Skip to content

Errors / Blocked by the browser

Mixed Content: The page at 'https://…' was loaded over HTTPS, but requested an insecure resource 'http://…'.

A secure page tried to load something over an insecure connection, and the browser refused.

Whatever it was (a script, a font, a form's target) does not load, and the browser may drop the padlock.

Why it happens

  • A hard-coded http:// URL in the content, the theme or a setting, often left from before the site moved to HTTPS.
  • An API or asset host that only offers http.
  • Images and media are upgraded to https automatically when they can be; scripts, styles, frames and data requests are blocked outright.

How to fix it

  1. Change the URL to https:// (or a relative one); in WordPress, a search-and-replace on the database after moving to HTTPS.
  2. Content-Security-Policy: upgrade-insecure-requests asks the browser to upgrade the rest.
  3. If the other host has no HTTPS, host the file yourself.

Whose problem it is

Usually the site's own code or settings.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.