Infrastructure
The Chrome HTTPS Warning Your New Customers See and You Never Will

Chrome 154 reached the stable channel on 22 September 2026, according to Google's own release calendar, and it is the version Google named for a change it has been signalling since 2022. A setting called Always Use Secure Connections is now switched on by default. In practice, Chrome tries every address over HTTPS first, and if a public website cannot answer securely, the browser stops and asks the visitor whether they really want to continue. It does that before it shows a single pixel of the page.
That is a different animal from the small grey "Not secure" label most business owners have learned to ignore. A label sits in the address bar while your page loads behind it. This is a full-page interruption with a Back button on it.
There is a twist that makes it easy to miss. In its announcement of HTTPS by default, the Chrome Security Team says Chrome will not keep warning about sites a person visits regularly, only new or not recently visited ones. You visit your own website every week. So do your regular customers. The people who get the warning are the ones you have never met: the first-time visitor from a Google search, a WhatsApp recommendation, a leaflet through the door. Exactly the people your marketing exists to reach.
This piece is built as a reference. It covers what changed, where HTTP still hides in a typical small business web presence, how to audit it in about half an hour, and what to fix first.
What Chrome 154 Actually Changed
From a label to an interruption
Some history helps. Google launched Always Use Secure Connections as an opt-in setting in 2022. With Chrome 147 in April 2026, it switched on for people who had opted into Enhanced Safe Browsing, a group Google puts at over a billion users. Chrome 154 extends the default to everyone else.
Once it is on, Chrome upgrades every link to HTTPS behind the scenes. If the secure version loads, nobody notices anything. When it does not, Chrome warns before loading the page. Google's own example of the dialog tells the visitor that attackers could see or change information sent to or from the site, then offers two choices: continue to the site, or go back.
Think about which button a stranger presses when the first thing your business says to them is a security warning. They have no loyalty to you yet, and there are three other results sitting on the same Google page. Back is the easy choice, and you will never know they were there.
Who gets warned, and how often
Google has been careful about volume. The Chrome Security Team reported that during an earlier experiment, the median user saw fewer than one of these warnings a week, and even heavy browsers at the 95th percentile saw fewer than three. Warnings made up well under 3% of navigations, a share Google expects to keep falling as the remaining HTTP sites migrate.
I read those numbers two ways. For the web as a whole, this is a gentle nudge. For your business, if your site happens to be one of the stragglers, the warning is not rare at all. It is every new visitor, every time.
Two other limits matter:
- Public sites only. Private addresses, such as an office router page or a company intranet, are excluded from the default. Your business website is public, so it is in scope.
- Bypassable. Visitors can click through, and anyone can switch the setting off in Chrome's security settings, as Google's Chrome help page explains. Very few people will bother for a business they have never heard of.
One note on timing. Chrome rolls new versions out in stages, and Google's calendar now shows a new stable version roughly every fortnight, so some of your visitors may be a version or two behind. That buys you days, not months.
How many sites does this touch?
W3Techs reported in October 2026 that roughly nine in ten websites now use HTTPS as their default protocol. That leaves something like one in ten that do not, though I would take that figure with a pinch of salt. Plenty of those sites support HTTPS perfectly well and simply never redirect visitors to it, and Chrome upgrades those quietly with no warning at all. The sites that get caught are the ones where the secure version does not exist or does not work.
Google's own transparency figures tell the same story from the browser side. HTTPS climbed from somewhere between 30% and 45% of Chrome page loads in 2015 to the mid-to-high nineties by around 2020, and then it stopped climbing. That plateau is the long tail Chrome 154 is aimed at. It is made up of old, forgotten and half-migrated addresses, and small businesses own a surprising number of them.

Where HTTP Still Hides in a Small Business Web Presence
When we migrate sites onto our platform, the main website is rarely what is still on plain HTTP. It is almost always an address the owner forgot they had. These are the six places it turns up most often, and whether a first-time visitor to each one will now be interrupted.
| Where HTTP hides | Who usually set it up | Will a first-time visitor be warned? |
|---|---|---|
| The main website, no certificate at all | An old host or agency | Yes |
| An old subdomain (shop., book., menu.) | A previous supplier | Yes |
| A second domain or campaign site | You, years ago | Yes, if its forwarding has no HTTPS |
| A third-party booking or ordering page | A software provider | Yes, if the provider has no HTTPS |
| An HTTPS version that is broken | Nobody, it lapsed | Yes, or a certificate error |
| Old http:// links on print and listings | You or a designer | No, if the redirect works |
1. The main website with no certificate at all
This is the obvious one, and it is rarer than it used to be, but it still turns up. Typically it is a site an agency built years ago, parked on budget hosting where SSL was sold as an extra, and never touched since because every small change meant an email to the agency and an hourly invoice back. The owner has seen the "Not secure" label so often it has become wallpaper.
From now on, every new visitor to that site meets the full-page warning instead. A certificate fixes it, and it should cost nothing: Let's Encrypt has been issuing free certificates for years, and a host still charging extra for basic SSL is charging for something most of the industry includes as standard.
A related case is worth separating out. If your site does have a certificate but Chrome still labels certain pages "Not secure", that is usually mixed content, a different problem with a different fix. Mixed content degrades the padlock. A missing certificate now blocks the door.
2. The forgotten subdomain
This is the one that catches people. Your main site might be properly secured at www.yourbusiness.ie, while shop.yourbusiness.ie or book.yourbusiness.ie still points at a system a previous supplier set up years ago. The certificate on your main site does not cover that subdomain unless somebody arranged it deliberately.
Consider a typical case, illustrative rather than any one business. An Offaly driving instructor has a perfectly good main site, but the Book a Lesson button leads to an old HTTP subdomain run by a booking reseller. A parent, sent the link in a family WhatsApp group, taps it on a Sunday evening, gets a security warning on the exact page where they were about to type their teenager's name and mobile number, and taps Back. The instructor never sees that warning, because their own phone has opened the booking page a hundred times. All they notice is that website bookings have gone quiet, and they put it down to the time of year.
3. The second domain nobody remembers
Plenty of businesses register an extra domain for a campaign, a product line or a rebrand, point it at a holding page, and forget about it. Those addresses often sit on a registrar's free parking or forwarding service, and not every forwarding service answers on HTTPS. If that domain is printed on old stock or still turns up in search, it now greets people with a warning before it forwards them anywhere.
The fix is to point it at your real site with a proper secure redirect, or to let it lapse. A domain that delivers nothing but a warning is not an asset.
4. The third-party page you link to
Your own site might be spotless while the ordering widget, table-booking page or appointment calendar you send people to lives on someone else's server. If that provider does not support HTTPS on the address you link to, Chrome warns your customer. To your customer, it looks like your problem, because they clicked your button.
You cannot install a certificate on another company's server. You can verify the exact link you use, ask the provider for the HTTPS version (most have one, and some businesses are simply linking to an address from years ago), and if they cannot provide it, treat that as a reason to move.
5. The HTTPS version that exists but is broken
Chrome can only upgrade a visitor to HTTPS if the secure version works. A certificate that has expired, or one that covers www.yourbusiness.ie but not plain yourbusiness.ie, leaves Chrome nothing valid to upgrade to. Depending on what exactly is broken, the visitor gets either the new HTTP warning or Chrome's older certificate error. Neither is the first impression you paid for.
This is where automatic renewal earns its keep. Certificates now have short lifetimes by design, and a renewal that depends on somebody remembering is a renewal that eventually fails, usually while that somebody is on holiday.
6. Old http:// links on print, listings and social bios
This one is mostly good news. Your Google Business Profile, your Facebook page, the side of your van and a few thousand printed menus may all still say http://. As long as your production site redirects HTTP to HTTPS and the secure version works, Chrome upgrades those visits without any warning. Updating them is tidy housekeeping, not an emergency.
The catch is the word "redirects". If the redirect is missing, every one of those printed links now leads a stranger to a warning. That is why the audit below verifies it explicitly.
How to Audit Every Address You Own in Five Steps
Your own browser is the worst possible test, because it has visited your site too often to warn you. Work through these steps instead. For most small businesses they take about half an hour.
- Inventory every address. List your main domain with and without www, every subdomain you have ever used, any other domains you own, every external booking, ordering or payment link on your site, and the website field on your Google Business Profile and social profiles.
- Verify the secure version. Type each address with https:// at the start and confirm it loads without a certificate error.
- Verify the redirect. Type each address again with http:// at the start and confirm the address bar ends up on https:// by itself.
- Check Search Console. If you use Google Search Console, open its HTTPS report, which counts how many of your indexed pages Google holds on HTTP versus HTTPS and explains why a secure version could not be indexed.
- Fix, move or retire. For each failure, decide whether it needs a certificate deployed, a redirect added, a corrected link from your supplier, or simply switching off.
Steps 2 and 3 take seconds per address. Any failure is a hole a first-time customer was about to fall into, found before they did.

What a Properly Secured Setup Looks Like
Strip away the specifics and a properly run website meets four standards:
- Every address you own answers on HTTPS with a valid certificate.
- Every HTTP address redirects to its HTTPS equivalent automatically.
- Certificates renew themselves, with nobody's diary involved.
- Someone other than a customer is responsible for noticing when any of that slips.
None of it is exotic. It is the baseline, and it is the baseline that most often erodes on sites built years ago and then left on hosting that nobody actively manages.
On Web60, SSL certificates come from Let's Encrypt and are provisioned and renewed automatically, so a site built with the AI website builder is on HTTPS from the moment it exists, with no add-on fee. Underneath that sits Web60's managed WordPress stack on sovereign Irish infrastructure, with server-level hardening, fail2ban intrusion prevention and nightly backups handled for you. For the business owner, the consequence is simple. The first thing a new customer sees is your homepage, not a security prompt.
Because it is full WordPress, the platform behind roughly four in ten of the world's websites according to W3Techs, nothing about securing your site this way locks you in. If your current site is one of the stragglers, moving it is less work than most people expect: Web60 includes free migration from other hosts, and hosting, SSL, backups, security and support from a team based in Ireland come to €60 a year. If the old site was built by someone you can no longer reach, describing your business to the AI builder and having a fresh, secure WordPress site in under a minute is a perfectly sensible alternative to chasing them.
When moving genuinely is not needed
If your audit comes back clean, Chrome 154 is a non-event for you, whoever hosts your site. Most competent hosts, including plenty of budget shared hosting and the big hosted website builders with a connected domain, have provided automatic SSL for years. A clean audit means there is nothing to move and nothing to buy. Spend the rest of that half hour on your Google Business Profile instead.
What HTTPS does not do
The padlock gets oversold, so it is worth being plain about its limits. HTTPS encrypts the connection between your visitor and your server. It does not prove your business is trustworthy, it does not stop a vulnerable plugin being exploited, and a scammer's site can carry a perfectly valid certificate. It is the entry ticket that stops Chrome interrupting your visitors. The rest of your security still has to be done, and our complete guide to WordPress security and backups for Irish websites covers that wider picture.
There is a platform limit too. Web60 can secure the addresses it hosts. A booking calendar on a third-party provider's server is still that provider's responsibility, which is why every external link belongs on your audit list regardless of who hosts your main site.
Conclusion
Chrome 154 does not punish the web. It punishes the forgotten corners of it, and it does so at the worst possible moment: the first time a stranger tries to decide whether your business deserves their money. The owner is usually the last person to notice, because their own browser stopped warning them long ago.
The fix is mostly an afternoon of checking, not a rebuild. List every address, type each one with https:// and then http://, and deal with whatever fails. If everything passes, you have spent half an hour and bought certainty. If something fails, you have found it before your next new customer does.
Frequently Asked Questions
What is Chrome's Always Use Secure Connections setting?
It is a Chrome security setting that tries every website over HTTPS first and shows a warning before loading a public site that does not support HTTPS. Google launched it as an opt-in in 2022, enabled it for Enhanced Safe Browsing users with Chrome 147 in April 2026, and named Chrome 154 as the version that turns it on by default for everyone. Visitors can still click through the warning or switch the setting off.
Will my business website show the new Chrome warning?
Only if a first-time visitor cannot reach it over HTTPS. If your site has a valid SSL certificate and redirects HTTP to HTTPS, Chrome upgrades the visit quietly and no warning appears. Sites with no certificate, an expired certificate, or a certificate that does not cover the address the visitor used are the ones that trigger it.
Why can I not see the warning when I visit my own website?
Google designed the warning to appear for new or not recently visited sites, not for sites a person visits regularly. Because you visit your own site often, your browser will probably never show it to you. Test by typing your address with https:// and with http:// at the start and checking where you land, rather than relying on whether you see a warning.
Do old http:// links on my flyers or Google Business Profile trigger the warning?
Not if your site redirects HTTP to HTTPS and the secure version works. Chrome upgrades the link to HTTPS before loading anything. If the redirect is missing or the HTTPS version is broken, those old links will lead first-time visitors to a warning, so verify the redirect and update the links when convenient.
Do I have to pay for an SSL certificate to avoid the warning?
No. Free certificates from Let's Encrypt provide the same encryption as paid ones for a typical business website, and many hosts install and renew them automatically. On Web60 they are included in the €60 a year price and renewed automatically.
Does the Chrome warning affect my Google rankings?
The warning is a browser feature rather than a change to Google Search. Google's page experience guidance does ask whether your pages are served securely, and the Search Console HTTPS report flags pages that are not. The bigger cost is practical: many first-time visitors who meet a warning will go back rather than continue, and they never see your business at all.
Sources
- Google Chrome Security Team: HTTPS by default
- Chromium Dash: Chrome release schedule
- Google Chrome Help: Always use secure connections
- W3Techs: Usage statistics of default protocol HTTPS for websites
- W3Techs: Usage statistics of WordPress
- Google Search Console Help: HTTPS report
- Google Search Central: Understanding page experience in Google Search results
Graeme Conkie founded SmartHost in 2020 and has spent years building hosting infrastructure for Irish businesses. He created Web60 after seeing the same problem repeatedly — Irish SMEs paying too much for hosting that underdelivers. He writes about WordPress infrastructure, server security, developer workflows, managed hosting strategy, and the real cost of hosting decisions for Irish business owners.
More by Graeme Conkie →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
Changing Your WordPress Theme: What Breaks, What Survives and How to Switch Safely
Changing your WordPress theme keeps your content but can break menus, widgets and theme-bundled features. How to switch safely, step by step, without surprises.
WordPress Timezone Setting: Why Your Bookings Drift an Hour Twice a Year
Is your WordPress timezone set to UTC+0 or UTC+1? It will not adjust when the clocks go back on 25 October. How to fix it and protect your bookings.
