At checkout, many hosts offer a paid SSL certificate as an add-on, sometimes with warnings about security and trust. For the vast majority of websites, you don’t need it. A free certificate gives the same encryption, and almost every reputable host includes one.
Use the free SSL certificate your host provides. Pay for one only if a client, bank or compliance rule specifically asks for an organization-validated certificate.
What SSL and HTTPS are
SSL (strictly speaking, its modern successor TLS) encrypts the connection between a visitor’s browser and your server. When it’s active, your address starts with https and browsers show a padlock or similar icon. Without it, browsers label your site “Not secure”, and anything typed into a form travels in plain text.
A certificate is the file that makes this work. It proves to browsers that the server really belongs to your domain. Every site needs one now, not just shops: search engines favor https, and visitors are wary of the warning.
Free certificates
Let’s Encrypt, a nonprofit certificate authority, made free certificates the norm. Most hosts now issue a Let’s Encrypt certificate or a similar free one automatically and renew it in the background, so there’s nothing for you to manage. Cloudflare also provides free certificates if you route your site through it.
These are domain-validated (DV) certificates. They confirm you control the domain, and they use the same strength of encryption as paid ones. For blogs, business sites and online stores using a standard payment provider, a DV certificate is all you need. If your current host doesn’t include one, that alone is a reason to look at our best shared hosting picks.
When paid SSL makes sense
Paid certificates come in a few kinds, and only some offer anything a free one doesn’t:
- Paid DV certificates: the same validation level as free ones. Usually pointless unless you want a vendor’s support or warranty terms.
- Organization validated (OV): the certificate authority checks that your organization is real and includes its name in the certificate details. Some corporate, government or financial partners require this.
- Extended validation (EV): a stricter organization check. Browsers no longer show the company name prominently in the address bar, so the visible benefit is small. Mostly bought for policy reasons.
Wildcard certificates, which cover every subdomain, used to be a reason to pay. Free wildcard certificates exist too now, though how easy they are to set up depends on your host. If a hosting provider can’t give you SSL on a subdomain for free, that’s worth asking about.
How to check yours
- Visit your site with https:// in front of the address and check that no warning appears.
- Click the padlock or site-information icon in the address bar to see who issued the certificate and when it expires.
- Try the plain http:// address too. It should redirect to https automatically.
- Check both the www and non-www versions of your domain.
- In your host’s control panel, confirm auto-renewal is on. Free certificates are short-lived and depend on it.
Free online SSL checkers can also test your setup in more detail, including the certificate chain and protocol versions.
If the certificate is missing or shows an error, the cause is usually DNS. Hosts can only issue a free certificate once your domain points at their server, so a recently moved or newly registered domain may need a few hours. If it still fails after that, open a support chat and ask them to reissue it. That’s a routine request, and it shouldn’t cost anything.
Fixing mixed content
The most common problem after switching to https is mixed content: the page loads over https, but some images, scripts or stylesheets still load over http. Browsers then show a broken or warning padlock, or block the files completely. It’s especially common on older WordPress sites.
- Update your site address. In WordPress, go to Settings, then General, and make sure both address fields start with https.
- Update old links in the database. Use a search-and-replace plugin to change http://yourdomain.com to https://yourdomain.com. Back up first.
- Check theme and plugin settings. Logos, background images and custom code sometimes have hard-coded http links.
- Find stragglers. Your browser’s developer console lists any file still loading over http.
- Clear caches. Purge your caching plugin and any CDN so visitors get the fixed pages.
A plugin that forces https can paper over problems quickly, but fixing the links themselves is cleaner and avoids an extra plugin. If you’re setting up a new site, our WordPress on Hostinger walkthrough covers SSL as part of the setup.
Upsells to ignore
- Paid DV certificates sold as “more secure” than the free one. The encryption is the same.
- Site seals and trust badges. Visitors rarely notice them.
- Large “warranties”. They cover narrow certificate failures, not hacks or data breaches.
- Paid installation of a certificate your host should install for free.
If a host only offers SSL as a paid extra, treat it as a red flag. It’s one of the points in our hosting checklist, and a sign the plan may hide other costs too.
FAQ
Is free SSL safe enough for an online store?
Yes. The encryption is the same as on paid certificates. Card details are normally handled by your payment provider, which has its own security requirements.
Why does my free certificate expire so quickly?
Free certificates are deliberately short-lived and renewed automatically by your host. If one expires, the auto-renewal failed, often because DNS changed. Your host’s support can reissue it.
Does SSL help SEO?
Google treats https as a small ranking signal, and browsers warn visitors away from sites without it. Content still matters far more, but there’s no reason to run without SSL.