"Mixed content" warning: why your https site still says not fully secure

Your page loads over https, but something on it loads over plain http. An image, a script, a font, a form. The browser blocks scripts like that outright and shows a broken padlock for images. The fix is to find every http:// address the page asks for and change it.

What to do, in order

  1. Find the offenders. Open the page in Chrome, press F12, open the Console tab and reload. Each warning starts with "Mixed Content" and names the exact http:// address.
  2. Images and files you uploaded. In WordPress these are usually old posts with http:// in the content. A search-and-replace plugin (Better Search Replace) changing http://yourdomain.com to https://yourdomain.com fixes them all at once. Back up the database first.
  3. Theme and plugin files. If the address is in a theme file, edit it to start with https://. If a plugin adds it, update the plugin or replace it.
  4. Third-party scripts. An old widget or tracker on http:// may have an https version. If it has none, remove it.
  5. Site address settings. In WordPress, Settings, General: both addresses must start with https://.
  6. Safety net. Add the header Content-Security-Policy: upgrade-insecure-requests. The browser then asks for https on every subresource. It does not fix links to sites that have no https at all.

Check it yourself

Run curl -s https://yourdomain.com | grep -o 'src="http://[^"]*"' | sort -u. Every line it prints is a resource loaded insecurely. A plain http link in an <a href> is not mixed content. Only things the page loads count.


Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.