JSM Force HTTP to HTTPS / SSL – No Setup, Fast and Reliable
No setup required - simply activate to force HTTP URLs to HTTPS using native WordPress filters and permanent redirects for best SEO.
Safe pick
Yes — JSM Force HTTP to HTTPS / SSL is a safe, well-maintained plugin to use in 2026. It runs on 7K+ sites, is rated 5/5 and was last updated 9 hours ago, and scores 84/100 on our health check.
- Actively developed — last update 9 hours ago
- Tested with the latest WordPress (7.1)
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where JSM Force HTTP to HTTPS / S… stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| force ssl | #3 |
| insecure content | #5 |
| mixed content | #6 |
| redirect | >100 |
| seo | >100 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 5 from 13 reviews
About JSM Force HTTP to HTTPS / SSL
From the official readme · v3.5.0Description
A simple, safe, and reliable way to force HTTP URLs to HTTPS dynamically:
No setup required – simply activate the plugin to force HTTP URLs to HTTPS.
There are no plugin settings to adjust, and no changes are made to your WordPress configuration.
SIGNIFICANTLY FASTER than other popular plugins of this type:
Other well known plugins use PHP’s output buffer to search & replace URLs in the rendered HTML, which is a technique that is error prone and negatively affects caching performance (as changes are not cached).
This plugin uses standard WordPress filters instead of PHP’s output buffer for maximum reliability, performance, caching compatibility, and uses 301 permanent redirects for best SEO results (301 redirects are considered best for SEO when moving from HTTP to HTTPS).
Supports advanced proxy / load-balancing HTTP headers:
X-Forwarded-Proto(akaHTTP_X_FORWARDED_PROTOserver value)X-Forwarded-Ssl(akaHTTP_X_FORWARDED_SSLserver value)
See Web technology for developers > HTTP > HTTP headers > X-Forwarded-Proto for more details.
Plugin Requirements
Your web server must already be configured with an SSL certificate and able to handle HTTPS connections. 😉
Changelog
(2024/09/28) Improved PHP 'HTTP_HOST' and 'REQUEST_URI' server variable checks for command line execution.
Version Numbering
Version components: {major}.{minor}.{bugfix}[-{stage}.{level}]
- {major} = Major structural code changes and/or incompatible API changes (ie. breaking changes).
- {minor} = New functionality was added or improved in a backwards-compatible manner.
- {bugfix} = Backwards-compatible bug fixes or small improvements.
- {stage}.{level} = Pre-production release: dev < a (alpha) < b (beta) < rc (release candidate).
Repositories
Changelog / Release Notes
Version 3.5.0 (2024/09/28)
- New Features
- None.
- Improvements
- Improved PHP ‘HTTP_HOST’ and ‘REQUEST_URI’ server variable checks for command line execution.
- Bugfixes
- None.
- Developer Notes
- Updated
JsmForceSsl::force_ssl_redirect()to use not empty() instead of isset().
- Updated
- Requires At Least
- PHP v7.4.33.
- WordPress v6.0.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best JSM Force HTTP to HTTPS / SSL alternatives
All force ssl plugins →FAQ
JSM Force HTTP to HTTPS / SSL: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 28, 2026
Is JSM Force HTTP to HTTPS / SSL free?
Yes. JSM Force HTTP to HTTPS / SSL is free to download and use from the official WordPress.org plugin directory.
Is JSM Force HTTP to HTTPS / SSL safe to use in 2026?
Yes — JSM Force HTTP to HTTPS / SSL is a safe, well-maintained plugin to use in 2026. It runs on 7K+ sites, is rated 5/5 and was last updated 9 hours ago, and scores 84/100 on our health check.
How many websites use JSM Force HTTP to HTTPS / SSL?
JSM Force HTTP to HTTPS / SSL is active on 7K+ WordPress websites and has been downloaded 108,696 times since it launched in January 2017. It was downloaded 627 times in the last 30 days.
Does JSM Force HTTP to HTTPS / SSL work with WordPress 7.1?
Yes. The developer has tested JSM Force HTTP to HTTPS / SSL up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does JSM Force HTTP to HTTPS / SSL need?
JSM Force HTTP to HTTPS / SSL requires PHP 7.4.33 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was JSM Force HTTP to HTTPS / SSL last updated?
The latest version, 3.5.0, was released on September 27, 2026 (9 hours ago).
Who makes JSM Force HTTP to HTTPS / SSL?
JSM Force HTTP to HTTPS / SSL is developed and maintained by JS Morisset.
What are the best alternatives to JSM Force HTTP to HTTPS / SSL?
The most popular alternatives to JSM Force HTTP to HTTPS / SSL are Easy HTTPS Redirection (SSL) (100K+ installs), WP Force SSL & HTTPS SSL Re… (80K+ installs) and SSL Zen (9K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card