Malware

Mixed content

Mixed content is an HTTPS page that pulls some resources over plain HTTP. Anyone on the network path can read or change those requests, which weakens the padlock.

How it is measured

Open the browser console on the page: it lists each blocked or warned HTTP URL. Active mixed content (scripts, stylesheets, iframes, fetch calls) is blocked by modern browsers; passive content (images, audio, video) may be upgraded to HTTPS or load with a warning. Count distinct URLs, not page loads.

To audit a whole site, crawl it and grep the rendered HTML and CSS for http:// references, then check redirects: a script requested over https that redirects to http still counts. A CSP report endpoint can log blocked loads from real visitors.

Worked example

A bakery's WooCommerce theme was moved from http to https last spring. The product page now shows a console error: the page was loaded over HTTPS but requested an insecure script, http://old-cdn.bakery.example/slider.js, and the request was blocked. The homepage slider is dead and nobody noticed on mobile.

A search of the database for 'http://bakery.example' returns 340 rows in wp_postmeta and the Customizer. A search-replace to https fixes the images, and the slider needs its script URL changed in the theme options.

How it differs

HSTS tells the browser to use HTTPS for your host and refuse a downgrade, which protects the connection to your origin. Mixed content is about what the page asks for after it loads, including third-party hosts that HSTS on your domain does not cover. A site can have HSTS and still ship an http:// script from a CDN.

Common errors

Fixing the page template and forgetting stored post content, widgets, and CSS url() values. Hard-coding http:// URLs in a plugin option. Ignoring images because they only warn. Assuming a green padlock means every sub-request is secure. Using protocol-relative // URLs on pages that might be served over HTTP.

In practice

Run a crawl after any HTTPS migration and fix the sources, not just the symptoms. Turn on upgrade-insecure-requests as a safety net while you work, then ship HSTS once nothing breaks. Replace third-party URLs that cannot serve HTTPS rather than allowing them.

See also

HSTS, Content Security Policy

Sources

Count this on a real site.

Watch my website