Mixed content: HTTPS without the padlock

PlatformAny website Doing it yourself30 to 90 minutes Checked

The short answer

The page itself loads over https, but some images, scripts or styles on it still load over plain http. Browsers block or warn about them. Find them in the browser console, then replace the old http addresses in the database and theme, with a backup and a dry run first.

Is this your problem?

  • No padlock, or "Not fully secure"
  • "Mixed Content" warnings in the browser console
  • Some images or styles missing on https

What usually causes it

1
Old http addresses saved in content

How to tell: Images and links inserted before the move to https.

2
Settings still on http

How to tell: Theme options, page-builder settings or plugin settings with http addresses.

3
Files from other sites over http

How to tell: An old embed, font or script from another server.

Before you touch anything

  • Take a full database backup. The replace step changes content.

How to fix it, step by step

  1. 1

    List the insecure files

    Open the browser console. Each "Mixed Content" warning names the http address.

  2. 2

    Set the site address to https

    In Settings, General, both addresses start with https.

  3. 3

    Replace addresses safely

    WP-CLI replaces addresses across the database, including saved settings. Run the dry run first and read the count, then run it for real. The Better Search Replace plugin does the same from wp-admin.

    wp search-replace "http://example.com" "https://example.com" --all-tables --dry-run
    wp search-replace "http://example.com" "https://example.com" --all-tables
  4. 4

    Fix the rest by hand

    Theme files and outside embeds need their addresses changed, or the embed removed if the other site has no https.

  5. 5

    Add a safety net

    This header asks browsers to load any leftover http files over https.

    Content-Security-Policy: upgrade-insecure-requests
  6. 6

    Force https once

    Redirect every http page to https in one place: the host, Cloudflare, or .htaccess.

Stop and get help if

  • The replace dry run reports far more changes than expected.
  • Insecure scripts come from addresses you do not recognise. That can be injected code.
Fix it for me

Stop it happening again

  • Insert media through the media library, not pasted addresses.
  • Check the console after adding embeds.

Questions people ask

Why not just edit the database with SQL?

Settings are stored in a packed format that breaks if text lengths change. WP-CLI and Better Search Replace handle that.

Does mixed content hurt search?

It hurts trust first. Visitors leave pages marked not secure.

Still broken? We can fix it.