Errors / Blocked by the browser
Mixed Content: The page at 'https://…' was loaded over HTTPS, but requested an insecure resource 'http://…'.
A secure page tried to load something over an insecure connection, and the browser refused.
Whatever it was (a script, a font, a form's target) does not load, and the browser may drop the padlock.
Why it happens
- A hard-coded
http://URL in the content, the theme or a setting, often left from before the site moved to HTTPS. - An API or asset host that only offers
http. - Images and media are upgraded to
httpsautomatically when they can be; scripts, styles, frames and data requests are blocked outright.
How to fix it
- Change the URL to
https://(or a relative one); in WordPress, a search-and-replace on the database after moving to HTTPS. Content-Security-Policy: upgrade-insecure-requestsasks the browser to upgrade the rest.- If the other host has no HTTPS, host the file yourself.
Whose problem it is
Usually the site's own code or settings.
Does your site have it?
Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.