25 August 2026 · 5 min read
The quiet cost of a website with no SSL certificate
A website with no SSL certificate shows a not secure warning before a visitor reads a word. What causes it, what it costs a local business, and how to fix it.
A website with no SSL certificate announces itself before a visitor reads a single word of the page. Every major browser now shows some version of a “not secure” label in the address bar the moment a site is served over plain HTTP instead of HTTPS. For a plumber in Warrington or a beauty salon in Didsbury, that label sits right next to their business name on every single visit, and most owners have no idea it is there because they never look at their own site through a stranger's browser.
What the warning actually shows
HTTPS means the connection between a visitor's browser and the site's server is encrypted, using a certificate the site owner has installed to prove the domain is what it claims to be. Without that certificate, the browser has no way to guarantee the page hasn't been tampered with in transit, so it says so. Chrome and Edge show “Not secure” directly in the address bar. Safari shows a crossed-out padlock. Firefox flags any page with a form as insecure the moment someone clicks into a field. None of this requires the visitor to click anything or dig into settings. It is the first thing they see, ahead of the logo, the opening hours, or the phone number.
How a site ends up without one
It is rarely a decision anyone made on purpose. Certificates used to cost money and take technical know-how to install, so a site built eight or nine years ago and never touched since may simply predate the point where HTTPS became the default. Some hosting packages still don't provision a free certificate automatically, and a business owner who set the site up themselves through a cheap hosting deal can go years without anyone flagging the gap. A rebuild that moved to a new host without carrying the certificate setup across is another common route, quiet enough that nobody notices until a customer mentions the browser warning, which most customers never bother to do. They just leave.
What it costs, and what it doesn't
It is worth being precise here rather than dramatic. A missing certificate does not usually stop a site loading, and most visitors will still see the homepage content behind the warning. What it genuinely damages is trust at the exact moment someone is deciding whether to fill in a contact form, book online or ring the number on the page. A browser telling a visitor a site is “not secure” right as they're about to type their name, phone number and job details into a form is a bad moment for that warning to appear, and some share of visitors will simply back out rather than push past it. It also affects how search engines treat the site, since HTTPS has been a ranking signal for years, on top of the trust problem rather than instead of it. There is no reliable public figure for how many enquiries this costs any one business, and anyone quoting one is guessing, but the mechanism, warning at the point of highest intent, followed by hesitation, is straightforward enough not to need a statistic to make the point.
Fixing it is rarely the hard part
The good news for anyone pitching this as a fix rather than just flagging it is that resolving a missing certificate is usually quick and cheap. Most modern hosting includes free, auto-renewing certificates through Let's Encrypt, and turning it on is often a single setting rather than a technical project. The harder cases are older sites on legacy hosting that doesn't support it at all, where the honest answer is that the certificate problem is a symptom of a hosting problem, and worth mentioning alongside whatever else that old setup is holding back, covered in more detail in reading the signs of a website nobody maintains. Either way, this is one of the easier wins to offer a prospect: a small, well-defined fix with a visible before-and-after, rather than a vague promise to “improve the website”.
Checking it takes seconds
Confirming whether a site has the problem doesn't need any tooling. Loading the site and looking at the address bar is enough: a padlock or a plain web address means it's fine, a “Not secure” label or a crossed-out padlock means it isn't. It is one line on a wider check, alongside things like page speed, mobile layout and whether the contact form actually works, covered fully in a website audit checklist for local business sites. Running through that fuller list on any prospect turns up a missing certificate alongside whatever else is wrong, rather than treating it as a one-off thing to remember to check.
Spotting it across a lot of prospects at once
Checking one site by eye takes seconds. Checking it across every plumber, joiner and salon in a town, alongside speed, mobile friendliness and everything else worth knowing before you email someone, is where doing it by hand starts to drag. Patchscout audits SSL status automatically as part of every site it crawls, alongside speed, mobile layout and the rest of the checks that make up a proper audit, so a missing certificate shows up as one line in a report rather than something you have to spot yourself on a site you've never seen before. The three free searches at app.patchscout.co.uk/signup are enough to run a trade and town you already know and see how many sites are quietly showing that warning to their own customers.