Guide · WordPress

WordPress SSL certificate expired: what to do in the next hour

Checked against sources on 2026-09-29 · 5 min read

A client calls: their WordPress site says "Your connection is not private". Visitors leave, checkout stops, and the admin login may not load either. The fix is usually quick once you know who was supposed to renew the certificate. Finding that out is most of the work.

WordPress itself doesn't issue or renew certificates. The WordPress documentation puts it plainly: WordPress is fully compatible with HTTPS when a TLS certificate is installed and available for the web server to use. The certificate belongs to the server, the host or a CDN in front of it. So the question is never "what did WordPress do", it is "which of those renews this certificate, and why didn't it".

1. Confirm it really is the expiry

Browsers show the same scary page for several different problems. Paste the hostname into our SSL checker: it shows the expiry date, the issuer and whether the certificate matches the name. Check both the bare domain and the www name, because they can carry different certificates.

  • Expired: the date is in the past. Carry on below.
  • Wrong name: the certificate is valid but for another name, often after a domain change or a new CDN. Reissue it for the right names.
  • Not trusted: a self-signed or incomplete chain, often after a manual install. Install the full chain the CA gave you.

2. Find out who issues the certificate

The issuer and the lifetime tell you most of the story:

  • Let's Encrypt, ZeroSSL or Google Trust Services, about 90 days: issued by an automated client. That is your host's panel, cPanel's AutoSSL, a CDN, or Certbot on your own server.
  • A commercial CA (DigiCert, Sectigo, GlobalSign and others), up to 200 days: most likely bought and installed by a person, who may have left the agency.
  • Amazon or Cloudflare: managed by that provider, which renews it on its own schedule.

On shared hosting with cPanel, AutoSSL installs domain-validated certificates for you, from Let's Encrypt by default. When it stops, the cause is usually a domain that no longer points at the server, or a validation request it can't answer.

How common is each kind? In our scan of the certificates on 7,847 of the most-visited sites (the Tranco top 10,000, 28–29 September 2026), 48.8% came from a CA that is renewed automatically over ACME, and 37.5% came from a CA without automated renewal and lasted more than 90 days, the ones someone probably renews by hand. 6.2% of all certificates had 30 days or fewer left on the day we looked.

Why WordPress certificates stop renewing

  • The domain or www name moved to a new host or CDN, and the old host keeps trying to validate a name that no longer points at it.
  • A security plugin, maintenance mode or redirect rule answers the validation request with a login page or an error.
  • A certificate was bought for a client years ago and the reminder goes to someone who no longer works with them.
  • A migration copied the site but not the renewal job, so the new server never renews anything.

3. Renew it, by type

Host panel or AutoSSL. Open the hosting panel's SSL or HTTPS section and run the renewal or "reissue" there. If it fails, the panel's error usually names the domain it couldn't validate. Point that domain at the server, or remove it from the certificate, and run it again.

Certbot on your own server. Run sudo certbot renew --dry-run to see the real error, fix it, then sudo certbot renew and reload the web server. The HTTP challenge needs /.well-known/acme-challenge/ reachable on port 80 (challenge types), and WordPress security plugins, redirect rules and maintenance modes are common ways to block it. Allow that one path and try again.

A bought certificate. Generate a new key and certificate signing request, buy or reissue the certificate at the CA, and install it with the full chain. While you are there, ask whether this site could move to automated renewal instead.

A CDN in front of WordPress. If the CDN serves the certificate, renew it there. Also check the certificate between the CDN and the server: when that one expires, visitors see a CDN error page rather than a browser warning.

4. Check the site after the fix

  1. Run the SSL checker again on every name the site uses: the domain, www, and any shop or members subdomain.
  2. Load the site and the admin login in a private window. If some images or scripts still load over http, the site shows a warning even with a valid certificate; update those URLs.
  3. If the admin login loops or refuses to load, check FORCE_SSL_ADMIN in wp-config.php and the WordPress Address and Site Address settings.
  4. Write down who renews this certificate and when it expires next. That note is the difference between a five-minute fix and a lost afternoon next time.

5. Make sure you hear about it first next time

Let's Encrypt stopped sending expiry emails in June 2025, and a bought certificate's reminder goes to whoever bought it. Certificates are also getting shorter: since 15 March 2026 no public certificate may last longer than 200 days, and from 15 March 2027 the maximum is 100 days (CA/Browser Forum ballot SC-081v3). A certificate renewed by hand now needs attention a few times a year.

For a list of client sites, the 47-day readiness checker shows which of a domain's certificates renew themselves and which are renewed by hand. To be told before anything expires, ExpiryOwl checks every certificate every 6 hours and emails from 30 days before expiry; the free plan covers 5 domains. Our page for WordPress agencies shows how that looks across many client sites on different hosts.

How we measured

We took the Tranco list (ID 64X3X, generated 27 September 2026), tried www. and then the bare domain for each of the top 10,000 entries, and made one TLS connection on port 443 per name with our own checker, at most eight at a time: no web page was requested. Percentages are of the 7,847 sites where we could read a certificate. "Renewed by hand" is a heuristic: a CA without automated renewal plus a lifetime over 90 days. Large companies that automate long certificates count too, so treat it as an upper bound. We publish totals only and never name a site.

Sources

  1. WordPress developer docs: HTTPS
  2. cPanel docs: Manage AutoSSL
  3. Let's Encrypt: Challenge types
  4. Let's Encrypt: Expiration notification service has ended
  5. CA/Browser Forum Ballot SC-081v3
  6. Tranco top-sites list

FAQ

Questions

Does WordPress renew SSL certificates?

No. The certificate belongs to the web server, the hosting panel or a CDN. WordPress works over HTTPS once a certificate is installed, but something outside WordPress has to renew it.

The certificate is renewed but the WordPress site still shows a warning. Why?

Either another name (www, a subdomain) still has the old certificate, the web server hasn't reloaded, or the page loads images or scripts over http. Check every name with an SSL checker, then look for http:// URLs in the page.

How long does a certificate last now?

At most 200 days for certificates issued since 15 March 2026, and at most 100 days from 15 March 2027. Let's Encrypt certificates last 90 days, 64 days by default from 10 February 2027.

Start with five domains, free.

The free plan watches 5 domains for one client: certificates, domain registration, DNS and uptime every 15 minutes. No card, no trial clock.