How to switch an e-commerce site to HTTPS
Switching to HTTPS isn't just about installing a certificate: the store also has to stop calling any resource over HTTP, and its URLs stored in the database need to reflect the new protocol. Skipping one of these steps leaves security warnings visible to visitors.
The full procedure
-
Install the SSL certificate
Most hosts offer activation of a free Let's Encrypt certificate directly from their panel, with no manual server configuration.
-
Force the HTTP-to-HTTPS redirect
A server-level redirect rule (.htaccess file for Apache, or equivalent configuration for Nginx) guarantees that no page remains reachable over unsecured HTTP.
-
Update the store's URL in its configuration
On PrestaShop, the store's URL and SSL activation are set in the shop parameters (Shop Parameters > General on 1.7 and later). On WordPress, the site address is set under Settings > General, in the WordPress Address (URL) and Site Address (URL) fields.
-
Fix mixed content
Any resource still called over HTTP (image, script, stylesheet) on a page served over HTTPS triggers a mixed-content warning in the browser. These resources are usually found in the theme, plugins, or content stored directly in the database.
-
Handle serialised data if needed
On WordPress, a simple SQL find-and-replace of http with https in the database can corrupt serialised data stored in certain columns; a dedicated tool for this replacement (such as WP-CLI's search-replace command) avoids that risk.
-
Check for the absence of browser warnings
Once the switch is done, confirm the padlock displays with no warning on the main pages, including the checkout flow.
The impact on SEO and sessions
Google treats HTTP and HTTPS as two distinct addresses. Without a 301 redirect from the old version to the new one, the site can end up with two versions indexed separately, which dilutes rankings instead of strengthening them, even though HTTPS is a factor Google weighs positively.
The protocol change can also invalidate user sessions in progress at the moment of the switch, particularly if session cookies were configured for a specific domain or protocol. Switching during a period of low traffic limits the visible impact for visitors connected at the moment of the change.
Common mistakes
- Enabling the certificate without forcing the redirect, leaving both versions of the site reachable in parallel.
- Forgetting to update the URL stored in the CMS configuration, which keeps generating internal links over HTTP.
- Running a raw SQL find-and-replace on a WordPress database without accounting for serialised data, corrupting certain settings.
- Not checking the checkout flow in particular, where mixed content can block some browsers more strictly than on other pages.
- Forgetting to renew, or to verify the automatic renewal of, the certificate, causing an abrupt security warning at expiry if the renewal fails silently.
Frequently asked questions
Can switching to HTTPS temporarily drop traffic?
Does an e-commerce store need a paid SSL certificate?
How can I check that no mixed content remains?
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.