SSL & Security

Mixed Content Checker

HTTPS Audit

Scan a page for mixed content

We'll crawl the rendered page and flag any HTTP subresources loaded over an HTTPS connection.

We fetch the rendered page and flag any HTTP subresource loaded over an HTTPS connection.

Tool features

Complete mixed content analysis for any HTTPS page
4 checks

Active & Passive Detection

Separates blocked resources from silent security downgrades

Full Resource Scan

Scripts, styles, images, frames, media and CSS url() assets

CSP & HSTS Checks

Flags missing upgrade-insecure-requests and HSTS headers

Export Options

Download the report as PDF, CSV or JSON

What is mixed content & how it works

Why insecure resources break HTTPS pages

Mixed content happens when a page loaded over HTTPS pulls in resources over plain HTTP. Those requests travel unencrypted, so anyone on the network can read or modify them, and a tampered script or stylesheet can take over the whole secure page.

Browsers block active mixed content (scripts, stylesheets, iframes) outright, which breaks layouts and features, and upgrade or warn on passive content such as images, audio and video. This tool fetches the page's HTML, lists every insecure reference by type, and checks the CSP and HSTS headers that change how browsers treat them.

Active mixed content
Scripts, stylesheets and frames over HTTP; blocked by every modern browser.
Passive mixed content
Images and media over HTTP; auto-upgraded or shown with a warning.
upgrade-insecure-requests
A CSP directive telling browsers to fetch http:// resources over https://.

How to use this tool

Find and fix mixed content in four steps
1
Enter an HTTPS URL
Type the full address of the page to scan, e.g. https://example.com/checkout.
2
Run the scan
The tool fetches the page and lists every resource referenced over plain HTTP.
3
Review by severity
Blocked (active) items break the page and come first; passive items follow.
4
Fix the URLs
Change each reference to https:// or a relative URL, or add upgrade-insecure-requests to your CSP as a safety net.

Frequently asked questions

Common questions about mixed content
5 Q&A

Resources such as scripts, stylesheets, images or iframes loaded over http:// on a page that itself was loaded over https://. It undermines the page’s encryption and triggers browser blocking or warnings.

Browsers remove or change the padlock when a secure page loads insecure resources. Scan the page here, fix every reported URL, and the padlock returns.

Update each http:// reference to https:// (after confirming the resource is available over HTTPS), or use relative URLs for your own assets. In a CMS, a search-and-replace on the database usually fixes old hard-coded links.

It makes browsers request http:// resources over HTTPS, which fixes them only if the other server supports HTTPS. It is a good safety net, but fixing the URLs at source is still the right fix.

The tool reads the HTML the server returns. Resources added later by JavaScript, or referenced from inside CSS files, do not appear there. Check the browser console’s Mixed Content warnings for those.