JSM Force HTTP to HTTPS / SSL – No Setup, Fast and Reliable icon

JSM Force HTTP to HTTPS / SSL – No Setup, Fast and Reliable

by JS Morisset

View on WordPress.org
80 Quality Score
Active Installs
17/30

With around 7,000 active installs, this is a niche utility plugin rather than a widely adopted tool, but it does exceed the threshold used in the scoring model.

Update Freshness
25/25

The plugin was last updated on 2026-05-18 and is confirmed compatible with WordPress 7.0, indicating the developer is actively maintaining it against the latest core release.

User Rating
15/15

A perfect 100/100 from 13 ratings is encouraging but the very small sample size limits how much weight this should carry in a decision.

Support Health
8/15

There are zero support threads in the tracked period, which means there is no public record of resolved or unresolved issues, a neutral signal at best.

WP Compatibility
15/15

It requires PHP 7.4.33 and WordPress 6.0 or newer, and is tested up to WordPress 7.0, giving it a clean and modern compatibility profile.

Scores higher than 77% of indexed plugins

About

No setup required - simply activate to force HTTP URLs to HTTPS using native WordPress filters and permanent redirects for best SEO.

Active Installs 7k+
Rating ★★★★★ 5/5
Last Updated 2026-09-18 5:18pm GMT
Requires WordPress 6.0+
Tested Up To 7.1.1
Requires PHP 7.4.33+
✓ No known vulnerabilities

What It Does

JSM Force HTTP to HTTPS is a lightweight, zero-configuration plugin that automatically redirects all incoming HTTP requests to their HTTPS equivalents and rewrites insecure content URLs within WordPress output. It relies on native WordPress filters and 301 permanent redirects, so there are no settings pages to configure after activation.

Who It's For

This plugin is well suited for site owners on hosts that lack built-in SSL redirection or who want a one-click safety net for mixed content issues. It is especially useful for small business sites, WooCommerce stores, membership portals, and professional services websites where HTTPS is mandatory but the underlying hosting setup does not already handle redirects cleanly.

Who Should Skip It

If your hosting provider already issues 301 redirects from HTTP to HTTPS at the server level (most managed WordPress hosts and most reverse proxy setups do), this plugin adds no value. Developers who need granular control over HSTS headers, proxy-aware detection, or per-page redirect rules should also look elsewhere.

The Bottom Line

JSM Force HTTP to HTTPS does one small job and appears to do it well, earning a 79.72/100 overall quality score driven mostly by its perfect compatibility and maintenance marks. The tradeoff is a tiny user base and no visible support history, so it is a reasonable choice for a simple site but a riskier one for high-traffic or revenue-critical installs. If your host already handles SSL redirection, skip it entirely.

Tags

force ssl insecure content mixed content redirect seo