Fix this
No lock icon, no customer
No lock icon, no customer. That is the whole article, plus the boring mechanics. A browser that says “Not secure” is a closed door. People leave. They should. They were about to type a name, a phone, maybe a card. The padlock is how the browser says the trip from their phone to your server is encrypted. It is not a prize. It is not an upsell. It is HTTPS — a certificate on the host you actually use.
Shops still launch on plain HTTP because a builder skipped it, a certificate expired, the domain points at the old server, or someone paid a registrar for a “security” add-on that never attached. The page can look finished and still fail in five seconds. We see it on Wix leftovers, on forgotten WordPress, on a cousin’s 2017 special. Fix the lock before you buy a rebrand. A prettier warning is still a warning.
Cheap Fast Websites sells a standard marketing site for $1,000, or $500* if you pay in full by September 30, 2026. Hosting setup on that job includes the certificate so the padlock shows. We do not sell the lock as a separate product with a scary name. If your host let it lapse, that is a host ticket, not a new logo.
What the lock actually is
HTTPS is HTTP plus TLS. The certificate proves the browser is talking to the machine that is allowed to answer for yourname.com, and the traffic is encrypted in transit. Let’s Encrypt made the certificate free on most hosts. Bluehost and everyone serious can issue one. You still have to turn it on, attach it to the name, and redirect http:// to https:// so nobody lands on the old door.
The lock is not a ranking prize. Google has treated HTTPS as a small signal for years. That is not “we will get you to #1.” Basic SEO on a site here is a title, a meta description, and Open Graph. The lock is hygiene. It sits next to a working form and a tap-to-call number. Miss it and the rest of the page does not get read.
The lock is also not a guarantee that the business is honest. Scam sites have certificates. A padlock means the pipe is encrypted, not that the plumber is licensed. Do not promise customers otherwise. Do not buy a $200 “security seal” gif to paste in the footer. Browsers already show the lock. A clip-art badge next to it looks like 2009.
- No padlock / “Not secure.” Certificate missing, expired, or the page is still on http://.
- Name mismatch. The cert is for www and the customer hit the apex, or the other way around. Or it is still the builder’s subdomain.
- Mixed content. The page is HTTPS but an image or script loads over HTTP. Browsers complain. Forms feel cursed.
- Redirect loops. Host SSL plus a plugin plus a CDN, all fighting. The lock never settles.
- The domain points at the old box. You installed SSL on Bluehost and DNS still aims at Wix. The customer sees whatever the old box is doing.
| Symptom | What it usually is | What to do |
|---|---|---|
| Browser interstitial, big warning | No cert, expired cert, or a name mismatch | Issue or renew SSL on the host that actually answers |
| “Not secure” in the URL bar, page still loads | HTTP, or mixed content | Force HTTPS, fix the http:// assets |
| Lock on desktop, warning on phone | Cached DNS, or you tested wifi vs cellular at the wrong name | Test the live name on cellular, both www and apex |
| Form works, browser still nags | You fixed the page, not the redirect | Send all http:// traffic to https:// |
| You paid a registrar for “security” | Often a badge or a scanner, not the cert | Read the invoice. Turn on SSL at the host. |
What a job here includes
A standard marketing site: custom layout, your photos, contact path, basic SEO tags, hosting setup, help pointing the domain, one round of changes. Most finish in under 72 hours when the brief is clear. The lock is part of hosting setup. You still click at the registrar. DNS can take minutes or a chunk of a day. We can be done on our side and still wait on nameservers. The clock on the build is the brief. The clock on the padlock at yourname.com is DNS plus the host’s certificate issuance.
It is not a cart, an app, or a members area at this price. Those get a quote. It is not a malware cleanup product. If the old WordPress is infected, say so. A brochure rebuild on a clean host is often cheaper than another year of “we should update PHP.” We do not promise rankings. We do not sell a national prize. We do not paste a fake Norton-style badge on the footer and call it security.
$100 down starts the $1,000 job. That is not the sale. $500 is pay-in-full by September 30, 2026 only. If you only need a single scroll with hours and a phone, the $27 one-page still needs a lock. You host it, or +$27 lifetime on our server ($54), and SSL still has to be on. A cheap page with a browser warning is not cheap. It is closed.
Do not confuse the lock with the rest of the bones
HTTPS will not fix a form that 404s. It will not make a photo of a phone number tappable. It will not replace stock handshakes with a picture of your truck. Those failures live in the boring list. The lock is one item. Pass it, then look at the others. Run the parked-car test on cellular: lock, tap-to-call, form, real photos. Four yeses and you may only need a patch. Three nos and a builder you cannot export, and you need a rebuild.
Look at live work if you want pages that load with a padlock and a phone. Dodo, Pets Helping Pets, Tampa’s Best DJ, LazerMerch, petcalendar.pet, US Helping the World — this shop’s own sites, not fake client revenue. Labeled SAMPLE pages for trades sit at /examples/. Worldwide, 24/7. Phone 813-451-2204. Forms notify tampasbestdj@gmail.com.
If you already have a URL, paste it. The check will tell you whether the basics a customer notices include the warning. If the only problem is an expired certificate on a host you control, fix that this afternoon and keep the site. Do not pay $500* for a lock you can turn on in the host panel. If the site is a rental with no keys, the lock is a reason to leave, not a reason to buy another year of the builder’s “security” upsell.