8,000+
September 14, 2026
January 31, 2019
With over 390 five-star reviews ⭐⭐⭐⭐⭐ and a 4.9 out of 5 stars average rating, ‘Auto-Install Free SSL’ empowers you to generate Free SSL Certificates in your WordPress dashboard effortlessly. This plugin helps secure your website and saves you money.
Let’s Encrypt™ SSL Certificate is FREE. But they provide it through their API. If you are not a programmer, you need to study and practice programming for years to be able to use the API of Let’s Encrypt™ to generate a single Free SSL Certificate for your WordPress website.
Here is where ‘Auto-Install Free SSL’ comes into play. This WordPress plugin provides a hassle-free way to obtain and install the Let’s Encrypt™ free SSL certificate for your website. You don’t need programming or coding experience to set it up. With this plugin, you don’t need to spend hours configuring SSL or waste money purchasing SSL certificates. All you need is a few minutes.
The free https SSL certificate issued by Let’s Encrypt™ expires in 90 days. They recommend renewing 30 days before expiry. Please check the FAQ section to learn why the lifetime is 90 days.
Use this plugin only for HTTPS redirects too.
If your WordPress website has an SSL certificate installed and you are looking ONLY for Force SSL activation (i.e., HTTPS redirect, fix insecure content), you can use the FREE version.
(The last five features are available for the unlimited sites license only.)
If your WordPress website is hosted on a VPS or dedicated server and you don’t have cPanel, Automatic Installation of the Free SSL Certificate is still possible. Please get in touch with us after purchase.
Protect your users’ data: If an SSL certificate is installed, your WordPress website’s data travels through the internet with 2048-bit (or more) encryption. No computer or hacker in between can read your users’ encrypted data. Only the intended recipient (users’ browser or your server) can decrypt and read the encrypted data. The data may be credit card-like necessary payment details, user input with a contact form, or a simple login form.
Display PADLOCK: Installing an SSL certificate is not optional anymore, even if your WordPress website doesn’t accept credit cards. Since July 2018, with version 68, Google Chrome has started to mark all HTTP (no SSL) websites as ‘Not secure’, even if it doesn’t accept user input. All other browsers followed the same path. When users visit an SSL-secured website, all browsers display a secured PADLOCK in the address bar.
Boost the Search Engine Ranking: Google and other search engines aim to create a secure web. So, search engines now favor SSL-secured HTTPS websites and discourage insecure ones in the search results. If your WordPress website doesn’t have an SSL certificate installed, you are missing something significant regarding SEO and staying away from potential customers.
Gain the trust of your users: If users see the secured PADLOCK and HTTPS connection in the URL, they are assured that your website is secured. Now you are gaining the trust of your potential customers. They are confident to purchase your product or service.
Please click here for the documentation.
Please check the existing topics in the WordPress support forum before creating a new topic for support or reporting a bug.
Translations can be added easily here if you want to translate in your language.
Let’s Encrypt™ is a trademark of the Internet Security Research Group. All rights reserved.
(Please check the Details tab for MINIMUM SYSTEM REQUIREMENTS.)
Video Tutorial: [cPanel] How to install the plugin and generate & install a Free SSL Certificate for your WordPress website
Video Tutorial: [Plesk] How to install the plugin and generate & install a Free SSL Certificate for your WordPress website
Now, check the AFTER ACTIVATION section below.
Now check either the WordPress, cPanel or FTP section below. If your web hosting control panel is other than cPanel, the steps are similar to cPanel.
Now, check the AFTER ACTIVATION section below.
/wp-content/plugins/ directory./wp-content/plugins/ directory.2.- Log in to your WordPress dashboard and go to the ‘Plugins’ page. You see, ‘Auto-Install Free SSL’ is listed here. Click the ‘Activate’ option here. You’re done!
After activating ‘Auto-Install Free SSL’, you’ll be redirected to a page (powered by freemius) where we request you opt-in to our security & feature update notifications and non-sensitive diagnostic tracking. You’ll get links there to learn about this in detail. Then you may or may not allow us to opt-in as you wish. We appreciate your help improving the plugin by letting us track a few non-sensitive usage data.
How to generate a Free SSL Certificate
Generating a free encryption certificate is straightforward. Please follow the steps below:
Please follow these steps:
/home/username/public_html/wp-site . Create a directory, ‘.well-known’ and another directory, ‘acme-challenge’, inside the ‘.well-known’ directory.Now wait a few seconds, and you will see a free SSL certificate has been issued to your WordPress website. The page looks like this screenshot. Download the SSL, Private Key, and CA Bundle files (.pem) by clicking the links.
After this, log in to your web hosting control panel and install the SSL certificate on your WordPress website.
How to install the SSL certificate with cPanel
How to install the SSL certificate with Plesk
Now you can access your website with ‘https://’.
The options will differ if your web hosting control panel is anything other than cPanel and Plesk, but the concept is similar.
NOTE: The free SSL security certificate issued by Let’s Encrypt™ expires in 90 days. So you need to spend time repeating the process of generating and installing an SSL certificate every 60 days. They recommend renewing 30 days before expiry.
Click the ‘Re-generate (renew) SSL’ button to start renewing.
However, the premium version of this plugin generates (issue/renew) and installs the free SSL certificate automatically. Please check the video tutorial (1:42 min) below and see how easy it is.
Are you interested? Click here to BUY the PREMIUM VERSION.
How to Activate Force HTTPS / HTTPS Redirect
After installing the SSL certificate, please perform the following steps:
Troubleshooting
Access the ‘Log’ menu within the ‘Auto-Install Free SSL’ menu in the left-hand sidebar. Be sure to review the log for any insights.
If you encounter issues with the Let’s Encrypt™ API connection and wish to log Let’s Encrypt™ server response details for each API call, you can achieve this by writing the following URL in the address bar by replacing ‘www.example.com’ with your domain name, and hit enter:
http://www.example.com/wp-admin/admin.php?page=auto_install_free_ssl&log_all_ca_server_response=yes
To stop logging all responses from the Let’s Encrypt™ server, replace ‘yes’ with ‘no’ in the above URL.
For deeper, AI-assisted troubleshooting, you can additionally log every single Let’s Encrypt™ server response (including responses with an unexpected HTTP status code) in JSON format by writing the following URL in the address bar by replacing ‘www.example.com’ with your domain name, and hit enter:
http://www.example.com/wp-admin/admin.php?page=auto_install_free_ssl&log_all_ca_server_response_array_json=yes
Each logged response is wrapped inside clearly named markers so it can be easily located and extracted from the log file, including by an AI model: [[AIFS_CA_RESPONSE_JSON_FORMAT_START]] … [[AIFS_CA_RESPONSE_JSON_FORMAT_END]] for JSON-encoded array responses, [[AIFS_CA_RESPONSE_ARRAY_FORMAT_START]] … [[AIFS_CA_RESPONSE_ARRAY_FORMAT_END]] when JSON encoding fails, or [[AIFS_CA_RESPONSE_START]] … [[AIFS_CA_RESPONSE_END]] for non-array (raw) responses. To stop logging, replace ‘yes’ with ‘no’ in the above URL.
Difference between the two logging options: aifs_log_all_ca_server_response logs only successful API responses (HTTP status 200, 201, 202, or 204) as plain text. aifs_log_all_ca_server_response_array_json logs every response—including failed or unexpected ones—in a structured, AI-friendly JSON format with clearly named markers for easier parsing.
Please check the existing topics in the WordPress support forum before creating a new topic for support or reporting a bug.
After generating an SSL certificate with this plugin, if SSL installation fails and you see such an error message: “Certificate verification failed! The system did not find the root certificate that corresponds to the supplied Certificate Authority Bundle’s intermediate certificate. Please supply a full Certificate Authority Bundle with the root certificate included.”
Previously, only the intermediate certificate was included in the CA bundle, which caused installation failures on hosting servers (including cPanel servers) where the root certificate was not present in the local trust store.
Version 4.6.3 and later now always includes the root certificate in the CA bundle, which resolves this error. Please update the plugin to the latest version.
This fix also ensures correct handling of Let’s Encrypt’s newer Generation Y chains, which can contain more than three certificates.
Please click here to learn about plugin installation.
Sorry, it doesn’t. Installing the plugin and installing SSL certificates are two different processes. After installing this plugin, you need to do some steps. Please check the ‘AFTER ACTIVATION’ section in the documentation.
However, the Premium plugin installs SSL certificates with complete automation. Please check the video tutorial (1:42 min) at the top of this page and see how easy it is.
Please check the ‘Benefits of installing an SSL certificate on your WordPress website’ above.
Please check the documentation. This documentation is for the free version of the plugin.
If you want complete automation, please check the Premium version’s video tutorial (1:42 min) at the top of this page.
Please click here to learn about installing an SSL certificate on your WordPress website.
FYI, the Premium version installs SSL certificates with complete automation.
Please check the log. It is located in the plugin menu. Most probably, you see an error saying ‘unable to register the account’ along with the following text in the log:
urn:ietf:params:acme:error:invalidEmail
Let’s Encrypt™ API throws this error if an invalid email was set as the admin email of your WordPress website, for example, “yourname@yourdomain.mamp” or “anything@example.com”. Let’s Encrypt™ expects we should register an account with a working email.
To fix this, please update this plugin to the latest version and try generating the SSL again. Then you’ll get a text field to update the admin email address.
Feel free to contact us through the WordPress support forum if you still need help with any issues (with the complete log).
Please visit the plugin’s ‘Force HTTPS’ page and click the ‘Activate Force HTTPS’ button.
This is a temporary issue. You may wait 24 hours or follow these steps:
Please access your website with HTTPS (e.g., https://example.com). If you are sure that the SSL certificate is installed correctly and the padlock is visible, please log in to your WordPress dashboard, open a new tab, write the following URL in the address bar by replacing ‘www.example.com’ with your domain name, and hit enter:
http://www.example.com/wp-admin/admin.php?page=aifs_force_https&aifsaction=aifs_force_https_override&checked_ssl_manually=done&valid_ssl_installed=yes
Please click the ‘Revert to HTTP’ button on the plugin’s ‘Force HTTPS’ page.
Alternatively, open the email you received after activating the HTTPS redirect (or Force HTTPS) and click the link to deactivate HTTPS redirect and revert to HTTP. The subject line of that email is “‘Auto-Install Free SSL’ has activated Force HTTPS on your website YourDomain.com”. [Replace YourDomain.com with your WordPress website’s domain].
If your website is accessible with WWW and non-WWW versions of the domain name (e.g., www.example.com and example.com) and both A record points to the same IP address, our plugin will include both versions in the free SSL certificate.
The validity period of free HTTPS certificate being 90 days is not a trial but rather a design choice of Let’s Encrypt™ that prioritizes security. With shorter validity periods, Let’s Encrypt™ encourages frequent certificate renewal, ensuring that websites always have up-to-date and secure certificates. This approach reduces the potential impact of compromised certificates.
The premium version of this plugin renews SSL certificates automatically. Automated renewal processes also make it easier for website owners to maintain security without manual intervention. While the 90-day validity might seem short, the automated renewal process ensures seamless and continuous protection for your website’s users.
Please click here to learn the statement of Let’s Encrypt™.
Let’s Encrypt™ issues SSL certificates for domain names rather than bare IP addresses. Free TLS certificates are designed to secure domain names, providing encrypted connections between users and websites. Using SSL certificates with domain names is considered the industry’s best practice.
If you’re looking to secure a website, it’s recommended to associate a domain name with the IP address rather than using the bare IP address. This enhances the user experience and aligns with security and usability standards.
Let’s Encrypt™ does not issue SSL certificates for localhost. Let’s Encrypt™ certificates are intended for public domain names, which are accessible via the internet for the domain control validation (DCV) process. Since localhost is a local server and a hostname used for development, it is not publicly accessible and cannot be validated online using the HTTP-01 challenge (the most common method).
After you complete developing the website in the local development environment, please do the following to secure your website with a free SSL certificate:
Rest assured, after you complete the above steps, you can easily generate an SSL certificate with this plugin, i.e., ‘Auto-Install Free SSL’. We’ve made the process as straightforward as possible for your peace of mind.
However, if you use a registered domain name (for your WordPress website), mapped to the localhost IP address (e.g., 127.0.0.1), and use the DNS-01 challenge for the domain control validation (DCV), our plugin will create a free SSL certificate for your registered domain name. Then you can download the SSL certificate files from our plugin’s ‘Generate SSL’ page and manually install them on the local server. In that case, we recommend you map the registered domain name to the localhost IP address (e.g., 127.0.0.1) using your local computer’s host file, but don’t set A records pointing to the localhost IP with your domain registrar. Use your domain registrar only to set TXT records for the DNS-01 challenge. Please read this for more information: https://letsencrypt.org/docs/certificates-for-localhost
It is possible only if you can use the DNS-01 challenge for the domain control validation (DCV).
However, using the HTTP-01 challenge (the most common method), it is not possible. If you map a registered domain name to a localhost IP address, it is still a localhost and can’t be accessed online. This means that the domain name is only accessible from your local computer and cannot be used to get a free SSL certificate from Let’s Encrypt™ using the HTTP-01 challenge. For more details, please refer to the previous FAQ.
Let’s Encrypt™ issues free SSL certificates only after successful domain control validation (DCV).
Let’s Encrypt™ HTTP-01 challenge works by creating a specific text file with specific content in a specified directory (.well-known/acme-challenge/) of the document root of the website, as defined by the ACME standard. The file name and its content are variable. Our plugin creates this file with the specific text by automatically communicating with the Let’s Encrypt™ API server, and as per their requirements. Users of the free version can download the static file and upload it to the specified directory. The premium plugin uploads this file to the specified directory automatically.
It’s the responsibility of your web server to make the static file available at the specific public URL. This is the standard behavior of every web server. To validate your domain control, Let’s Encrypt™ API server accesses the specific URL and checks if the file’s content is valid. For example, the file at the following URL:
http://yourdomain.com/.well-known/acme-challenge/pqv-gjW9kF0VjktRxdqpPNK-0tLA_n5ORCzuB71-Zog
Must return this exact content or text:
pqv-gjW9kF0VjktRxdqpPNK-0tLA_n5ORCzuB71-Zog.aSOSwUGmotjVbnE_hY1u-2wwHhwyl5qtPLVr4COOSQs
If your web server (or hosting provider) purposefully blocks access to such files, Let’s Encrypt™ cannot validate that you control the domain, and will not issue an SSL certificate for your domain name.
Please contact your web hosting provider and ask whether they allow Let’s Encrypt™ API access to HTTP-01 challenge files.
Optionally, follow these steps: create two directories (i.e., folders) ‘.well-known/acme-challenge/’ in the document root of your domain name or website. Create a static file with the following file name:
pqv-gjW9kF0VjktRxdqpPNK-0tLA_n5ORCzuB71-Zog
and without any file extension inside the ‘.well-known/acme-challenge/’ folder. Copy the following content into the file and save it:
pqv-gjW9kF0VjktRxdqpPNK-0tLA_n5ORCzuB71-Zog.aSOSwUGmotjVbnE_hY1u-2wwHhwyl5qtPLVr4COOSQs
Then try to access it over HTTP like the following URL:
http://yourdomain.com/.well-known/acme-challenge/pqv-gjW9kF0VjktRxdqpPNK-0tLA_n5ORCzuB71-Zog
(Make sure to replace ‘yourdomain.com’ with your actual domain name.) If you can see the exact file content in your browser, your server is ready.
However, some hosts allow you to view the file manually in a browser but block Let’s Encrypt™ API from accessing it, which also causes failures. So, the best way is to ask your web hosting provider.
All other Let’s Encrypt clients who auto-install free SSL certificates need root access, a higher privilege than the cPanel user. In shared hosting, the root access belongs to the web hosting company. So those clients will not work on shared hosting.
cPanel username and password (or API Token) are required to install the free SSL certificate with the cPanel API automatically. Let’s Encrypt SSL’s lifetime is 90 days. You need to get and install another SSL certificate before the expiration of the current SSL. If you provide your cPanel username and password (or API Token), this plugin will do this repeated job automatically. All your credentials remain safe in your database. Moreover, ‘Auto-Install Free SSL’ encrypts the password (or API Token) before saving it in your database.
We or Let’s Encrypt don’t collect any credentials. This plugin’s source code is open for audit. The WordPress team approved it after the audit. Please feel free to audit yourself too.
You don’t need to set the Cron Job manually. It works by default (from version 3.0.0). However, ‘Auto-Install Free SSL’ can add an optional cron job with one click from your WordPress dashboard (available for unlimited sites license).
Since version 3.0.0, You can access the cron output by clicking the ‘Log’ menu.
If you have an unlimited site license and created a cron job manually, ensure you have provided your email address in the ‘Cron Email’ section of the Cron Jobs page of cPanel.
Please click the following URL for the previous changelog:
https://freessl.tech/aifs_changelog.txt
| Version | Download | Type |
|---|---|---|
| 5.0.0 | Download | Stable |
| 4.7.0 | Download | Stable |
| 4.6.3 | Download | Stable |
| 4.6.2 | Download | Stable |
| 4.6.1 | Download | Stable |
| 4.6.0 | Download | Stable |
| 4.5.1 | Download | Stable |
| 4.5.0 | Download | Stable |
| 4.4.0 | Download | Stable |
| 4.3.0 | Download | Stable |
| 4.2.0 | Download | Stable |
| 4.1.0 | Download | Stable |
| 4.0.0 | Download | Stable |
| 3.6.10 | Download | Stable |
| 3.6.9 | Download | Stable |
| 3.6.8 | Download | Stable |
| 3.6.7 | Download | Stable |
| 3.6.6 | Download | Stable |
| 3.6.5 | Download | Stable |
| 3.6.4 | Download | Stable |
| 3.6.3 | Download | Stable |
| 3.6.2 | Download | Stable |
| 3.6.1 | Download | Stable |
| 3.6.0 | Download | Stable |
| 3.5.1 | Download | Stable |
| 3.5.0 | Download | Stable |
| 3.4.3 | Download | Stable |
| 3.4.2 | Download | Stable |
| 3.4.1 | Download | Stable |
| 3.4.0 | Download | Stable |
| 3.3.2 | Download | Stable |
| 3.3.1 | Download | Stable |
| 3.3.0 | Download | Stable |
| 3.2.15 | Download | Stable |
| 3.2.14 | Download | Stable |
| 3.2.13 | Download | Stable |
| 3.2.12 | Download | Stable |
| 3.2.11 | Download | Stable |
| 3.2.10 | Download | Stable |
| 3.2.9 | Download | Stable |
| 3.2.8 | Download | Stable |
| 3.2.7 | Download | Stable |
| 3.2.6 | Download | Stable |
| 3.2.5 | Download | Stable |
| 3.2.4 | Download | Stable |
| 3.2.3 | Download | Stable |
| 3.2.2 | Download | Stable |
| 3.2.1 | Download | Stable |
| 3.2.0 | Download | Stable |
| 3.1.3 | Download | Stable |
| 3.1.2 | Download | Stable |
| 3.1.1 | Download | Stable |
| 3.1.0 | Download | Stable |
| 3.0.7 | Download | Stable |
| 3.0.6 | Download | Stable |
| 3.0.5 | Download | Stable |
| 3.0.4 | Download | Stable |
| 3.0.3 | Download | Stable |
| 3.0.2 | Download | Stable |
| 3.0.1 | Download | Stable |
| 3.0.0 | Download | Stable |
| Development | Download | Trunk |