What it checks
An SSL (TLS) certificate lets browsers open an encrypted connection to your site and confirm the site is really yours. Every certificate has an expiry date. The tool connects, reads the certificate and reports the days left; it also checks that the site ends up on HTTPS after its redirects.
Why it matters
With an expired certificate, browsers show visitors a full-page security warning, and most of them leave right there. Automatic renewal can break silently: a DNS change, a server move or an expired API key is enough.
How to fix it
- In your hosting panel or CDN (Cloudflare, for example), check that the certificate renews automatically.
- If you use Let's Encrypt, look at the last run of whatever renews it (certbot, Traefik, Caddy).
- Run this tool again after renewing; the new expiry date should appear.