Mixed Content Checker
Scan any HTTPS page for insecure HTTP resources — scripts, images, styles, and media — that trigger browser security warnings.
Blocked Content
Scripts and stylesheets loaded over HTTP are blocked by browsers. They break functionality and expose users to MITM attacks.
Optionally Blocked
Images, video, and audio served via HTTP may display but degrade your page security — triggering browser warnings.
Fully Secure
All resources must use HTTPS URLs. Use a CSP upgrade-insecure-requests directive to auto-upgrade legacy HTTP links.
How it works
Enter any HTTPS URL
We accept URLs or bare domains — HTTPS is assumed.
We fetch & parse the page
HTML is retrieved server-side and all resource references extracted.
Each URL is classified
HTTP resources are flagged as blocked or optionally-blocked.
Get an actionable report
See resource type, line number, severity — and copy the URL to fix it.