Your page loads over https, but something on it loads over plain http. An image, a script, a font, a form. The browser blocks scripts like that outright and shows a broken padlock for images. The fix is to find every http:// address the page asks for and change it.
http://yourdomain.com to https://yourdomain.com fixes them all at once. Back up the database first.https://. If a plugin adds it, update the plugin or replace it.Content-Security-Policy: upgrade-insecure-requests. The browser then asks for https on every subresource. It does not fix links to sites that have no https at all.Run curl -s https://yourdomain.com | grep -o 'src="http://[^"]*"' | sort -u. Every line it prints is a resource loaded insecurely. A plain http link in an <a href> is not mixed content. Only things the page loads count.
Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.