HTTPS everywhere
Without it, Chrome shows “Not secure” and your forms travel in the clear. A free Let's Encrypt certificate is enough.
Free tool
People type your address in four different ways. All four should land on the same secure page, in a single hop, without anything loaded over an insecure connection.
To a browser and to Google, http://example.com, https://example.com and https://www.example.com are three different sites. Unless they all redirect to one of them, your visitors, your links and your search ranking get split.
Without it, Chrome shows “Not secure” and your forms travel in the clear. A free Let's Encrypt certificate is enough.
http://www → https:// directly, not through two or three intermediate addresses: each hop costs time, especially on mobile.
A 301 or 308 tells search engines the move is final, so they transfer the old address's ranking to the new one.
It doesn't matter for ranking. What matters is choosing one and redirecting the other to it. Without www is shorter; with www is sometimes simpler with certain CDNs.
A secure page (HTTPS) that loads an image, script or style sheet over plain HTTP. Browsers block scripts and styles in that case, which can break the page. It usually happens after moving a site to HTTPS, when old addresses remain in the content.
Usually at your host (a “Force HTTPS” option in Plesk or cPanel), or in the .htaccess file on Apache. On WordPress, the site address in Settings › General must also use https://.
Your cookies
With your consent, Google Analytics counts visits to this site (_ga cookies, 2 years). Google processes these measurements, including outside Canada. Nothing loads until you say yes. Learn more (French)