Web Development 12 min read

Is It Still Important to Switch to HTTPS?

Yes, if you're one of the few sites left on HTTP. What HTTPS protects, why Google cares, and the SSL, HSTS and mixed content checks most sites get wrong after switching.

From transport security to browser compatibility, switching to HTTPS still matters.

Yes, and if you're asking, there's a good chance your site, or a client's, is still on plain HTTP. HTTPS encrypts everything sent between a browser and your server, so a password, a card number or a contact form submission can't be read or altered in transit. Major browsers treat plain HTTP as insecure and flag it, Google announced HTTPS as a lightweight ranking signal back in 2014, and free certificates with automatic renewal mean there's no longer a real cost or excuse. Code23 has fitted SSL to every website we've built for years, and if you're already on HTTPS, that's not the end of the job. Most of the sites we're asked to fix aren't missing a certificate. They're missing the follow-up: mixed content warnings from old HTTP images or scripts, no HSTS header, or a certificate nobody's watching that's due to expire. That's what this piece actually covers.

Reasons to switch to HTTPS

Improved Security

This is the key reason behind choosing to switch from HTTP to HTTPS.

Providing your customers with a secure and trustworthy website is fundamental to having online success as a business.
Whether you’re running a huge eCommerce site where customers buy directly from you or a boutique brochure website where visitors are asked for little more than their email address, ensuring those processes are secure should be a priority.

The risks of an unprotected website are simple enough to understand. Without HTTPS, any data travelling between a visitor’s browser and your website can be read, intercepted or changed on the way. It’s a scary thought for many consumers and one that breeds a general state of caution when typing in personal details.

The bottom line is this: if your customers can’t trust that your website will keep their details safe, do you think they are likely to offer them to you?

Simply put, HTTPS encrypts data sent to and from your website, protecting your customers’ details and your own while they travel between browser and server.

Here are the three ways HTTPS boosts your website security:

  • HTTPS encrypts data sent to and from your website, so anyone intercepting it just gets a load of gobbledegook that they can’t decrypt. So even if they manage to intercept it, they can’t use it.
  • Your SSL certificate, the thing that enables HTTPS, lets the browser confirm it has connected to your domain rather than an impostor on the network. It doesn’t stop lookalike domains or phishing emails, so it’s one layer of protection, not the whole job.
  • HTTPS protects the integrity of data in transit, so it can’t be changed on the way without the browser noticing.

That was the tipping point. HTTPS is normal now. Running plain HTTP in 2026 puts you in a shrinking minority, and browsers make a point of flagging it.

A site still on plain HTTP stands out: browsers treat the connection as insecure, and anyone able to intercept its traffic can read or change data in transit.

All our web designs come with SSL certificates and we encourage our client to choose an HTTPS connection for their websites. And we’re in good company in making your online security one of our key website build priorities.

Google is also prioritising HTTPS and is throwing its weight behind programmes to move the whole internet to more secure and encrypted connections.

In 2014, Google called for “HTTPS everywhere” and introduced HTTPS as a lightweight ranking signal. Today its guidance treats HTTPS as a security basic rather than a route to higher rankings.

It also means an HTTPS move needs handling properly for search: redirects, canonicals and sitemaps all have to switch cleanly.

[ what https blocks ] Six risks for unencrypted traffic. HTTPS protects it in transit
None of this is exotic. It's what happens to unencrypted traffic on public wifi, a shared network or anywhere in between.

Search, migration and trust

Google introduced HTTPS as a very lightweight ranking signal in 2014, carrying less weight than content quality. Its guidance doesn\'t promise that moving to HTTPS will raise your rankings.

A properly handled migration should keep your search visibility intact, while broken redirects, canonicals or internal links can cause disruption. There is no guaranteed ranking boost (more on the migration below).

Visitors notice the difference too. Browsers treat HTTP as insecure, and the warning they show (which varies by browser and settings) is hard to miss on a contact or checkout page. (Chrome replaced its padlock with a neutral icon in 2023, but the "Not secure" label for HTTP stays.)

What does this do? It adds an additional layer of trust in the mind of your website visitor. And this could make all the difference between getting a conversion and losing it.

Major browsers flag plain HTTP as insecure, and the warnings are most prominent next to a login or payment form.

A "Not secure" warning next to your contact form puts people off right when they're deciding whether to trust you with their details. HTTPS removes that warning; it doesn't prove on its own that a site is trustworthy, but its absence is noticed.

A faster future

Google’s 2014 announcement speculated that the signal might become stronger, but current guidance does not promise a ranking gain from switching. In its original announcement Google told us:

“Over time, we may decide to strengthen [the SEO effect] because we’d like to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web”

Google Search Central Blog, 2014

That was a 2014 possibility, not a current ranking guarantee.

There's a speed reason too. Browsers only use HTTP/2 and HTTP/3 over HTTPS, so in practice HTTPS is what lets your site use them instead of the older, slower HTTP/1.1.

Want a faster-loading website with secure connections? HTTPS is foundational, alongside secure server, application and cookie configuration.

Are there any reasons not to switch to HTTPS?

There's no longer a real case against it. Free certificates, automatic renewal and hosting that includes HTTPS by default mean there's no meaningful cost or excuse left. Every site, blog included, should be on HTTPS.

That said, migrating from HTTP to HTTPS is not completely straightforward and getting the migration wrong can have a negative impact on your website’s performance.

Google offers some information on how to migrate to HTTPS and the process is outlined well here too. But if all that tech chat looks too complicated for what seems like a small change to your website (choosing the SSL certificate that’s right for you, for example), you’re far from alone.

We support businesses making the switch from HTTP to HTTPS all the time. Our specialist expertise as web hosts and developers ensures the switch to HTTPS can take place under optimal conditions.

Careful implementation reduces migration errors that can temporarily affect crawling, indexing and search visibility.

Google notes that URL migrations can cause temporary ranking fluctuations while pages are recrawled. Correct redirects and an up-to-date sitemap reduce avoidable problems, and moving during a quieter period limits disruption for visitors.

We use URL mapping, permanent redirects, updated canonicals and sitemaps, and post-launch monitoring to reduce avoidable migration disruption.

Temporary search fluctuations can occur during a migration, but HTTPS remains necessary for transport security and visitor confidence; improved rankings are not guaranteed.

How to switch to HTTPS

Most sites can switch in a day, but the order matters:

  1. Get a certificate. Many hosts include free, automatically renewing certificates, so there’s often nothing to buy.
  2. Fix mixed content. Update internal links, images and scripts to https:// so no part of the page still loads over plain HTTP.
  3. Redirect everything. Add permanent (301) redirects from every http:// address to its https:// version, page by page, not just to the homepage.
  4. Update the signals. Point canonical tags and your XML sitemap at the https:// URLs, and, if you use a URL-prefix property in Google Search Console, add the https:// version (a Domain property already covers both).
  5. Turn on HSTS last. Once every page works over HTTPS, add HSTS so browsers that have received the policy use HTTPS on later visits; first-visit protection requires HSTS preloading.

Then crawl the site to catch anything still loading over http://.

Frequently asked questions

Is it still important to switch to HTTPS in 2026?

Yes, if you’re one of the few sites left on plain HTTP. Major browsers treat HTTP as insecure, and anything submitted on an HTTP page, including passwords and card details, travels unencrypted. Google introduced HTTPS as a lightweight ranking signal in 2014, but the real reason to switch is protecting that data. Free certificates and hosting that includes SSL by default have removed the last excuse.

What is mixed content and why does it break HTTPS?

Mixed content is when a page loaded over HTTPS still pulls in an image, script or stylesheet over plain HTTP. Modern browsers generally auto-upgrade eligible image, audio and video requests and block active mixed content such as scripts and stylesheets; remaining insecure resources still need fixing. It’s the most common reason a site with a valid certificate still shows warnings, usually from an old image URL or a third-party embed nobody updated after the switch.

What is HSTS and do I need it?

HSTS (HTTP Strict Transport Security) tells browsers to only ever connect to your site over HTTPS, even if someone types or links to the HTTP version. Without it, a visitor’s first request, or one that follows an old http:// link, can go out unencrypted before your redirect kicks in, which leaves room for a downgrade. With HSTS the browser switches to HTTPS itself on later visits. It’s a small server setting, and one of the checks we run as part of our website support and maintenance.

Does moving from HTTP to HTTPS affect SEO?

A correctly implemented migration should preserve search visibility. Google introduced HTTPS as a lightweight signal in 2014, but current guidance does not promise higher rankings from the switch. A “Not secure” warning does affect how much a visitor trusts your site before they’ve read a word. Any migration carries a short-term risk if redirects aren’t handled properly, which is worth getting a developer to check rather than doing it yourself.

Next step

HTTPS isn’t the finish line. Most of the sites we’re called in to fix already have a certificate. What they’re missing is the follow-up: HSTS, mixed content cleared up, renewals nobody has to remember, and someone checking the whole thing actually works end to end.

If you’re not sure where your site stands, tell us your address and we’ll tell you what needs fixing; ongoing checks are part of our website support and maintenance service. If you’re planning a new build, we fit HTTPS, HSTS and clean redirects properly from day one, not as an afterthought. We’ve delivered 350+ projects since 2005, and we look after the sites we build.

Plan the next release

Build the next version around the result it needs to produce.

We’ll define the scope, design the journeys and build the systems behind them with one senior UK team.

James Ansell

Written by

James Ansell

Founder & Director

James founded Code23 in 2005 and leads its AI, product and engineering work across marketplaces, SaaS platforms and websites.

Related

More from the blog

Engineering deep-dives, product updates, and notes from the team.

View all posts