Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Fix SSL mixed content warnings

Your site has SSL but the padlock is missing or shows a warning. Mixed content is the usual reason. This guide helps you fix it.

SSL and Security2 min read12 steps1 screenshots

What is mixed content?

SSL makes your page load over https://, which is secure. Mixed content happens when the page itself is secure, but some parts still load over plain http://. Those parts can be images, scripts or style files. It is like a locked house with one open window. Browsers warn about it or block those parts.

Find the problem

  1. Open your page in Chrome.
  2. Right-click and choose Inspect. Open the Console tab.
  3. Look for messages that say "Mixed Content". They show the exact http:// link.

Fix it in WordPress

  1. Take a backup of your site and database first.
  2. Go to Settings then General. Make both WordPress Address and Site Address start with https://. Click Save Changes.
  3. Install a plugin that updates old links, such as a search-and-replace plugin.
  4. Search for http://yourdomain.com and replace with https://yourdomain.com. Run it once on the database.
  5. Clear your site cache and any caching plugin.

Fix it in a normal HTML site

  1. Open File Manager in cPanel.
  2. Edit the page files that hold old links.
  3. Change http:// to https:// in image, script and link tags.
  4. Save and reload the page.

Example change:

<img src="http://example.com/photo.jpg">
<img src="https://example.com/photo.jpg">

The second line is the fixed one. It loads the picture securely.

Check that the other site supports https. If it does, change the link. If it does not, host the file on your own site instead.

Tip: After you fix the links, a force-https redirect in .htaccess keeps visitors on the secure version. Ask support if you need help.

Quick recap

  • Mixed content means a secure page loads insecure parts.
    Screenshot: Mixed content means a secure page loads insecure parts.
  • Find the http:// links in the browser Console.
  • Change them to https://.
  • In WordPress, set https addresses and run a search-and-replace.
  • Back up first and clear caches.