What is mixed content?
HTTPS is the safe, locked version of a web address. An SSL certificate is a digital badge that turns the lock on. Your page may load over HTTPS, but some parts, like pictures or scripts, may still load over plain HTTP. HTTP is the old, unlocked version. When both are mixed on one page, the browser shows a warning or hides the padlock.
Think of a locked car carrying a window left open. The car is only as safe as its weakest part.
Step 1: Find the unsafe items
- Open your website in Google Chrome.
- Right-click the page and choose Inspect.
- Click the Console tab.
- Reload the page.
- Look for yellow or red messages that say "Mixed Content". Each one shows the exact address that is still using
http://.
Step 2: Change the addresses to HTTPS
For each unsafe item, change http:// to https:// in the link. For example:
http://example.com/images/logo.png
https://example.com/images/logo.png
The second line is the safe one. Use it everywhere.
Step 3: Fix a WordPress site
WordPress is a popular tool for building websites. Old links are often saved inside its database.
- Take a full backup of your site first. Changes to the database can break a site.
- Log in to your WordPress dashboard.
- Go to Settings, then General.
- Change both WordPress Address (URL) and Site Address (URL) to start with
https://. - Click Save Changes.
- Install a plugin such as "Really Simple SSL" or "Better Search Replace". Use it to replace
http://yourdomain.comwithhttps://yourdomain.comin the database.
Step 4: Check outside links
Some pictures or scripts may come from other websites. Check that those sites support HTTPS. If they do, change the link to https://. If they do not, download the file and upload it to your own hosting, or remove it.
Step 5: Test again
- Clear your browser cache. The cache is a small store of saved page parts.
- Reload your page.
- Check that the padlock shows and the Console has no more mixed content messages.
Quick recap
- The warning appears when an HTTPS page loads some items over HTTP.
- Use the browser Console to find the unsafe items.
- Change every
http://link tohttps://. - On WordPress, update the site addresses and replace old links in the database after a backup.
- Clear the cache and test again.