SSL & Security
Mixed Content Checker
Scan a page for mixed content
Tool features
4 checks
Active & Passive Detection
Separates blocked resources from silent security downgrades
Full Resource Scan
Scripts, styles, images, frames, media and CSS url() assets
CSP & HSTS Checks
Flags missing upgrade-insecure-requests and HSTS headers
Export Options
Download the report as PDF, CSV or JSON
What is mixed content & how it works
Mixed content happens when a page loaded over HTTPS pulls in resources over plain HTTP. Those requests travel unencrypted, so anyone on the network can read or modify them, and a tampered script or stylesheet can take over the whole secure page.
Browsers block active mixed content (scripts, stylesheets, iframes) outright, which breaks layouts and features, and upgrade or warn on passive content such as images, audio and video. This tool fetches the page's HTML, lists every insecure reference by type, and checks the CSP and HSTS headers that change how browsers treat them.
Active mixed content
Scripts, stylesheets and frames over HTTP; blocked by every modern browser.
Passive mixed content
Images and media over HTTP; auto-upgraded or shown with a warning.
upgrade-insecure-requests
A CSP directive telling browsers to fetch http:// resources over https://.
How to use this tool
1
Enter an HTTPS URL
Type the full address of the page to scan, e.g. https://example.com/checkout.
2
Run the scan
The tool fetches the page and lists every resource referenced over plain HTTP.
3
Review by severity
Blocked (active) items break the page and come first; passive items follow.
4
Fix the URLs
Change each reference to https:// or a relative URL, or add upgrade-insecure-requests to your CSP as a safety net.
Related tools
5 tools
Web Security Scorecard
Grade a site across transport, HSTS, content security, cookies and headers — one weighted A-F score with the fix for every gap found
SSL Checker
Comprehensive SSL certificate analysis including validity, expiration, chain verification, TLS versions, and security assessment
HSTS Checker
Check HTTP Strict Transport Security (HSTS) header configuration and preload status
OCSP Checker
Check SSL certificate revocation status using the Online Certificate Status Protocol (OCSP)
HTTP Header Checker
Analyze HTTP response headers for any website or URL with detailed header information
Frequently asked questions
5 Q&A
Browsers remove or change the padlock when a secure page loads insecure resources. Scan the page here, fix every reported URL, and the padlock returns.
Update each
http:// reference to https:// (after confirming the resource is available over HTTPS), or use relative URLs for your own assets. In a CMS, a search-and-replace on the database usually fixes old hard-coded links.It makes browsers request
http:// resources over HTTPS, which fixes them only if the other server supports HTTPS. It is a good safety net, but fixing the URLs at source is still the right fix.The tool reads the HTML the server returns. Resources added later by JavaScript, or referenced from inside CSS files, do not appear there. Check the browser console’s Mixed Content warnings for those.