Mixed Content Checker
Find out why a page isn't fully secure. The checker fetches the page and lists every resource loaded over plain http:// — scripts, stylesheets, iframes and form targets (blocked by browsers) and images, audio and video (upgraded or flagged) — so you can switch them to https://.
Enter an https:// page URL. Our server fetches the HTML and your browser scans it for http:// URLs in src, href, srcset, poster, data and action attributes and in inline CSS url() values, then classifies them as active (blocked) or passive (upgraded or warned) mixed content, with CSV export.
Instant Results
Live checks in seconds
Nothing Stored
No logs of what you check
No Sign-Up
Free, no credits or email
Suggest a Feature or Improvement for Mixed Content Checker
Need custom options, higher limits, or extra format support? Let our engineering team know!
How to use Mixed Content Checker
- 1Enter the HTTPS page URL.
- 2Review active mixed content first — it's blocked by browsers.
- 3Change each URL to https:// or a relative path.
- 4Re-scan, and add upgrade-insecure-requests as a safety net.
Active vs passive mixed content
Active content (scripts, stylesheets, iframes, fonts, XHR) could let an attacker take over the page, so browsers block it outright — often breaking layouts or features. Passive content (images, audio, video) is now automatically upgraded to HTTPS by Chrome and Firefox, and blocked if the HTTPS version doesn't exist.
Mixed content often hides in old blog posts, theme files, database-stored URLs after migrating to HTTPS, and third-party embeds.
Fixing it
Update URLs to https:// (search-and-replace in your database after a migration), use protocol-relative or relative paths for your own assets, and add Content-Security-Policy: upgrade-insecure-requests. Check the certificate itself with the SSL Checker.
Frequently Asked Questions
Why does my page still show mixed content warnings?
Resources added by JavaScript after load aren't in the HTML we scan. Check the browser's DevTools console for “Mixed Content” messages.
What do you do with the domains and URLs I check?
Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.
Is it free? Do I need an account?
It's completely free with no sign-up and no daily credits.
Guides & Tutorials
Related Tools
SSL Checker
Check a site's SSL/TLS certificate, chain, expiry, TLS versions, HTTPS redirect and HSTS.
Security Headers Checker
Scan any website's HTTP security headers and get an A+ to F grade with fixes.
CSP Header Generator
Build a Content-Security-Policy — strict nonce-based or allowlist — for any server or framework.