My website shows as insecure due to mixed content?

If the website is now showing your certificate but still has an insecure warning, this is often caused by ‘mixed content’ on the website. This means there is content on the page that is being loaded through a ‘http://’ URL. For a webpage to be classed as secure, all content must be loaded over HTTPS. This includes external images, JavaScript and CSS. You should search the source code of your website to locate the ‘http://’ references and update or remove them.

Finding Mixed Content

When visiting an HTTPS page in Google Chrome, the browser alerts you to mixed content as errors and warnings in the JavaScript console. You can open the console either from the View menu: View -> Developer -> JavaScript Console, or by right-clicking the page, selecting ‘Inspect Element’, then selecting ‘Console’. You need to remove or update the ‘http://’ URLs listed in these errors and warnings in your sites source.

If your site is hosted on our Web Hosting you can also use ‘Why No Padlock?’ to identify mixed content: https://www.whynopadlock.com/

If the site is running WordPress, you can use the SSL Insecure Content Fixer plugin that should identify all mixed content and replace it with a secure version for you. You can find the plugin here: https://en-gb.wordpress.org/plugins/ssl-insecure-content-fixer/

Once all references on your website are called using https:// URLs, your site will load securely in your browser.

Download Our AI Solutions Brochure

Download our AI Services brochure to discover how AI can revolutionise your business. Learn the best approaches for AI adoption, cost-effective implementation strategies, and how to maximise ROI with tailored solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *