Mixed Content Checker
Every http:// address on an HTTPS page, what browsers do with it and the fix.
Free preview.
- Free preview: the summary counts, with the first insecure addresses in full (up to 10): what browsers do with each and the fix.
- Locked until you unlock it: download and copy.
- Unlock: Pro pass, ₹179 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Check a page for mixed content
Fetching the page from MySmartCoPilot’s server… slow sites can take up to a minute.
Mixed content
Asks MySmartCoPilot’s server whether the https:// version of each insecure address answers (without downloading it), so you know which ones you can simply switch.
What was found
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
About the Mixed Content Checker
Mixed content is an HTTPS page that still loads something over plain http://: a script, a stylesheet, a font, an embedded video, an image. Browsers refuse most of it, upgrade images, audio and video to https:// (and show nothing when that address does not exist), and warn about forms that send data unencrypted. The result is a page that looks broken, or one that no longer shows as secure.
Enter a page address or paste its HTML. The checker lists every insecure address in the HTML — in src, srcset, <picture>, stylesheets and @import, @font-face, inline styles, frames, objects, preloads, icons, form actions, downloads, <base href> and meta refresh — with the line it is on, what current browsers do with it and how to fix it. It reads the page’s Content-Security-Policy too, and can check which addresses already work over HTTPS, so you know which ones you can simply switch.
How to use it
- Enter the page address in Page URL, or switch to Paste HTML and paste the page source (in the browser: View page source, select all, copy). Add the page address next to pasted HTML so relative addresses and same-site files are recognised.
- Press Find mixed content. In URL mode MySmartCoPilot’s server fetches the page once and the check runs in your browser; pasted HTML never leaves it.
- Read the summary, then the list: blocked resources first (they are missing for every visitor), then upgraded ones (they work only if the https:// address exists), then forms, redirects and notes. Each item shows the element, the line and the fix.
- Press Check HTTPS versions to see which https:// addresses answer. Where one works, replace
http://withhttps://; where none does, host the file yourself or find another provider. - Without a pass the list is a free preview: every count, and the first half of the insecure addresses in full. With a Pro pass you see all of them, can copy the report or download it as text or CSV for whoever fixes the site, and, for pasted HTML, download a copy with the working hosts switched to https://.
Examples
<script src="http://cdn.example.net/slider.js"></script>
Error · Script · <script src> Blocked: browsers refuse to run an http:// script on an HTTPS page, so whatever it does (menus, forms, analytics) is missing. Fix: Change it to https://cdn.example.net/slider.js if that address works.
<img src="http://www.example.com/logo.png" alt="Logo">
Warning · Image · <img src> Upgraded: current browsers request the https:// address instead, and the image is missing if the server does not answer over HTTPS. Fix: Use https:// or a relative address (/logo.png).
Images in srcset or <picture> are not upgraded: browsers block them.
<form action="http://forms.example.org/subscribe" method="post">
Error · Form submission · <form action> The form sends what people type to an http:// address, unencrypted.
Common uses
- Finding why the padlock disappeared, or why the browser console shows “Mixed Content” errors, after moving a site to HTTPS.
- Checking a theme, template or CMS page for hard-coded http:// addresses before going live.
- Finding third-party widgets, ad tags, fonts or embeds that still use http://, and checking whether their https:// versions work.
- Reviewing pasted HTML from an email template or landing-page builder before it goes on an HTTPS site.
Blocked or upgraded: what browsers do
Current browsers treat mixed content in two ways (MDN: Mixed content, W3C Mixed Content Level 2):
- Upgraded:
<img src>,<audio>,<video>and their<source>elements, video posters and CSS images. The browser asks for thehttps://address instead and, if the server has no HTTPS version, the file is simply missing. Older browsers load it unencrypted and stop showing the page as secure. - Blocked: everything else — scripts, stylesheets and
@import, web fonts, frames,<object>and<embed>, captions (<track>), preloads, manifests, and images insrcsetor<picture>. Upgradeable requests to an IP address are blocked too. - Forms that submit to
http://send what people type unencrypted, and browsers may warn before sending it. - Links to
http://pages are not mixed content: following a link opens a new page. The checker lists them only if you ask. http://localhostand127.0.0.1are trusted by browsers and are not mixed content, but on a public page they point to the visitor’s own computer, so they are reported as mistakes.
How to fix mixed content
- Your own files: serve them over HTTPS and write their addresses as
https://or relative (/images/logo.png), so they always follow the page. - Other sites: switch to their
https://address when it works — the HTTPS check above tells you — otherwise download the file and host it yourself, or replace the provider. - Templates and databases: a CMS often stores full
http://addresses in posts and settings; update the site address setting and search-and-replace old addresses in the content. - Safety net: the header
Content-Security-Policy: upgrade-insecure-requests(or<meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests">) makes browsers upgrade every http:// subresource and navigations within your own site. It does not create HTTPS versions that do not exist, and it does not upgrade links to other sites (MDN: upgrade-insecure-requests). block-all-mixed-contentis obsolete: the Mixed Content Level 2 draft makes it unnecessary, because browsers now block or upgrade all mixed content by default.
What is checked
Every address in the HTML that makes the browser fetch something or go somewhere: src, srcset, poster, data, background, href of stylesheets, preloads, icons and manifests, @import, url() and image-set() in <style> elements and style attributes, inline SVG <image>, <use> and <script>, form action and formaction, download links, <base href>, meta refresh, the canonical URL and social sharing images. Addresses inside <noscript> and <template> are reported with a lower severity, because browsers load them only when scripting is off or a script uses the template. Inline scripts are searched for http:// addresses, and lazy-loading attributes such as data-src are reported as the mixed content they become.
Limitations
- The check reads the HTML. Addresses inside external stylesheets and scripts, and anything a script adds after the page loads (ads, widgets, lazy loaders), are not seen; the browser console (Developer tools → Console) lists those as “Mixed Content” messages when you open the page.
- Exactly how a browser treats a borderline case (CSS images, favicons, preloaded images) can differ between browsers and versions; the checker reports the rule current browsers follow and says when a request is upgraded rather than blocked.
- The HTTPS check asks each address with a HEAD request (a GET without reading the body if that fails). A server can answer MySmartCoPilot’s server differently from a browser, and a working answer does not prove the file is the same one.
- A site can answer MySmartCoPilot’s server differently from your browser (bot protection, country or device rules), and the server reads at most 2 MiB of a page.
- Each visitor can run a limited number of server checks per hour, which keeps the service within its hosting limits. Pasted HTML is checked without any server request; only “Check HTTPS versions” asks the server.
Privacy
In Page URL mode the address is sent to MySmartCoPilot’s server, which fetches the page from the website; “Check HTTPS versions” sends the https:// addresses to check. MySmartCoPilot does not store the addresses, the HTML or the result, and the server log records only the host name, status code and time of each request, never the full URL or your IP address. In Paste HTML mode the HTML stays in your browser.
Frequently asked questions
What do I get without a pass?
Without a pass, Mixed Content Checker shows the summary counts, with the first insecure addresses in full (up to 10): what browsers do with each and the fix. Until you unlock it, the result can’t be downloaded or copied. A Pro or Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Why does my HTTPS site show “Not secure” or no padlock?
Usually because the page loads something over http:// (mixed content): an image, a script, a font or an embed. Blocked files are missing; images that older browsers load unencrypted remove the padlock. Run the checker on the page, fix what it lists, and check the browser console for anything added by scripts. An expired or mismatched certificate is the other common cause: the SSL Certificate Checker shows that.
What is the difference between active and passive mixed content?
They are the older names. “Passive” (or “optionally blockable”) content — images, audio and video — is what browsers now upgrade to https://. “Active” content — scripts, stylesheets, frames, fonts and everything else — is blocked. The checker uses the current terms and says what happens to each address.
Is upgrade-insecure-requests enough?
It is a good safety net: browsers then request https:// for every http:// subresource. But it only helps where the https:// address exists, it does not upgrade links to other sites, and the page still contains the old addresses. Fix the addresses and keep the policy.
Are protocol-relative URLs like //cdn.example.com/app.js mixed content?
No. On an HTTPS page they load over HTTPS. They are only a problem if the page itself is served over HTTP, which is a bigger problem. Writing https:// explicitly is clearer.
Can I check a page that is not public yet?
Yes: use Paste HTML and paste the page source. Nothing is sent anywhere. Add the page’s future address so the checker can tell your own files from other sites’.