{"id":243,"date":"2026-09-25T11:58:41","date_gmt":"2026-09-25T18:58:41","guid":{"rendered":"https:\/\/hostandtech.com\/kb\/?p=243"},"modified":"2026-09-27T10:06:30","modified_gmt":"2026-09-27T17:06:30","slug":"fix-mixed-content-warnings-https","status":"publish","type":"post","link":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/","title":{"rendered":"How to Fix Mixed Content Warnings After Switching to HTTPS"},"content":{"rendered":"<h2>Overview<\/h2>\n<p>A mixed content warning means your page loads over HTTPS but still pulls some files (images, scripts, stylesheets, fonts) over plain HTTP. The fix is to change those <code class=\"\" data-line=\"\">http:\/\/<\/code> links to <code class=\"\" data-line=\"\">https:\/\/<\/code> at their source, which on WordPress usually means updating the site URL settings and running a search-and-replace on the database. Browser DevTools shows you exactly which files are at fault in under a minute.<\/p>\n<p>In Chrome&#8217;s console the error looks like this:<\/p>\n<p><code class=\"\" data-line=\"\">Mixed Content: The page at &#039;https:\/\/yourdomain.com\/&#039; was loaded over HTTPS, but requested an insecure script &#039;http:\/\/yourdomain.com\/wp-content\/...&#039;. This request has been blocked; the content must be served over HTTPS.<\/code><\/p>\n<p>This guide is for site owners who have just installed an SSL certificate, or moved a site to a new host, and now see a broken padlock, a &#8220;not fully secure&#8221; notice, or parts of the page that stopped working. You&#8217;ll find every insecure URL, fix it at the source, and set things up so it doesn&#8217;t come back. If you haven&#8217;t got a working certificate yet, read <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/what-is-ssl-certificate-and-why-you-need-it\/\">what an SSL certificate is and why you need one<\/a> first.<\/p>\n<h2>What causes mixed content<\/h2>\n<ul>\n<li><strong>Old URLs stored in the database.<\/strong> WordPress saves full URLs in posts, page builder data, widgets and theme settings. Installing SSL doesn&#8217;t change them.<\/li>\n<li><strong>Hard-coded links in theme or plugin files<\/strong>, including CSS <code class=\"\" data-line=\"\">background-image<\/code> rules and custom header or footer scripts.<\/li>\n<li><strong>Third-party resources<\/strong> embedded over HTTP: an old analytics snippet, a widget, fonts or images from a site that doesn&#8217;t support HTTPS.<\/li>\n<li><strong>Forms that post to an <code class=\"\" data-line=\"\">http:\/\/<\/code> address<\/strong>, which browsers flag with &#8220;The information you&#8217;re about to submit is not secure&#8221;.<\/li>\n<\/ul>\n<p>Modern browsers treat these differently, which is why mixed content can be hard to spot. Plain images, audio and video are upgraded to HTTPS automatically, so they often look fine. Scripts, stylesheets, fonts and iframes are blocked outright. So are images in a <code class=\"\" data-line=\"\">srcset<\/code> attribute, which WordPress uses for every responsive image. The usual result is a padlock that looks almost normal while a slider, menu, font or contact form quietly stops working.<\/p>\n<h2>How to fix mixed content warnings<\/h2>\n<h3>Fix 1: Find every insecure URL<\/h3>\n<ol>\n<li>Open the page in Chrome, Edge or Firefox and press <strong>F12<\/strong> (or <strong>Cmd+Option+I<\/strong> on a Mac).<\/li>\n<li>Open the <strong>Console<\/strong> tab and reload the page. Every line starting with <strong>Mixed Content<\/strong> names the page and the insecure file.<\/li>\n<li>Repeat on your main templates: the home page, a blog post, a product page, the cart and checkout, and any page with a form.<\/li>\n<\/ol>\n<p>To check a page&#8217;s source from a terminal, this lists every HTTP resource the HTML references:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-1\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-1'><code class=\"\" data-line=\"\">curl -s https:\/\/yourdomain.com\/ | grep -oE &#039;(src|href|srcset)=&quot;http:\/\/[^&quot;]*&quot;&#039; | sort -u<\/code><\/pre>\n<\/div>\n<p>Ignore ordinary <code class=\"\" data-line=\"\">&lt;a href&gt;<\/code> links to other websites. Linking to an HTTP page is fine; loading a file from one is the problem.<\/p>\n<h3>Fix 2: Set WordPress to use HTTPS<\/h3>\n<ol>\n<li>In WordPress, go to <strong>Settings<\/strong> &gt; <strong>General<\/strong>.<\/li>\n<li>Change <strong>WordPress Address (URL)<\/strong> and <strong>Site Address (URL)<\/strong> from <code class=\"\" data-line=\"\">http:\/\/<\/code> to <code class=\"\" data-line=\"\">https:\/\/<\/code>, and save. You&#8217;ll be logged out; log back in over HTTPS.<\/li>\n<\/ol>\n<p>If those fields are greyed out, the URLs are set in <code class=\"\" data-line=\"\">wp-config.php<\/code> as <code class=\"\" data-line=\"\">WP_HOME<\/code> and <code class=\"\" data-line=\"\">WP_SITEURL<\/code>. Edit them there with cPanel&#8217;s File Manager.<\/p>\n<h3>Fix 3: Replace old URLs in the database<\/h3>\n<p>This fixes most mixed content on WordPress sites in one pass.<\/p>\n<p><strong>Warning:<\/strong> A search-and-replace changes every matching row in the database and can&#8217;t be undone on its own. Take a full backup first, as described in <a href=\"https:\/\/hostandtech.com\/kb\/wordpress\/how-to-backup-wordpress-site\/\">how to back up your WordPress site<\/a>.<\/p>\n<p>With SSH access, WP-CLI does it safely, including serialised data that a plain SQL replace would corrupt. Run these from the site&#8217;s folder. The first command makes a backup, the second is a dry run that only reports what would change:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-2\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-2'><code class=\"\" data-line=\"\">wp db export before-https.sql\nwp search-replace &#039;http:\/\/yourdomain.com&#039; &#039;https:\/\/yourdomain.com&#039; --all-tables-with-prefix --skip-columns=guid --dry-run<\/code><\/pre>\n<\/div>\n<p>If the counts look right, run the same command without <code class=\"\" data-line=\"\">--dry-run<\/code>, then repeat it with <code class=\"\" data-line=\"\">http:\/\/www.yourdomain.com<\/code> if your site was ever reached on www. Finish with <code class=\"\" data-line=\"\">wp cache flush<\/code> and clear any caching plugin.<\/p>\n<p>Without SSH, a search-and-replace plugin such as Better Search Replace does the same job from the dashboard. Tick all tables, run it as a dry run first, and leave the GUID column alone.<\/p>\n<h3>Fix 4: Update hard-coded links in themes, CSS and page builders<\/h3>\n<p>Anything outside the database needs editing where it lives. To find those files over SSH:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-3\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-3'><code class=\"\" data-line=\"\">grep -rln &quot;http:\/\/yourdomain.com&quot; wp-content\/themes wp-content\/plugins<\/code><\/pre>\n<\/div>\n<ul>\n<li><strong>Theme files and custom CSS:<\/strong> change the URLs to <code class=\"\" data-line=\"\">https:\/\/<\/code>, or to relative paths like <code class=\"\" data-line=\"\">\/wp-content\/uploads\/logo.png<\/code>. Edit a child theme rather than the parent so an update doesn&#8217;t undo it.<\/li>\n<li><strong>Elementor:<\/strong> go to <strong>Elementor<\/strong> &gt; <strong>Tools<\/strong> &gt; <strong>Replace URL<\/strong>, then click <strong>Regenerate Files &amp; Data<\/strong> on the same screen. Elementor keeps generated CSS files that the database replace doesn&#8217;t touch.<\/li>\n<li><strong>Customizer and header\/footer script plugins:<\/strong> check <strong>Appearance<\/strong> &gt; <strong>Customize<\/strong> &gt; <strong>Additional CSS<\/strong>, and any plugin you&#8217;ve used to paste tracking codes.<\/li>\n<\/ul>\n<h3>Fix 5: Replace third-party HTTP resources<\/h3>\n<p>For files hosted on someone else&#8217;s domain, try the same URL with <code class=\"\" data-line=\"\">https:\/\/<\/code> in a new tab. If it loads, update the link. If it doesn&#8217;t, the provider doesn&#8217;t support HTTPS: download the file and host it on your own site (if its licence allows), switch to a current version of the widget, or remove it. An analytics or chat snippet from several years ago is often the culprit, and the provider will have a current HTTPS version.<\/p>\n<h3>Fix 6: Add upgrade-insecure-requests as a safety net<\/h3>\n<p>While you track down the last few URLs, you can tell browsers to request everything over HTTPS by adding this to the top of the <code class=\"\" data-line=\"\">.htaccess<\/code> file in your site&#8217;s root folder:<\/p>\n<div class='ht-code-snippet'><button class='ht-code-snippet__copy' onclick='htCopyCode(\"code-block-4\")' type='button' aria-label='Copy code'><svg class='ht-copy-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M28,10V28H10V10H28m0-2H10a2,2,0,0,0-2,2V28a2,2,0,0,0,2,2H28a2,2,0,0,0,2-2V10a2,2,0,0,0-2-2Z'><\/path><path d='M4,18H2V4A2,2,0,0,1,4,2H18V4H4Z'><\/path><\/svg><svg class='ht-check-icon' viewBox='0 0 32 32' width='16' height='16' fill='currentColor'><path d='M13,24l-9-9,1.414-1.414L13,21.171,26.586,7.586,28,9Z'><\/path><\/svg><\/button><span class='ht-code-snippet__feedback'>Copied to clipboard<\/span><\/p>\n<pre class='ht-code-snippet__code' id='code-block-4'><code class=\"\" data-line=\"\">&lt;IfModule mod_headers.c&gt;\nHeader always set Content-Security-Policy &quot;upgrade-insecure-requests&quot;\n&lt;\/IfModule&gt;<\/code><\/pre>\n<\/div>\n<p>It only helps when the resource is actually available over HTTPS, and it hides the problem from the console rather than fixing it, so treat it as a stopgap. If your site already sends a <code class=\"\" data-line=\"\">Content-Security-Policy<\/code> header (some security plugins do), add the directive to that policy instead of setting a second one. If the site shows a 500 error after the edit, remove the lines and see <a href=\"https:\/\/hostandtech.com\/kb\/wordpress\/fix-500-internal-server-error-wordpress\/\">how to fix the 500 internal server error in WordPress<\/a>.<\/p>\n<h2>How to prevent it<\/h2>\n<ul>\n<li><strong>Force HTTPS for the whole site.<\/strong> In cPanel, go to <strong>Domains<\/strong> and turn on <strong>Force HTTPS Redirect<\/strong> for the domain. It needs a valid certificate on the domain first. For Plesk, Nginx, IIS or a single-hop www rule, see <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/force-https-redirect-http-to-https\/\">how to redirect HTTP to HTTPS<\/a>.<\/li>\n<li><strong>Keep the certificate renewing.<\/strong> An expired certificate causes bigger warnings than mixed content. If AutoSSL fails, see <a href=\"https:\/\/hostandtech.com\/kb\/ssl\/ssl-certificate-not-renewing-fix\/\">SSL certificate not renewing<\/a>.<\/li>\n<li><strong>Use relative or HTTPS URLs<\/strong> in custom code, and paste media links from the Media Library rather than typing them.<\/li>\n<li><strong>Run the search-and-replace as part of every move.<\/strong> Mixed content is common after a migration, when the old site was on HTTP. The steps in <a href=\"https:\/\/hostandtech.com\/kb\/wordpress\/how-to-migrate-wordpress-to-a-new-host\/\">how to migrate WordPress to a new host<\/a> include it.<\/li>\n<li><strong>Re-check the console<\/strong> after installing a new theme, page builder template or tracking script.<\/li>\n<\/ul>\n<p>On cPanel hosting, including Host &amp; Tech <a href=\"https:\/\/hostandtech.com\/cloudlinux-cpanel-shared-hosting\">cPanel shared hosting<\/a>, open <strong>SSL\/TLS Status<\/strong> before you turn on the redirect. It shows which of your domains and subdomains have a valid certificate, and lets you run AutoSSL for any that don&#8217;t.<\/p>\n<div class=\"ht-faq-section\">\n<h2>Frequently Asked Questions<\/h2>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">What is a mixed content warning?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>It means a page loaded over HTTPS is also loading some files, such as images, scripts or stylesheets, over plain HTTP. Browsers block the insecure scripts and styles and may show a not fully secure notice, which can break parts of the page. The fix is to change those file URLs to HTTPS.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">How do I find mixed content on my site?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>Open the page, press F12 to open developer tools, and reload with the Console tab open. Each Mixed Content message names the insecure file. Check your home page, a post, a product page, checkout and any page with a form, because each template can load different files.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Why do I still get mixed content after installing SSL?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>Installing a certificate doesn&#8217;t change the URLs already saved in your site. WordPress stores full http:\/\/ addresses in posts, page builder data and theme settings, so they keep loading over HTTP until you update the site URL settings and replace the old addresses in the database.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Is a plugin like Really Simple SSL enough to fix mixed content?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>It can hide most warnings by rewriting URLs as each page is served, which is a reasonable quick fix. It doesn&#8217;t correct the stored URLs, adds work to every page load, and the warnings come back if the plugin is disabled. Fixing the URLs at the source with a database search-and-replace is the lasting solution.<\/p>\n<\/div>\n<\/div>\n<div class=\"ht-faq-item\">\n<h3 class=\"ht-faq-question\">Does mixed content affect SEO?<\/h3>\n<div class=\"ht-faq-answer\">\n<p>Indirectly, yes. Google prefers HTTPS pages, and blocked scripts or stylesheets can break layout, menus and forms, which hurts both user experience and how Google renders the page. Clearing mixed content makes sure search engines and visitors see the page as intended.<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Broken padlock or blocked scripts after installing SSL? Find every insecure URL in a minute with DevTools, fix it at the source in WordPress, themes and page builders, and make sure mixed content doesn&#8217;t come back.<\/p>\n","protected":false},"author":1,"featured_media":246,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[79],"tags":[81,103,83,92,121],"class_list":["post-243","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ssl","tag-https","tag-ssl-certificate","tag-tls","tag-wordpress","tag-wordpress-troubleshooting"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Fix Mixed Content Warnings After Enabling HTTPS<\/title>\n<meta name=\"description\" content=\"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Fix Mixed Content Warnings After Enabling HTTPS\" \/>\n<meta property=\"og:description\" content=\"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/\" \/>\n<meta property=\"og:site_name\" content=\"Host And Tech knowledge base\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/stshostandtech\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-25T18:58:41+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-27T17:06:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@stshostandtech\" \/>\n<meta name=\"twitter:site\" content=\"@stshostandtech\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/person\\\/b6fa79c48ddaba71af32e395c5b017ee\"},\"headline\":\"How to Fix Mixed Content Warnings After Switching to HTTPS\",\"datePublished\":\"2026-09-25T18:58:41+00:00\",\"dateModified\":\"2026-09-27T17:06:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/\"},\"wordCount\":1438,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fix-mixed-content-warnings-https.webp\",\"keywords\":[\"https\",\"ssl certificate\",\"tls\",\"wordpress\",\"WordPress troubleshooting\"],\"articleSection\":[\"SSL &amp; HTTPS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/\",\"name\":\"How to Fix Mixed Content Warnings After Enabling HTTPS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fix-mixed-content-warnings-https.webp\",\"datePublished\":\"2026-09-25T18:58:41+00:00\",\"dateModified\":\"2026-09-27T17:06:30+00:00\",\"description\":\"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#primaryimage\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fix-mixed-content-warnings-https.webp\",\"contentUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fix-mixed-content-warnings-https.webp\",\"width\":1200,\"height\":630,\"caption\":\"Fix mixed content warnings: find them in the browser console and change http to https at the source\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/ssl\\\/fix-mixed-content-warnings-https\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Fix Mixed Content Warnings After Switching to HTTPS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#website\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\",\"name\":\"Host And Tech knowledge base\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#organization\",\"name\":\"Host And Tech knowledge base\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/logo-dark.png\",\"contentUrl\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/logo-dark.png\",\"width\":1134,\"height\":395,\"caption\":\"Host And Tech knowledge base\"},\"image\":{\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/stshostandtech\",\"https:\\\/\\\/x.com\\\/stshostandtech\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/#\\\/schema\\\/person\\\/b6fa79c48ddaba71af32e395c5b017ee\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\\\/\\\/hostandtech.com\\\/kb\"],\"url\":\"https:\\\/\\\/hostandtech.com\\\/kb\\\/author\\\/admin_fjj7qydm\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Fix Mixed Content Warnings After Enabling HTTPS","description":"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/","og_locale":"en_US","og_type":"article","og_title":"How to Fix Mixed Content Warnings After Enabling HTTPS","og_description":"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.","og_url":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/","og_site_name":"Host And Tech knowledge base","article_publisher":"https:\/\/www.facebook.com\/stshostandtech","article_published_time":"2026-09-25T18:58:41+00:00","article_modified_time":"2026-09-27T17:06:30+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp","type":"image\/webp"}],"author":"admin","twitter_card":"summary_large_image","twitter_creator":"@stshostandtech","twitter_site":"@stshostandtech","twitter_misc":{"Written by":"admin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#article","isPartOf":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/"},"author":{"name":"admin","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/person\/b6fa79c48ddaba71af32e395c5b017ee"},"headline":"How to Fix Mixed Content Warnings After Switching to HTTPS","datePublished":"2026-09-25T18:58:41+00:00","dateModified":"2026-09-27T17:06:30+00:00","mainEntityOfPage":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/"},"wordCount":1438,"commentCount":0,"publisher":{"@id":"https:\/\/hostandtech.com\/kb\/#organization"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#primaryimage"},"thumbnailUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp","keywords":["https","ssl certificate","tls","wordpress","WordPress troubleshooting"],"articleSection":["SSL &amp; HTTPS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/","url":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/","name":"How to Fix Mixed Content Warnings After Enabling HTTPS","isPartOf":{"@id":"https:\/\/hostandtech.com\/kb\/#website"},"primaryImageOfPage":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#primaryimage"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#primaryimage"},"thumbnailUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp","datePublished":"2026-09-25T18:58:41+00:00","dateModified":"2026-09-27T17:06:30+00:00","description":"Fix mixed content warnings after enabling HTTPS: find insecure URLs in DevTools, update WordPress URLs, run a safe search-replace and stop it coming back.","breadcrumb":{"@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#primaryimage","url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp","contentUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/09\/fix-mixed-content-warnings-https.webp","width":1200,"height":630,"caption":"Fix mixed content warnings: find them in the browser console and change http to https at the source"},{"@type":"BreadcrumbList","@id":"https:\/\/hostandtech.com\/kb\/ssl\/fix-mixed-content-warnings-https\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/hostandtech.com\/kb\/"},{"@type":"ListItem","position":2,"name":"How to Fix Mixed Content Warnings After Switching to HTTPS"}]},{"@type":"WebSite","@id":"https:\/\/hostandtech.com\/kb\/#website","url":"https:\/\/hostandtech.com\/kb\/","name":"Host And Tech knowledge base","description":"","publisher":{"@id":"https:\/\/hostandtech.com\/kb\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/hostandtech.com\/kb\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/hostandtech.com\/kb\/#organization","name":"Host And Tech knowledge base","url":"https:\/\/hostandtech.com\/kb\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/logo\/image\/","url":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/05\/logo-dark.png","contentUrl":"https:\/\/hostandtech.com\/kb\/wp-content\/uploads\/2026\/05\/logo-dark.png","width":1134,"height":395,"caption":"Host And Tech knowledge base"},"image":{"@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/stshostandtech","https:\/\/x.com\/stshostandtech"]},{"@type":"Person","@id":"https:\/\/hostandtech.com\/kb\/#\/schema\/person\/b6fa79c48ddaba71af32e395c5b017ee","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/aa1edac8bbadb442e059a5b65ad45a3b2e3ce689202373b96e3e567517ae4b39?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/hostandtech.com\/kb"],"url":"https:\/\/hostandtech.com\/kb\/author\/admin_fjj7qydm\/"}]}},"_links":{"self":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/243","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/comments?post=243"}],"version-history":[{"count":1,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/243\/revisions"}],"predecessor-version":[{"id":249,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/posts\/243\/revisions\/249"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/media\/246"}],"wp:attachment":[{"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/media?parent=243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/categories?post=243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hostandtech.com\/kb\/wp-json\/wp\/v2\/tags?post=243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}