> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.faaaster.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# My Faaaster site shows as "not secure"

First check the certificate status in the site's **Domains** tab, **HTTPS** column. If it's **active** but the browser reports a problem, the most frequent cause is **mixed content**: resources still loaded over `http://` on a site served over `https://`.

## 1. Is HTTPS active?

Open the site's **Domains** tab: the **HTTPS** column shows the certificate status of each domain — **active** (with its expiration date), **generating…**, **expired**, **no certificate** or **failed**. The **Recheck DNS and HTTPS** button checks this status again. When the certificate is missing or has failed, the row's **Generate certificate** or **Retry** button restarts its generation. The certificate is included in every plan.

## 2. HTTPS is active but the browser complains

In that case it's **mixed content**: the page is served over HTTPS, but it loads images, scripts or stylesheets over HTTP. The browser shows a crossed-out padlock or a warning.

These `http://` addresses usually come from the database — often after a migration or a domain change.

### Fix mixed content

There's no button in the interface for this, but **WP-CLI is installed on every site** and does the job in one command. Connect via SSH, go to `www`, then:

```bash
wp search-replace 'http://your-domain.com' 'https://your-domain.com' --all-tables --dry-run
```

The `--dry-run` option shows how many replacements would be made, without changing anything. Check the number, then run the command again without the option.

> ⚠️ **Create a backup first.** `search-replace` rewrites the database, and the operation can only be undone by restoring.

Remember the variants present in your database: with and without `www`, and the old domain if you're coming from a migration. Each one needs its own pass.

If you'd rather avoid the command line, the **Better Search Replace** plugin, installed from the WordPress admin, does the same thing with a form and a dry run.

👉 [How do I use WP-CLI?](https://help.faaaster.io/en-us/article/use-wp-cli-19wrcm0/) · [How do I back up and restore a site?](https://help.faaaster.io/en-us/article/backups-1j7rzgw/)

## 3. After a domain change

If you've just connected a new domain, give the certificate time to be issued (**generating…** in the **HTTPS** column of the **Domains** tab) and clear the site's cache with **Clear cache**.