SEO-30
Missing HTTP → HTTPS redirect on the homepage
What the check measures
The audit tries to connect to http:// (the insecure variant of your home page) and watches whether the response redirects to https://. If it does not, the finding is raised. It is the only check in the whole set that deliberately visits an insecure URL.
Only the home page is checked, not the whole site. When http cannot be reached at all (the port is closed), the check stays quiet. That is not a fault, it is a legitimate way of switching http off.
What the check does not do: it does not verify the certificate, does not check redirects on subpages, and does not verify the redirect stays on the same domain. The finding attaches to the home page; severity is critical. The next section explains why, because it is not for the reason you would expect.
How strong the evidence is
We recommend it because it does no harm or has some other benefit, but we promise nothing about whether it makes language models cite you. Nobody has demonstrated that yet.
This finding is critical and yet sits in the “effect not demonstrated” class. That looks like a contradiction and is not. And it is worth explaining precisely, because more inaccuracy circulates about HTTPS than about anything else in SEO.
HTTPS was briefly announced as a ranking signal in 2014. Today Google confirms no direct effect on ranking. We verified this on 2026-09-07 in its own “page experience” documentation, and it says the opposite of the expectation: beyond Core Web Vitals, other page experience aspects do not directly help a website rank higher in search results.
So we will not promise you a better position, let alone better visibility in AI. We can document neither.
The critical severity is about something else and it is solid: security and trust for your visitor. Browsers mark insecure http:// pages with forms as “Not secure”, and every customer who wants to fill something in sees that. On an insecure connection anyone on the path can read the page and change it.
In other words: it is the one finding in the entire audit whose reason has nothing to do with search. Do not fix it for Google; fix it because without it you send your customers' data in the open.
How to fix it
The goal is for every http:// URL to redirect permanently to its https:// counterpart, not just the home page and not temporarily.
# nginx: one server block that only redirects
server {
listen 80;
server_name your-domain www.your-domain;
return 301 https://your-domain$request_uri;
}- 301, not 302. A permanent redirect; a temporary one says “try http again next time”.
$request_uripreserves the path. Redirecting everything to the home page is a common mistake that discards every inbound link.- Do not redirect via waypoints.
httpwithout www →httpswithout www →httpswith www is a needless chain (SEO-09). - Once the redirect works, add HSTS (
SEO-31); only then does it make sense, because it tells browsers not to tryhttpat all. - Check subpages too, not just the root. Configuration often covers only the domain.
Verification is the same thing the audit does:
curl -sI http://your-domain/ | grep -iE '^HTTP/|^location'Order matters: a working certificate and redirect first, HSTS only afterwards. The other way round you can lock your site away for months: a browser remembers HSTS and will not touch http again, even if https stops working.
What the report says about it
Finding description
The homepage on `http://` does not redirect to the secure `https://` version. Browsers (Chrome) mark such a connection as "Not secure" and warn users on `http://` forms. This is a security/trust gap. Current Google documentation (developers.
Recommendation
Set up a permanent (301) redirect from `http://` to `https://` at the server/CDN level, and add HSTS (see SEO-31).
Sources
- Google Search Central: Understanding page experience (accessed 2026-09-07)
- MDN: Strict-Transport-Security (accessed 2026-09-12)
Text verified 2026-09-12