Your site has SSL (the lock icon), but something isn't right — either your WordPress URLs still use http:// or some resources are loaded over insecure connections.

Why This Matters

Mixed content = your page loads over HTTPS, but some resources (images, scripts, styles) load over HTTP. This:

  • Triggers browser warnings — "This page has insecure content" or no padlock icon
  • Hurts SEO — Google prefers fully secure sites and may rank HTTPS versions higher
  • Breaks functionality — modern browsers block insecure scripts entirely, which can break forms, sliders, or checkout
  • Erodes trust — visitors see a "Not Secure" indicator

How to Diagnose

  1. Open your site in Chrome
  2. Click the padlock (or warning) icon in the address bar
  3. Click "Connection" → if it says "mixed content," you have the issue
  4. Open Developer Tools (F12) → Console tab — mixed content resources are listed as warnings

How to Fix It

Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.

Step 1: Update WordPress URLs

Go to Settings → General and make sure both URLs use https://:

  • WordPress Address (URL): https://yourdomain.com
  • Site Address (URL): https://yourdomain.com

Step 2: Search and Replace Old URLs

Old http:// URLs in your content need updating. Use the Better Search Replace plugin:

  1. Install and activate Better Search Replace
  2. Search for: http://yourdomain.com
  3. Replace with: https://yourdomain.com
  4. Select all tables
  5. Run as a dry run first to see how many changes it'll make
  6. Run for real

Step 3: Force HTTPS Redirect

Ensure all HTTP requests redirect to HTTPS. Add to .htaccess (Apache):

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

For Nginx:

server {
    listen 80;
    server_name yourdomain.com;
    return 301 https://$server_name$request_uri;
}

Step 4: Fix Remaining Mixed Content

After search-replace, check for remaining issues:

  • Theme settings: Custom CSS or settings with hard-coded http:// URLs
  • Widget content: Check all widgets for old URLs
  • External scripts: Third-party scripts loaded over HTTP need updating or replacing

What to Watch For

  • Most hosts offer free SSL via Let's Encrypt. If you don't have SSL at all, enable it in your hosting control panel first.
  • After making changes, clear all caches (plugin cache, CDN cache, browser cache).
  • Some plugins (Really Simple SSL) handle the redirect and mixed content detection automatically. It's fine for a quick fix, but the manual approach above is more permanent.
  • If you're using a CDN (Cloudflare, StackPath), make sure it's configured for HTTPS too — set SSL mode to "Full (Strict)" in Cloudflare.