
Quick Answer: Work in order. Install or renew the SSL certificate, update your WordPress site address to HTTPS, force a redirect from HTTP, then fix any mixed content and clear the cache. Most sites lose the Not Secure warning by the third step. You do not need to be a developer for any of this.
These steps run from the fix that solves most cases to the tidy-up that catches the rest. Stop once the padlock shows on every page.
If your site runs on a heavy page builder or handles payments, and you would rather not risk a live site, our web design and maintenance team sets this up cleanly with no downtime.
Quick Answer: If the certificate is active but one page still says Not Secure, the cause is almost always mixed content: an image, script, or embed on that page still loads over HTTP. The browser flags the whole page until every asset is served over HTTPS. Find the HTTP asset and repoint it, and the padlock returns.
This is the case that confuses most owners. The homepage is secure, but one inner page keeps showing the warning. Open your browser’s inspect tool on that page and look for a mixed content note; it points to the exact file still calling http://. Common culprits are:
A database search and replace, swapping http:// for https:// across your content, fixes the large majority of these in one pass. Take a backup first, because you are editing the database.
Quick Answer: The warning has several faces, from a quiet “Not secure” label to a full red screen that blocks the page. The severity depends on whether there is a form on the page, an expired certificate, or a self-signed one. The table below shows what each situation looks like to a visitor.
Knowing which version you have tells you how urgent the fix is, because some warnings just look bad while others stop visitors from reaching the page at all.
| Situation | What the visitor sees | How serious |
|---|---|---|
| HTTP page, no certificate | “Not secure” in the address bar | High |
| HTTP page with a form or login | Red “Not secure” warning when they type | Very high |
| HTTPS page with mixed content | Broken padlock or “Not secure” | Medium |
| Expired certificate | Full-page “Your connection is not private” | Blocks the page |
| Self-signed certificate | Full-page security warning | Blocks the page |
Source: ZenWeb client tracking across Malaysian SME sites, 2024–2026. Behaviour is typical, not guaranteed on every browser version.
The label went from optional to unavoidable in 2018, when Chrome started marking every HTTP page as Not Secure and later showed a red warning as users typed, per Google’s Chromium blog. Today the HTTPS Transparency Report shows the large majority of pages load over HTTPS, so an HTTP site stands out for the wrong reasons.
Quick Answer: Removing the Not Secure warning does more than swap a label for a padlock. It stops visitors bouncing on sight, lifts form and checkout completion, restores the HTTPS ranking signal, and keeps your ad landing pages compliant. The table below shows the typical shift on the sites we secure.
The change is felt quickly once the certificate is in and HTTPS is enforced everywhere. Here is the before-and-after we see on the Malaysian sites we repair.
| Metric | Before | After |
|---|---|---|
| Address bar | “Not secure” | Padlock, secure |
| Visitors leaving on the warning | ~1 in 5 | Near zero |
| Form and checkout completion | Baseline | +18% |
| HTTPS ranking signal | Missing | Active |
| Ad landing page status | At risk of disapproval | Compliant |
Source: ZenWeb client results before and after securing the site, Malaysia, 2024–2026. Illustrative of typical gains; completion lift varies by site.
The bounce and completion gains are what owners feel first. A padlock signals a business that takes basic care of its site, and that quiet reassurance carries through every form, checkout, and page we design.
Want the padlock back today without breaking the site?
We handle the certificate, the redirect, and the mixed content in one go. Get your site secured →
Quick Answer: Install the certificate and switch the site address yourself. Call for help when the warning stays after the basics, when a search and replace could damage the database, or when the site sells and every hour of downtime costs orders. A clean fix beats a risky one.
Plenty of this is a same-day, do-it-yourself job. But some cases are worth handing over rather than gambling with a live, revenue-earning site:
While you are in there, it is worth a wider check so one fix does not hide another problem. Our web design and maintenance service secures the site and keeps every page, form, and enquiry channel working.
A Not Secure warning looks alarming, but it follows a simple pattern. It means a page is not fully served over HTTPS, and the fix is to install or renew the certificate, force every URL to HTTPS, and clear any mixed content. Do that and the padlock returns, usually within an hour.
The payoff is trust on every page: fewer bounces, smoother forms, and a small ranking edge back in your favour. If your site still shows the warning, you can have it removed properly the first time. ZenWeb can secure it and keep it that way with an ongoing web design and maintenance plan.
Seeing “Not secure” on your site? Let’s remove it fast.
Book a free 30-minute session — we’ll check your certificate, force HTTPS across the whole site, clear any mixed content, and get the padlock back with a plan to keep it there.
Your website says Not Secure because the page is loading over HTTP instead of HTTPS, so the connection is not encrypted. Usually there is no SSL certificate, it has expired, or a few files still load over HTTP. It does not mean you were hacked; it means the encryption is missing or incomplete.
Install or renew an SSL certificate from your hosting dashboard, change your WordPress site address to https://, then force a redirect from HTTP to HTTPS. Fix any remaining mixed content and clear your cache. Most sites lose the Not Secure warning after the certificate is active and HTTPS is enforced site-wide.
That is almost always mixed content. The certificate is fine, but one image, script, or embed on that page still loads over HTTP, so the browser flags the whole page. Open the inspect tool to find the HTTP asset, repoint it to HTTPS, and the padlock returns.
Yes, a little. Google has treated HTTPS as a ranking signal since 2014, so an HTTP site gives up a small edge. The bigger cost is trust: visitors who see Not Secure often leave before reading anything, which raises your bounce rate and quietly lowers conversions.
Often it is free. Most Malaysian hosts include a free Let’s Encrypt SSL certificate, so the fix is activating it and forcing HTTPS rather than buying anything. A paid certificate is only needed for special cases. If the site is complex or takes payments, professional help keeps the switch safe.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Online