Mixed Content Checker

Find insecure http:// scripts, styles, images and iframes on an HTTPS page.

What is mixed content?

Mixed content happens when a page loaded over secure HTTPS also loads files — scripts, styles, images or iframes — over insecure HTTP. Browsers block the dangerous ones and show a "Not secure" warning for the rest.

Active vs passive mixed content

TypeExamplesWhat browsers do
ActiveScripts, stylesheets, iframes, objects, form actionsBlocked — parts of the page break
PassiveImages, video, audio, posters, inline background imagesUpgraded or loaded with a "Not secure" warning

How to fix it

  1. Change every http:// resource URL to https:// (or a relative path).
  2. In WordPress, update the site URL and run a search-and-replace on the database.
  3. Add the header Content-Security-Policy: upgrade-insecure-requests so browsers upgrade any remaining links automatically.

The checker scans the HTML the server sends. Resources added later by JavaScript can still cause mixed content, so also check your browser console.

Frequently asked questions

Does mixed content hurt SEO?

It can. Broken scripts and "Not secure" warnings hurt user trust and can stop parts of the page from working.

Why does my padlock disappear?

At least one resource on the page loads over HTTP. Run this check to find it.

Can I check an HTTP page?

Mixed content only applies to HTTPS pages. An HTTP page is insecure as a whole — move it to HTTPS first.