All posts
September 2014·6 min read

Should your WordPress site use HTTPS?

Google announced in August 2014 that HTTPS would be used as a ranking signal. SSL certificates still cost money and require configuration. Here's an honest look at whether it's worth it.

What changed in August 2014

In August 2014, Google's Webmaster Central blog announced that HTTPS would be used as a ranking signal in its search algorithm. The announcement was measured — they described it as a "lightweight" signal affecting less than 1% of queries — but it opened a conversation that the industry had been approaching slowly for years.

For most small business WordPress sites in 2014, SSL was something you thought about if you were accepting payments online. For everyone else, it was an optional extra that came with cost and complexity that didn't seem worth it. Google's announcement changed the calculus.

The state of SSL in 2014

Getting SSL on a website in 2014 meant purchasing a certificate from a Certificate Authority — Comodo, GeoTrust, Symantec, and others. Prices ranged from around $10/year for a basic domain-validated certificate to hundreds of dollars annually for extended validation certificates with the green padlock and company name.

Installation required technical steps: generating a certificate signing request, submitting it to the CA, waiting for validation, downloading the certificate files, and installing them on your server or through your hosting control panel. For sites on shared hosting, this often meant a support ticket and a wait. Let's Encrypt, which would provide free automated certificates, didn't exist yet — it wouldn't launch until 2015.

The actual ranking impact

Google was careful to describe the initial HTTPS signal as minor. Independent analysis in the months following the announcement found correlation between HTTPS and better rankings, but disentangling the SSL signal from other factors — site quality, content, authority — proved difficult.

The honest assessment in late 2014: switching to HTTPS probably won't dramatically move your rankings by itself. But Google explicitly stated they intended to strengthen the signal over time, and the direction was clear. SSL was becoming a baseline expectation, not a premium option.

The real reasons to use HTTPS

The SEO argument is actually secondary. The substantive reasons for HTTPS:

  • Data in transit is encrypted. Without HTTPS, any data submitted through your site's forms — contact details, enquiry content, login credentials — is transmitted in plaintext. Anyone positioned between your visitor and your server can read it. On public WiFi networks, this is a realistic threat.
  • Visitor trust. Browsers were increasingly showing padlock indicators (or their absence) prominently. A site without SSL was starting to carry an implicit "not secure" signal to technically aware visitors.
  • If you're taking payments, it's non-negotiable. PCI DSS compliance requires HTTPS for any page that handles payment card data. This isn't optional.

WordPress-specific considerations

Switching an existing WordPress site to HTTPS involves more than just installing a certificate. WordPress stores your site's URL in the database, and any hardcoded HTTP URLs in your content will generate mixed-content warnings (the padlock disappearing) even after SSL is active.

After switching, you need to:

  • Update WordPress's siteurl and home settings to https://
  • Run a search-replace in the database to update hardcoded HTTP URLs in content and widget settings
  • Set up HTTP to HTTPS redirects so old links and bookmarks still work
  • Update your Google Search Console property to the HTTPS version

The verdict for 2014

For a business site: yes, move to HTTPS. The ranking signal will only get stronger, the browser UX is moving toward marking non-HTTPS sites visibly, and the cost of a basic SSL certificate is a one-off annual expense that's hard to justify not paying. The migration work is a few hours on a straightforward WordPress site.

For a personal or low-traffic site: the case is weaker but the direction is clear. SSL is becoming a baseline, not a differentiator. The question isn't whether to move to HTTPS, it's when.


At DownUnder WP, SSL via Let's Encrypt is automatic for every site. When your domain's DNS is pointing to your server, the certificate issues and renews without any action from you. No cost, no configuration, no expiry to track.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.