Your site has SSL (the lock icon), but something isn't right — either your WordPress URLs still use http:// or some resources are loaded over insecure connections.
Why This Matters
Mixed content = your page loads over HTTPS, but some resources (images, scripts, styles) load over HTTP. This:
- Triggers browser warnings — "This page has insecure content" or no padlock icon
- Hurts SEO — Google prefers fully secure sites and may rank HTTPS versions higher
- Breaks functionality — modern browsers block insecure scripts entirely, which can break forms, sliders, or checkout
- Erodes trust — visitors see a "Not Secure" indicator
How to Diagnose
- Open your site in Chrome
- Click the padlock (or warning) icon in the address bar
- Click "Connection" → if it says "mixed content," you have the issue
- Open Developer Tools (F12) → Console tab — mixed content resources are listed as warnings
How to Fix It
Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.
Step 1: Update WordPress URLs
Go to Settings → General and make sure both URLs use https://:
- WordPress Address (URL):
https://yourdomain.com - Site Address (URL):
https://yourdomain.com
Step 2: Search and Replace Old URLs
Old http:// URLs in your content need updating. Use the Better Search Replace plugin:
- Install and activate Better Search Replace
- Search for:
http://yourdomain.com - Replace with:
https://yourdomain.com - Select all tables
- Run as a dry run first to see how many changes it'll make
- Run for real
Step 3: Force HTTPS Redirect
Ensure all HTTP requests redirect to HTTPS. Add to .htaccess (Apache):
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]For Nginx:
server {
listen 80;
server_name yourdomain.com;
return 301 https://$server_name$request_uri;
}Step 4: Fix Remaining Mixed Content
After search-replace, check for remaining issues:
- Theme settings: Custom CSS or settings with hard-coded
http://URLs - Widget content: Check all widgets for old URLs
- External scripts: Third-party scripts loaded over HTTP need updating or replacing
What to Watch For
- Most hosts offer free SSL via Let's Encrypt. If you don't have SSL at all, enable it in your hosting control panel first.
- After making changes, clear all caches (plugin cache, CDN cache, browser cache).
- Some plugins (Really Simple SSL) handle the redirect and mixed content detection automatically. It's fine for a quick fix, but the manual approach above is more permanent.
- If you're using a CDN (Cloudflare, StackPath), make sure it's configured for HTTPS too — set SSL mode to "Full (Strict)" in Cloudflare.