An installed SSL doesn't always mean the padlock shows. Common causes include:
- HTTPS isn't forced — visitors still land on the
http://version. Enable Force HTTPS in cPanel > Domains. - Mixed content — some images or scripts load over
http://. Update those links tohttps://. - Wrong or expired certificate — check SSL/TLS Status and run AutoSSL.
- Cache — your browser or a CDN may serve the old insecure page; clear caches and retry in a private window.
- DNS not pointing here — if your domain uses an external proxy or old nameservers, the certificate may not apply.
If it still shows insecure after these checks, open a ticket with the URL so we can investigate.