The certificate is installed, the site opens on https, and the browser still says “not secure” or shows a padlock with a warning. That is mixed content: the page is secure, but part of it (an image, a font, a script) is still requested over http. The certificate is not at fault. What is left is swapping the old addresses, one by one.
First: find what still comes over http
| 1 |
Open the page with the problem and press F12 to open the browser’s developer tools. The console tab lists “Mixed Content” warnings with the exact address of each file that came over http.
|
|
| 2 |
Or search the source. Right-click, “View page source”, and search for http://. Every hit that points to an image, stylesheet or script is a suspect.
|
|
| 3 |
Sort yours from other people’s. Yours (on your own domain) are fixed inside WordPress. Third-party ones (a font, a map, an embedded video) are fixed by changing the address to https or by dropping the element.
|
|
Then: fix it at the source
| 2 |
Replace the old addresses inside your content. Images inserted into posts and pages store the full address. Use a proper search and replace tool, one that handles the data WordPress stores in a special format, and never a plain replacement in the database.
|
|
| 3 |
Look where the content is not. Widgets, the theme customiser, theme options, custom fields and plugin settings store addresses too. If you use Elementor, regenerate its styles from its tools: see using Elementor.
|
|
| 5 |
Clear the caches: the cache plugin’s, the browser’s and Cloudflare’s if you use it. A page stored before the fix keeps showing the warning.
|
|
What the browser is telling you
| Sign |
What it means |
| A padlock with a warning, or “not secure” on a single page |
That page loads at least one file over http. |
| “Not secure” on every page |
Not mixed content: the certificate is not being accepted. See the missing padlock, in order. |
| Images that do not show |
The browser blocked them for being http inside an https page. |
| A warning only on phones or only for some visitors |
A cache serving an old version of the page. |
|
A plugin that “fixes” mixed content is a plaster, not a cure. It does the swap in front of the visitor, every time the page is requested, and leaves the wrong addresses in the database. It buys time (with Really Simple SSL, for instance), but the real fix is changing the addresses at the source.
|
|
Walk the visitor’s route. After fixing, open the home page, a post, an inner page and the contact page in a private window. If the padlock stays clean on all of them, you are done. The certificate itself is issued by the server (AutoSSL); if that is what is missing, start with what an SSL certificate is.
|
|
Padlock still showing a warning after you swapped the addresses? Send us the page address and what the console says, and we will tell you whether it is the certificate or the content.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon) See plans |