No mixed HTTP/HTTPS content
Mixed content occurs when an HTTPS page loads resources (scripts, images, CSS, iframes) over unsecured HTTP. It's like sending a letter in a…
Analyse my site for freeHow TheSiteFuse checks "No mixed HTTP/HTTPS content"
Mixed content occurs when an HTTPS page loads resources (scripts, images, CSS, iframes) over unsecured HTTP. It's like sending a letter in a secure envelope but leaving some documents unencrypted inside. Modern browsers block active mixed content (scripts, CSS) and show warnings for passive mixed content (images).
Real-world impact of "No mixed HTTP/HTTPS content"
Mixed content enables man-in-the-middle attacks on HTTPS pages: an attacker can modify the HTTP script loaded by the HTTPS page. Modern browsers block these resources, causing visual errors. Google also penalises pages with mixed content warnings.
Does your site pass this check?
Run the free full audit (120 checks) and instantly discover what needs fixing.