HTTPS and certificates
These checks look at the encrypted connection to your site:
- cert_invalid, cert_expired: browsers will warn visitors. Renew or reissue the certificate (most hosts do this automatically with Let's Encrypt; check that automatic renewal works).
- cert_expiring, cert_expiring_soon: the certificate expires within 14 days (critical) or within 30 days (warning). Paid plans check the certificate daily and alert 14, 7 and 1 day before expiry.
- tls_old_version: the server still accepts TLS 1.0 or 1.1. Set the minimum version to TLS 1.2 (on Cloudflare: SSL/TLS, Edge Certificates, Minimum TLS Version).
- tls_unreachable, tls_handshake_refused: HTTPS did not answer, or refused our scanner's direct connection.
- no_https_redirect:
http://addresses do not redirect tohttps://. Turn on "Force HTTPS" or add the redirect. - redirect_chain_http: the redirect passes through another plain-http hop first.
- mixed_content: an HTTPS page loads images, scripts or styles over plain http.
Last reviewed Oct 7, 2026, 12:00:00 AM