Manual
Product site My Page

SSL / HTTPS

Watch your SSL certificate every day and get notified before it expires, and switch an http site to HTTPS after checking it's safe

Watch certificate expiry and help switch to HTTPS

"Sorabun > Security / Speed > SSL / HTTPS" watches your SSL certificate every day and switches sites still on http to HTTPS (Pro, administrators only).

Sorabun doesn't issue certificates. Even when a certificate can be obtained, installing it on the web server is a server-side task, and most hosting plans don't let a plugin do it. Major Japanese hosts such as Xserver, ConoHa WING, Sakura, and Lolipop offer free SSL with automatic renewal from their control panels. Please issue the certificate there.

No AI is used, so there are no AI costs.

1. Watch the SSL certificate

On https sites, the certificate is read once a day. "Check now" on the screen reads it right away.

LabelMeaning
ValidNo problems
Expiring soonFewer than 14 days until expiry
About to expireFewer than 3 days until expiry
ExpiredReaders' browsers show "Not secure"
Wrong domainThe certificate doesn't cover this site's domain (with or without www is a common cause)
Untrusted certificateSelf-signed, a missing intermediate certificate, and so on
Can't open over httpsSSL isn't set up for this domain

The expiry date, issuer, covered domains, and whether browsers trust it are shown too.

You're notified 14 days and 3 days before expiry, and when the certificate expires, covers the wrong domain, or becomes untrusted (each notice only once). Notices go to the email, Slack, or Chatwork set up in Notifications, or to the administrator's email if none is set up. Free SSL from your host normally renews automatically before expiry. If you get a notice, check in your hosting control panel that automatic renewal hasn't stopped.

2. Switch to HTTPS (sites still on http)

Press "Switch to HTTPS" and Sorabun checks two things before changing the site URLs (WordPress Address and Site Address) to https. If either can't be confirmed, nothing is switched.

  • The certificate is valid, covers this domain, and is trusted by browsers
  • The site opens over https

Switching without a certificate can lock you out of the admin screen. These checks prevent that.

After switching, log in again on the https login screen. The setting that fixes your own site's http:// images and links at display time is turned on automatically.

To switch back

If you ever can't log in, add define( 'WP_HOME', 'http://your-domain' ); and define( 'WP_SITEURL', 'http://your-domain' ); to wp-config.php to return to http. If your site URLs are set by WP_HOME and WP_SITEURL in wp-config.php, the screen can't switch them. Change http:// to https:// in wp-config.php instead.

Mixed content (http:// loaded on https pages)

When an https page loads images or other files over http://, browsers block them and the padlock disappears. The screen shows how many articles contain your own site's http:// URLs, and how many load files over http:// from other sites (with those sites' names).

  • Your own site's http:// is delivered as https to readers with the "fix at display time" setting. "Rewrite article bodies" also rewrites the stored text (your own site's URLs only; no revisions are created; take a backup first to be safe)
  • Other sites' http:// isn't fixed automatically, because they may not work over https. Use "Replace URL" in the Link Checker to change them to https URLs

Settings

SettingDefaultMeaning
Redirect http visitors to httpsOffUse this when your server doesn't redirect. The screen shows whether the server already does
Fix your own http:// at display timeOff (on after switching)Readers don't see mixed content
Send HSTSOffTells browsers to open this site only over https for one year
Notify about certificate expiryOnNotifies 14 and 3 days before expiry, and when it expires or breaks

Before turning on the redirect, Sorabun opens the site over https and checks that it isn't redirected again. If something in front of the server (such as a CDN's "Flexible SSL") passes https visits to the server as http, the redirect would loop and the site would stop opening. If that risk exists, the redirect isn't turned on. Form submissions (POST) aren't redirected, because redirecting them would lose their contents.

Be careful with HSTS

If the certificate expires or you go back to http after turning on HSTS, readers can't open the site (browsers remember it for a year). Turn it on only after confirming that automatic certificate renewal is reliable.