Mixed content scanner
Insecure Link Finder
Find HTTP resources that can prevent an HTTPS page from appearing fully secure in a browser.
Checks one public HTTPS page
SSLassist downloads up to 2 MB of HTML and does not crawl other pages. Private, local and non-HTTPS addresses are blocked.
How to fix mixed content
- Back up the website before making bulk URL changes.
- Open each HTTP URL using HTTPS. If it works correctly, update the page, theme, template or database reference to
https://. - If the external service has no HTTPS version, replace it, host the resource securely where licensing permits, or remove it.
- Purge website, plugin, server and CDN caches.
- Reload the page in a private browser window and check the browser developer console.
Where insecure URLs commonly hide
- WordPress: page-builder content, theme options, widgets, menus, Custom CSS and old database URLs.
- Images and fonts: CSS backgrounds, webfont files, logos and media inserted before HTTPS was enabled.
- Scripts and styles: old analytics, chat, advertising, CDN or plugin URLs.
- Forms and iframes: embedded booking, payment, video and contact services.
Still no secure indicator? Modern browsers may load resources with JavaScript after the initial HTML is downloaded, which this server-side check cannot see. Open the page’s developer tools, look under Console for “Mixed Content”, and also check for certificate errors, unsafe forms, browser extensions and cached content.
Continue with SSLassist
Explore more SSL tools
Move straight to the next certificate task without returning to the tools index.