sandywp / plugins / https-redirection
Easy HTTPS Redirection (SSL)
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
Ready in seconds.
v2.0.1 100,000+ installs WP 6.5+

What you get inside
4 screens-
Plugin settings page.
About this plugin
Only use this plugin if you have installed SSL certificate on your site and HTTPS is working correctly
Once you’ve installed an SSL certificate on your site, it’s important to ensure that your webpages are accessed via their secure HTTPS URLs.
To improve SEO and user security, you want search engines and visitors to always use the HTTPS version of your pages. This plugin makes that easy by automatically redirecting users to the HTTPS version whenever they try to access the non-HTTPS (HTTP) version of a page.
Example
Let’s say you want to ensure the following page is always accessed over HTTPS:
https://www.example.com/checkout
If a visitor tries to access:
http://www.example.com/checkout
The plugin will automatically redirect them to the secure version:
https://www.example.com/checkout
This ensures that visitors always access the HTTPS version of your pages or site.
You can choose to automatically redirect your entire domain to HTTPS, or selectively apply HTTPS redirection to specific pages.
Video Tutorials
Force Load Static Files Using HTTPS
If you started using SSL from day 1 of your site then all your static files are already embedded using HTTPS URL. You have no issue there.
However, if you have an existing website where you have a lot of static files that are embedded in your posts and pages using NON-HTTPS URL then you will need to change those. Otherwise, the browser will show an SSL warning to your visitors.
This plugin has an option that will allow you to force load those static files using HTTPS URL dynamically.
This will help you make the webpage fully compatible with SSL.
Mixed Content Scanner & Database URL Fixer
After switching to HTTPS, your pages can still trigger browser “mixed content” warnings if old HTTP URLs remain saved in your database (in post content, custom post types, post meta, or WordPress options). This plugin includes a built-in scanner to find and update those insecure URLs to their HTTPS version – no manual database editing required.
Available from the Mixed Contents settings tab, the scanner lets you:
- Scan selected post types – Choose exactly which post types to scan and update, including posts, pages, and any custom post types registered by your other plugins (products, orders, downloads, subscriptions, and more).
- Update other database tables – Optionally include the WordPress options table in the scan.
- Include post meta – Extend the scan to post meta for the selected post types.
- Choose your scan scope – Run a quick “Scan Static Resources Only” pass, or a thorough “Scan All” to catch every non-HTTPS reference.
This makes cleaning up legacy HTTP links straightforward, helping you achieve a fully secure padlock with no mixed content errors.
SSL Certificate Expiry Notification
This plugin includes a feature that allows you to receive email notifications when your SSL certificate is about to expire. It helps ensure your website remains secure and accessible over HTTPS.
You can configure the recipient email address and specify how many days in advance the notification should be sent. By default, the notification is sent 7 days before expiry, but you can adjust this to suit your preference.
This feature is especially useful for site owners who may not frequently check their SSL status, or for those managing multiple websites. By receiving timely alerts, you can renew your SSL certificate in advance and prevent potential downtime or security warnings.
HTTP Strict Transport Security (HSTS) Support
Easy HTTPS Redirection includes built-in support for sending the HTTP Strict Transport Security (HSTS) response header.
HSTS instructs compatible web browsers to automatically access your website over HTTPS after a visitor has successfully visited your secure site. This helps strengthen your site’s HTTPS enforcement and reduces the risk of users accidentally accessing the HTTP version of your website.
The plugin allows you to:
- Enable or disable the HSTS response header with a simple checkbox.
- Configure the HSTS max-age value.
- Apply the HSTS policy to all subdomains using the
includeSubDomainsdirective. - Include the
preloaddirective for sites that intend to submit their domain to the browser HSTS preload list.
Features
- Automatically redirect all HTTP traffic to HTTPS
- Option to force HTTPS on the entire site
- Option to selectively apply HTTPS redirection to specific pages
- Helps search engines index the secure versions of your pages
- Improves site security and user trust
- Force load static files (images, js, css etc) using a HTTPS URL
- Built-in mixed content scanner to find and update non-HTTPS URLs across post content, post meta, custom post types, and WordPress options
- SSL certificate expiry notification – Option to send SSL expiry notifications to a specific email address
- Easily see which SSL certificates on your site are approaching their expiry date.
- HTTP Strict Transport Security (HSTS) support with configurable max-age, includeSubDomains, and preload options.
View more details on the HTTPS Redirection plugin page.
Questions
- How will the plugin work with the existing .htaccess file?
If the file exists, the plugin will update existing .htaccess file.
- What should I do if the .htaccess file does not exist?
The plugin will store the settings in the database and add all the necessary conditions to the settings of WordPress automatically.
- What should I do if after making changes in the .htaccess file with the help of the plugin my site stops working?
The.htaccess is located in the site root. With your FTP program or via cPanel go to the site root, open the .htaccess file and delete the necessary strings manually.
Please make use of the following information: https://codex.wordpress.org/FTP_Clients- How to use the other language files with the HTTPS Redirection?
Here is an example for German language files.
-
In order to use another language for WordPress it is necessary to set the WP version to the required language and in configuration wp file –
wp-config.phpin the linedefine('WPLANG', '');writedefine('WPLANG', 'de_DE');. If everything is done properly the admin panel will be in German. -
Make sure that there are files
de_DE.poandde_DE.moin the plugin (the folder languages in the root of the plugin). -
If there are no such files it will be necessary to copy other files from this folder (for example, for Russian or Italian language) and rename them (you should write
de_DEinstead ofru_RUin the both files). -
The files are edited with the help of the program Poedit – https://poedit.net/download – please load this program, install it, open the file with the help of this program (the required language file) and for each line in English you should write translation in German.
-
If everything has been done properly all the lines will be in German in the admin panel and on frontend.
-
sandywp / also on the shelf
Try another plugin
WP Force SSL & HTTPS SSL Redirect
4.7 · 80K+ installs
Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS &…
SSL Zen — SSL Certificate Installer & HTTPS Redirects
4.9 · 10K+ installs
Free SSL certificate for WordPress — install a Let's Encrypt SSL, force HTTPS, fix mixed content and redirect HTTP to HTTPS. No…
4.1 · 8K+ installs
A fix for mixed content! This Plugin creates protocol relative urls by removing http + https from links. Works in Front- and…
Spin up a real WordPress site in seconds.
Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.