Ffile2fix
Sign in Get started

How to fix mixed content warnings after adding SSL to WordPress

Mixed Content: The page at 'https://example.com/' was loaded over HTTPS, but requested an insecure image 'http://example.com/wp-content/uploads/2024/05/hero.jpg'. This content should also be served over HTTPS.

Your pages load over HTTPS, but some images, scripts or styles still use http:// URLs. Browsers upgrade or block these requests and remove the padlock. After moving WordPress to SSL, old URLs remain in the database, theme files and settings.

Also appears as: Mixed Content: The page at 'https://example.com/' was loaded over HTTPS, but requested an insecure script 'http://example.com/wp-includes/js/jquery/jquery.min.js'. This request has been blocked; the content must be served over HTTPS. · Not secure / padlock missing after installing an SSL certificate · Parts of this page are not secure (such as images)

Common causes

  • WordPress Address and Site Address still start with http://
  • Old http:// URLs stored in posts, widgets and page-builder data
  • Theme or plugin files with hard-coded http:// links
  • External resources (fonts, scripts, embeds) loaded over http
  • CSS files with background images using absolute http:// URLs
  • A cache or CDN still serving old HTML

How to fix it

  1. Update the site URLs. In Settings > General change both WordPress Address and Site Address to https://. This changes all URLs WordPress generates from now on.
  2. Replace old URLs in the database. Run wp search-replace 'http://example.com' 'https://example.com' --all-tables --dry-run, then run it without --dry-run. WP-CLI handles serialized data safely; never use a plain SQL REPLACE on serialized fields.
  3. Find the remaining insecure URLs. Open the browser console (F12) and reload. Each Mixed Content message shows the exact URL; search your theme, plugins and CSS for it.
  4. Fix hard-coded links in code. Replace http:// with https:// in theme and plugin files, or use functions like get_template_directory_uri() and home_url() that follow the site setting.
  5. Add an upgrade header as a safety net. Send Content-Security-Policy: upgrade-insecure-requests so browsers fetch remaining same-site http URLs over HTTPS. Keep fixing the real URLs too.
  6. Purge all caches. Clear the caching plugin, server cache and CDN so visitors get the updated HTML.

Update URLs safely with WP-CLI

wp search-replace 'http://example.com' 'https://example.com' --all-tables --dry-run
wp search-replace 'http://example.com' 'https://example.com' --all-tables
wp cache flush

How to stop it happening again

  • Use relative or function-generated URLs in themes
  • Run a search-replace after every domain or protocol change
  • Load third-party resources only over HTTPS
  • Add HSTS once the site is fully HTTPS

Frequently asked questions

Is a plugin like Really Simple SSL enough?

It can rewrite URLs on output, which hides the problem. Updating the database URLs is cleaner and faster, and works if the plugin is removed later.

Why not use SQL REPLACE in phpMyAdmin?

Many WordPress settings are serialized and store string lengths. A plain replace changes the length and corrupts the data. WP-CLI search-replace adjusts these correctly.

The padlock is still missing after fixing everything. Why?

A cached page or CSS file may still contain http URLs. Purge every cache and check the console again for the remaining URL.