# How to switch an e-commerce site to HTTPS

> Switching to HTTPS isn't just about installing a certificate: the store also has to stop calling any resource over HTTP, and its URLs stored in the database need to reflect the new protocol. Skipping one of these steps leaves security warnings visible to visitors.

- Source canonique : [https://allaux.fr/en/guides/passer-site-en-https](https://allaux.fr/en/guides/passer-site-en-https)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Install an SSL certificate (often free via Let's Encrypt through the host), force all HTTP traffic to redirect to HTTPS, then update the store's URL in its configuration so resources and internal links get generated over HTTPS.

## The full procedure

1. **Install the SSL certificate** — Most hosts offer activation of a free Let's Encrypt certificate directly from their panel, with no manual server configuration.
2. **Force the HTTP-to-HTTPS redirect** — A server-level redirect rule (.htaccess file for Apache, or equivalent configuration for Nginx) guarantees that no page remains reachable over unsecured HTTP.
3. **Update the store's URL in its configuration** — On PrestaShop, the store's URL and SSL activation are set in the shop parameters (Shop Parameters > General on 1.7 and later). On WordPress, the site address is set under Settings > General, in the WordPress Address (URL) and Site Address (URL) fields.
4. **Fix mixed content** — Any resource still called over HTTP (image, script, stylesheet) on a page served over HTTPS triggers a mixed-content warning in the browser. These resources are usually found in the theme, plugins, or content stored directly in the database.
5. **Handle serialised data if needed** — On WordPress, a simple SQL find-and-replace of http with https in the database can corrupt serialised data stored in certain columns; a dedicated tool for this replacement (such as WP-CLI's search-replace command) avoids that risk.
6. **Check for the absence of browser warnings** — Once the switch is done, confirm the padlock displays with no warning on the main pages, including the checkout flow.

## The impact on SEO and sessions

Google treats HTTP and HTTPS as two distinct addresses. Without a 301 redirect from the old version to the new one, the site can end up with two versions indexed separately, which dilutes rankings instead of strengthening them, even though HTTPS is a factor Google weighs positively.

The protocol change can also invalidate user sessions in progress at the moment of the switch, particularly if session cookies were configured for a specific domain or protocol. Switching during a period of low traffic limits the visible impact for visitors connected at the moment of the change.

## Common mistakes

- Enabling the certificate without forcing the redirect, leaving both versions of the site reachable in parallel.
- Forgetting to update the URL stored in the CMS configuration, which keeps generating internal links over HTTP.
- Running a raw SQL find-and-replace on a WordPress database without accounting for serialised data, corrupting certain settings.
- Not checking the checkout flow in particular, where mixed content can block some browsers more strictly than on other pages.
- Forgetting to renew, or to verify the automatic renewal of, the certificate, causing an abrupt security warning at expiry if the renewal fails silently.

## HSTS, a protection to enable cautiously

> The HSTS header tells the browser to never again attempt to reach the site over HTTP, even if a visitor deliberately types that address. Useful once HTTPS is stable, it's risky to enable too early: a certificate problem afterwards would make the site unreachable for visitors who already have it cached, until the header expires.

## FAQ

### Can switching to HTTPS temporarily drop traffic?

A slight wobble is possible while search engines take the redirects into account, but a switch carried out correctly with clean 301 redirects doesn't cause any lasting loss.

### Does an e-commerce store need a paid SSL certificate?

A free certificate such as Let's Encrypt offers the same level of encryption as a paid one for everyday use. Paid certificates sometimes add commercial guarantees or stronger identity validation, without changing the technical security of the encryption itself.

### How can I check that no mixed content remains?

The browser's developer tools flag resources loaded over HTTP on an HTTPS page in their console. Systematically checking the main pages before going live avoids unpleasant surprises.
