Short answer
Usually mixed content: the page loads over HTTPS but pulls in an image, stylesheet or script over plain HTTP, so the browser downgrades the padlock. Find those references and change them to
https://.Your browser’s developer console lists every mixed-content item by name, which is much faster than guessing. On WordPress, the usual culprits are hard-coded image URLs in old posts and a site address still set to http:// in Settings.
Learn more
- How to fix mixed content warningsWhy a site on HTTPS still shows ‘not fully secure’, how to find the insecure images, scripts and styles, and how to fix them for good.
- “Your connection is not private” on your websiteDecode browser certificate errors — NET::ERR_CERT_COMMON_NAME_INVALID, DATE_INVALID, AUTHORITY_INVALID — and fix the cause on your site.
- How to force HTTPS (redirect HTTP to HTTPS)Send every visitor to the secure version of your site with an .htaccess rule or WordPress settings, without creating a redirect loop.