Mixed Content Checker

Scan any HTTPS page for insecure HTTP resources — scripts, images, styles, and media — that trigger browser security warnings.

Blocked Content

Scripts and stylesheets loaded over HTTP are blocked by browsers. They break functionality and expose users to MITM attacks.

Optionally Blocked

Images, video, and audio served via HTTP may display but degrade your page security — triggering browser warnings.

Fully Secure

All resources must use HTTPS URLs. Use a CSP upgrade-insecure-requests directive to auto-upgrade legacy HTTP links.

How it works

01

Enter any HTTPS URL

We accept URLs or bare domains — HTTPS is assumed.

02

We fetch & parse the page

HTML is retrieved server-side and all resource references extracted.

03

Each URL is classified

HTTP resources are flagged as blocked or optionally-blocked.

04

Get an actionable report

See resource type, line number, severity — and copy the URL to fix it.