Website Mixed Content Checker
Fix the “not fully secure” warning. The checker lists every resource an https page loads over plain http – scripts, stylesheets, frames and objects that browsers block, and images, video, audio, srcset candidates and CSS backgrounds that cause warnings or are upgraded – and tests whether each file is also available over https, so you know which addresses you can simply change. Forms that submit to http are flagged too.
- Encrypted connection
- No sign-up
- Free to use
How to use Website Mixed Content Checker
- Enter the https address of the page.
- Click “Find mixed content”.
- Change the fixable addresses to https.
- Run the check again.
Website Mixed Content Checker features
Active and passive
Blocked vs warning.
https test
Is a secure version available?
All sources
srcset, CSS url(), media.
Forms
Insecure form actions.
Safe fetching
Public addresses only, with size and time limits.
Clear fixes
Per resource.
When to use Website Mixed Content Checker
- After moving a site to HTTPS.
- Fixing padlock warnings.
- Old blog posts with hard-coded images.
- Theme or plugin audits.
Website Mixed Content Checker FAQ
What is mixed content?
An https page that loads parts over http. Those parts can be read or changed by others on the network.
Why do some resources break the page?
Browsers block active mixed content – scripts, styles, frames – because it could take over the page.
Can a header fix it?
Content-Security-Policy: upgrade-insecure-requests makes browsers request https versions automatically, if they exist.
Does it check external CSS files?
No, only the HTML and its inline styles.
Finishing the move to HTTPS
Mixed content usually comes from hard-coded http:// addresses in old content, themes or settings. A search-and-replace in the database or templates fixes most of it.
Prefer https:// or relative addresses for every resource.
How it works: our server downloads the page once through a guarded fetcher that only connects to public addresses, follows a limited number of redirects and stops after a size and time limit. The HTML is then analysed in your browser as inert text – scripts on the page never run and nothing is stored.
What it cannot see: content and resources that a page adds with JavaScript after it loads, pages behind a login, and servers that block automated requests. For those, open the page in your browser, use its developer tools, or paste the page source where the tool offers a paste option.
Use the results as a starting point: fix the items marked red first, review the yellow warnings in context, and run the check again after a change. Requests are rate-limited to keep the service fair; if you check many pages in a row, wait a few minutes.
Related checks on this site cover the rest of a technical review – speed and Core Web Vitals, security headers, structured data, accessibility and SEO signals – so you can work through a whole site audit one topic at a time.
Who it is for: site owners checking their own pages, developers debugging a release, SEO and marketing teams auditing clients or competitors, and students learning how the web works. No account or installation is needed, and the results are plain text and tables you can copy into a report or ticket.