Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Redirect HTTP to HTTPS in WordPress

This guide shows how to make every visitor use the safe HTTPS version of your WordPress site.

WordPress2 min read13 steps8 screenshots

What are HTTP and HTTPS?

HTTP is the way browsers and websites talk. HTTPS is the same thing, but scrambled so others cannot read it. You see a padlock in the browser bar. To use HTTPS, you need an SSL certificate. This is a small file that proves your site is real. Check your cPanel or ask Hostvento support to get one installed.

A redirect sends visitors from one address to another automatically. Here it sends http:// visitors to https://.

Take a backup of your site before changing anything.

Step 1: check that SSL works

  1. Type https://yourdomain.com in your browser.
  2. If you see a padlock, SSL is working. If you see a warning, fix SSL first.

Step 2: change the WordPress addresses

  1. Log in to the WordPress dashboard.
    Screenshot: Log in to the WordPress dashboard.
  2. Go to Settings, then General.
  3. Change both WordPress Address (URL) and Site Address (URL) to start with https://.
    Screenshot: Change both WordPress Address (URL) and Site Address (URL) to start with https:// .
    Screenshot: Change both WordPress Address (URL) and Site Address (URL) to start with https:// .
  4. Click Save Changes. You may need to log in again.

Step 3: add the redirect in .htaccess

The .htaccess file holds rules for your site.

  1. Log in to cPanel and open File Manager.
    Screenshot: Log in to cPanel and open File Manager .
  2. Go to the folder of your site, often public_html.
  3. Click Settings and tick Show Hidden Files.
  4. Right-click .htaccess and choose Edit.
    Screenshot: Right-click .htaccess and choose Edit .
  5. Add these lines at the very top.
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [L,R=301]

These lines check if the visit is not secure. If so, they send it to the HTTPS address for good.

  1. Click Save Changes.
    Screenshot: Click Save Changes .
    Screenshot: Click Save Changes .
  2. Visit the http:// address. It should switch to https://.

Step 4: fix mixed content

Mixed content means a secure page loads a picture over plain HTTP. This removes the padlock. A plugin such as Really Simple SSL can fix it. Search for it under Plugins, then Add New.

Screenshot: Mixed content means a secure page loads a picture over plain HTTP. This removes the padloc
Tip: If you see a redirect loop, clear your browser cache and check that the WordPress addresses use https://.

Quick recap

  • Install and test SSL first.
  • Change both addresses to https:// in WordPress.
  • Add the redirect rules to .htaccess.
  • Fix mixed content if the padlock is missing.