Some Security Ninja tests use cURL to request your own site over HTTPS (loopback). You may see:
cURL error 60: SSL certificate problem: unable to get local issuer certificate
That usually means the server cannot validate its own certificate chain.
Common causes
- Cloudflare proxy with a Cloudflare Origin Certificate on the origin server
- Missing or outdated CA certificate bundle on the server
- Custom or self-signed SSL certificates (common on local and staging sites)
Why Security Ninja does not ignore SSL errors by default
Skipping SSL verification hides real problems and weakens security. Do not disable verification on production unless you understand the risk.
What to try
1. Update CA certificates on the server
On Debian/Ubuntu:
sudo apt-get update && sudo apt-get install ca-certificates
On RHEL/CentOS-style hosts:
sudo yum update ca-certificates
Ask your host if you do not have shell access.
2. Prefer a publicly trusted certificate
When possible, use a certificate from a public CA (for example Let’s Encrypt) on the origin, or a setup your host documents as trusted for loopback HTTPS.
3. Point WordPress at a CA bundle
If you cannot update the system bundle, tell WordPress where a valid CA file lives. Prefer a small custom plugin or must-use plugin over a parent theme functions.php:
add_filter(
'http_request_args',
function ( $args, $url ) {
if ( false !== strpos( $url, home_url() ) ) {
$args['sslcertificates'] = '/etc/ssl/cert.pem'; // Adjust to your server path.
}
return $args;
},
10,
2
);
4. Last resort: disable SSL verification for local requests
Only for temporary debugging. Do not leave this enabled on a live site.
Related: Fixed test results still fail, Maintenance and password-protected sites.