SSL encryption
Silktide checks that your pages, documents, and the resources they load are served over an encrypted connection. Encryption protects everything passing between your website and its visitors from being read or altered in transit.
Encrypted pages are served over - the
address starts with https:// rather than http://.
Why this matters
On an unencrypted connection, anyone positioned between the visitor and your website - on public Wi-Fi, at an internet provider, or on a compromised network - can read what is sent and even modify the page in transit. That includes anything visitors type into your forms.
The practical costs are immediate: browsers label unencrypted pages 'Not secure', which visibly undermines trust; search engines use HTTPS as a ranking signal; and privacy regulations such as expect to be protected in transit, for which encryption is the baseline. Certificates are now free through services like Let's Encrypt, and most hosting platforms and CDNs enable them with a few clicks.
How to fix it
- If your website does not have an SSL/TLS certificate, obtain one. Most hosting platforms and CDNs offer free certificates and can enable HTTPS with a setting.
- Redirect all
http://addresses to theirhttps://equivalents, so no-one lands on an unencrypted version. - For pages flagged because of individual resources, update the page's code
so images, scripts, styles, and other embedded content are loaded with
https://URLs (or protocol-relative references). Anything hosted by a third party that offers no HTTPS version should be replaced. - Once everything is served over HTTPS, consider adding Strict Transport Security so browsers never try the unencrypted version at all.
How Silktide tests this
- Check the address of each page and document. If it is not served over HTTPS, report the whole page - individual resources are not listed in this case.
- For pages that are served over HTTPS, examine the resources they load (images, scripts, styles, media) and report each one requested over an unencrypted connection.
- Report the percentage of your pages served over HTTPS over time, so you can track progress.
Troubleshooting
My site has a certificate but pages are still flagged
A certificate alone is not enough - the page must actually be served at an
https:// address. Check that visitors (and Silktide) are not reaching an
unencrypted version that never redirects.
A flagged resource comes from a third party
You control the URL your page requests. If the provider supports HTTPS,
change the reference to https://; if it does not, replace the provider.
For subdomains or hosts you have deliberately left unencrypted, you can
exclude that hostname from the check when recording your
.