Common causes
- WordPress Address and Site Address still start with http://
- Old http:// URLs stored in posts, widgets and page-builder data
- Theme or plugin files with hard-coded http:// links
- External resources (fonts, scripts, embeds) loaded over http
- CSS files with background images using absolute http:// URLs
- A cache or CDN still serving old HTML
How to fix it
- Update the site URLs. In Settings > General change both WordPress Address and Site Address to https://. This changes all URLs WordPress generates from now on.
- Replace old URLs in the database. Run wp search-replace 'http://example.com' 'https://example.com' --all-tables --dry-run, then run it without --dry-run. WP-CLI handles serialized data safely; never use a plain SQL REPLACE on serialized fields.
- Find the remaining insecure URLs. Open the browser console (F12) and reload. Each Mixed Content message shows the exact URL; search your theme, plugins and CSS for it.
- Fix hard-coded links in code. Replace http:// with https:// in theme and plugin files, or use functions like get_template_directory_uri() and home_url() that follow the site setting.
- Add an upgrade header as a safety net. Send Content-Security-Policy: upgrade-insecure-requests so browsers fetch remaining same-site http URLs over HTTPS. Keep fixing the real URLs too.
- Purge all caches. Clear the caching plugin, server cache and CDN so visitors get the updated HTML.
Update URLs safely with WP-CLI
wp search-replace 'http://example.com' 'https://example.com' --all-tables --dry-run
wp search-replace 'http://example.com' 'https://example.com' --all-tables
wp cache flush How to stop it happening again
- Use relative or function-generated URLs in themes
- Run a search-replace after every domain or protocol change
- Load third-party resources only over HTTPS
- Add HSTS once the site is fully HTTPS