SSL For Free – How to add a free Cloudflare SSL Certificate to your WordPress website

Posted by

This is a quick tutorial on how to setup your WordPress site to get the benefits of an SSL certificate and the accompanying secure padlock you see in your browser address bar. Without these your customers (as well as Google) will have less confidence in the security of your website. There are a number of advantages to having an SSL certificate:

  1. Increased Traffic to your website – Google have for a while been telling website owners of the importance of secure websites. They’ve called for all websites to be secure, and actively use SSL certificates as a ranking signal. Therefore your traffic will be affected without SSL.
  2. Improved Security – Cyber attacks occur all the time, and you want your site to be safe I’m sure! Therefore using https along with secure services such as CloudFlare will help protect your site from attacks.
  3. End User Confidence – Google Chrome for example now shows in bright red letters “Not Secure”. This doesn’t send a positive message to your end user. This directly links to:
  4. Increased Sales Conversions – Your customers want a positive experience. They want to be confident in using your site to make a purchase or to submit their data, therefore having a secure URL and padlock in your address bar is vital.

First of all a little technical background on what I’m updating… This is a relatively new WordPress installation, version 5.3.2, there’s minimal plugins installed, and web hosting and domain name administration to provided by Ionos (previously 1&1).

Setting Up Your Domain and Cloudflare for your Free SSL Certificate

  1. Sign up to Cloudflare at https://cloudflare.com (or login if you already have an account).
  2. On the Cloudflare homepage, select ‘+Add a Site’.
  3. Enter your site name, for example ‘vinyldirectory.co.uk’
  4. Choose the ‘Free’ plan. This will give you basic security for your website. You can easily upgrade later for enhanced security features or for high traffic sites later if you wish.
  5. Cloudflare will now scan your name and identify your current domain records. It will most likely highlight the websites AAAA and A records. Hit ‘Continue’.
  6. Cloudflare will now ask you to change your domain nameserver records. You will need to login to your domain name provider, identify the nameserver settings for your domain and then change the nameserver settings to the ones provided by Cloudflare. In the case of ionos.co.uk for example you would choose ‘Use Custom Name Servers’ within the Nameserver setting to achieve this.
  7. Go back to cloudflare.com. Select your domain. Click on Crypto found on the row of icons at the top of the page. Ensure that you have ‘Flexible’ selected in the SSL box at the top of the page. It will probably be selected by default.

Get WordPress Ready for your Free Cloudflare SSL Certificate

You will need to install a plugin to enable Cloudflare to work correctly. This plugin prevents ‘infinite redirect loops’, that will prevent your visitors from viewing your website. There’s no setting to worry about here, just install and activate.

Force All Content to HTTPS

If you have a new website, this may not be necessary, or maybe all plugins and links on your website are already delivered by HTTPS. If not then you can install plugins such as SSL Insecure Content Fixer, which will convert existing links to HTTPS. This is an easy plugin to configure, simply check the ‘Simple’ option first and everything should work, if not, then you can enhance the settings, or disable the plugin.

Check Nameserver & HTTPS Settings

By this point, your certificate should be established with Cloudflare. Go back and see if your nameserver changes have been recognised. You can also us online tools such as mxtoolbox.com to see if your nameserver changes are live.

Within Cloudflare visit the ‘Page Rules’ page and ensure that ‘Always Use HTTPS’ is selected for your domain, if not, create it.

Change Your WordPress Site URL

Go to your WordPress settings (Settings > General) and change the ‘Site Address (URL) ‘ from http:// to https://.

**IMPORTANT** Leave the ‘WordPress Address (URL) as it is, also ensure that you have previously installed and activated the Cloudflare Flexible SSL Plugin. Failure to do this may cause severe trauma, and a broken website.

That’s All Folks!

Hopefully you’ve followed this guide correctly, and if everything is working correctly you now have the padlock showing in the domain address bar in your browser. You now have an HTTPS address and both Google and your website visitors are more confident visiting and ranking your web content.