You installed an SSL certificate, the address starts with https://, yet the browser still shows a warning instead of a clean padlock, or images and scripts are missing. The usual cause is mixed content: a secure page that still loads some files over plain http://. This guide explains what browsers do with mixed content in 2026, how to find every insecure link, and how to fix it for good on WordPress and hand-built sites.
Mixed content means an HTTPS page loads images, scripts, stylesheets or iframes over http://. Browsers now try to upgrade images, audio and video to HTTPS and block them if that fails, and they block insecure scripts, stylesheets and iframes outright. Find the http:// links in the browser console, change them to https:// in your theme, content and database, then force HTTPS with one redirect.
1. What mixed content is
A page is loaded over HTTPS, so the page itself is encrypted. But inside it, some resources still point to http:// addresses. Those requests travel unencrypted, so someone on the same network could read or change them. That is why browsers treat them as a security problem.
There are two kinds:
| Type | Examples | What modern browsers do |
|---|---|---|
| Passive (display) content | Images, audio, video | Try to load them over HTTPS instead; block them if HTTPS fails, and remove the secure padlock or show a warning |
| Active content | Scripts, stylesheets, iframes, fonts, fetch/XHR requests | Block them outright |
The old Firefox message "Loading mixed (insecure) display content" referred to passive content. Today the result is usually one of two things: a missing image or broken layout, or a padlock that shows a warning.
2. Why it matters
- Broken pages. A blocked stylesheet or script can break your menu, slider, checkout or contact form.
- Trust. Visitors who see a warning instead of a padlock are less likely to buy or fill in a form.
- Security. An insecure script can be replaced in transit, which gives an attacker control of the whole page.
3. Find every insecure resource
- Open the page in Chrome, Edge or Firefoxand press F12 (Cmd+Option+I on a Mac) to open developer tools.
- Open the Console tab and reload.Each problem appears as a "Mixed Content" line naming the page and the exact http:// address, and whether it was upgraded or blocked.
- Check the Network tab.Filter by "http:" to see every request that was not secure.
- Click the padlock or warning iconnext to the address bar to see the browser's security summary.
- Repeat on key pages.Check the home page, a post or product, the cart and checkout, and the contact page. Mixed content is often on one template only.
Note down where each insecure address comes from: your own domain, a theme or plugin file, or a third-party service.
4. Fix it on a WordPress site
Most WordPress mixed content comes from old http:// addresses stored in the database: image links inside posts, widget text, theme settings and page builder data.
- Take a backup first.Download a copy of your files and database, or check your latest JetBackup copy, before changing anything.
- Set both site addresses to https.In Settings › General, set WordPress Address (URL) and Site Address (URL) to
https://yourdomain.com(with or without www, matching your redirect). - Replace old addresses in the database.Use a search-and-replace tool that understands WordPress's serialized data, such as the Better Search Replace plugin, or WP-CLI (below). Search for
http://yourdomain.comand replace withhttps://yourdomain.com. Run a dry run first. - Check your theme and plugins.Hard-coded http:// links in a theme's files or in a plugin's settings will not be touched by the database replacement. Update the theme and plugins, and edit custom code by hand.
- Clear every cache.Clear your caching plugin (WP Super Cache or W3 Total Cache), any Cloudflare cache, and your browser cache, then test again.
If jailed SSH is enabled on your account, WP-CLI does the replacement in one step. Jailed SSH is available on every shared hosting plan but is off by default; ask support to enable it.
cd ~/public_html
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tablesWordPress stores many settings as serialized data, which records the length of each string. A plain SQL REPLACE in phpMyAdmin changes the text but not the length, and the setting silently breaks. Use WP-CLI or a serialization-aware plugin.
A plugin that rewrites http:// to https:// on the fly can hide the symptoms, but it adds work to every page load and hides links that are still wrong. Fix the stored addresses and keep a plugin only as a temporary bridge.
5. Fix it on a hand-built or other CMS site
- Search your files. Look for
http://in HTML, PHP templates, CSS (url(...)and@import) and JavaScript. Change your own domain's links to https:// or to root-relative paths such as/images/logo.png. - Avoid protocol-relative links. Addresses that start with
//were a workaround years ago. Today, usehttps://explicitly. - Check third-party embeds. Fonts, maps, video players, chat widgets, analytics and payment scripts must all load over HTTPS. If a provider has no HTTPS version, replace it.
- Check your CDN. If images or scripts are served from a CDN or subdomain, that host needs a valid certificate too.
- Check the database of other CMSs (Joomla, Drupal, PrestaShop) for stored http:// links, using the CMS's own tools where they exist.
6. Force HTTPS and add a safety net
Once the links are fixed, make sure every visitor lands on HTTPS:
- cPanel: the Domains page has a Force HTTPS Redirect switch for each domain.
- Any Apache host: an
.htaccessredirect works on our cPanel, DirectAdmin and Webuzo servers. Use one method, not several, or you risk "too many redirects". The tested rules are in How do I redirect non-www to www.
As an extra safety net, a Content Security Policy can tell browsers to upgrade any http:// resource your page still requests. Add it in your theme's header:
<meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests">It only helps if the resource is also available over HTTPS. It does not replace fixing the links.
On our cPanel servers a front-end cache can keep a copy of a page for up to two hours. Add ?t=123 to the address to see the fresh version before deciding the fix did not work.
7. SSL on Domain India hosting
Every Domain India shared hosting plan includes free SSL: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt on DirectAdmin. Certificates are issued and renewed automatically once your domain points to the hosting. The certificate protects the page; clearing mixed content is what gives you the clean padlock.
- Set up or check your certificate: How to enable free SSL with Let's Encrypt.
- Manage certificates in cPanel: How to manage SSL certificates in cPanel.
- Using Cloudflare in front of your site? Set SSL mode to Full (strict); see the complete Cloudflare setup guide.
If you are choosing hosting for a new WordPress site, see WordPress hosting or compare plans on cPanel hosting.
What does "mixed content" mean?
It means a page loaded over HTTPS also requests images, scripts, stylesheets or other files over plain http://. Those requests are not encrypted, so browsers upgrade or block them and may show a warning instead of a secure padlock.
Why does my site still show "Not secure" after installing SSL?
The certificate is working, but something on the page is still loaded over http://. Open the browser console (F12), reload the page and look for "Mixed Content" lines that name the insecure addresses.
How do I fix mixed content in WordPress?
Set both addresses in Settings, General to https, then replace http://yourdomain.com with https://yourdomain.com in the database using WP-CLI search-replace or a serialization-aware plugin, update the theme and plugins, and clear all caches.
Is it safe to use a plain SQL query in phpMyAdmin to replace http with https?
Not for WordPress. Many WordPress settings are serialized, and a plain SQL REPLACE breaks their stored lengths. Use WP-CLI or a plugin such as Better Search Replace.
Should I use protocol-relative URLs that start with two slashes?
No. Use https:// explicitly, or root-relative paths for files on your own domain. Protocol-relative URLs are an outdated workaround.
Does Domain India hosting include SSL?
Yes. Domain India shared hosting includes free SSL: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt on DirectAdmin, issued automatically once the domain points to the hosting.
Ready to get a clean padlock? Check your certificate with How to enable free SSL with Let's Encrypt, then set up a single HTTPS redirect using How do I redirect non-www to www. If a warning will not go away, open a support ticket with the page address.
Send us the page address and a screenshot of the browser console, and our team will help you track down the insecure links.
Open a support ticket