How to Fix Mixed Content Warnings After Installing SSL

Resolve mixed content warnings by finding and updating insecure HTTP resources so your padlock stays green.

· Updated · 2,783 views

Mixed content happens when a page is served over HTTPS but still loads some resources, such as images, scripts, or stylesheets, over insecure HTTP. The browser shows a broken or grey padlock and may block the insecure content entirely.

Find the Insecure Resources

  1. Open the affected page in Chrome.
  2. Press F12 to open Developer Tools.
  3. Go to the Console tab.
  4. Look for warnings that say "Mixed Content" and note the HTTP URLs listed.

These warnings point to the exact files causing the problem.

Fix the URLs

Update each insecure reference to use https:// or a protocol-relative path:

  • Replace http:// with https:// in your theme files and content.
  • Update image and link URLs stored in your database.
  • Re-upload any media that was inserted with an HTTP address.

In WordPress, a search-and-replace plugin can update every stored URL at once. Always back up the database first.

Force Secure Requests with .htaccess

To upgrade insecure requests automatically, add this header in your .htaccess:

Header always set Content-Security-Policy "upgrade-insecure-requests"

This tells the browser to load HTTP resources over HTTPS where possible.

Verify the Fix

  • Reload the page and confirm a solid green padlock.
  • Recheck the Console for remaining warnings.
  • Test on more than one page, including the home page and a blog post.

If a third-party script only offers an HTTP version, find an HTTPS alternative or host the file yourself. Most reputable services now provide HTTPS by default, so an HTTP-only resource is often a sign the asset should be replaced.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.