Skip to content
FlexibleToolsAI
Security Toolkit · Free, Nothing Stored

Mixed Content Checker

Find out why a page isn't fully secure. The checker fetches the page and lists every resource loaded over plain http:// — scripts, stylesheets, iframes and form targets (blocked by browsers) and images, audio and video (upgraded or flagged) — so you can switch them to https://.

Enter an https:// page URL. Our server fetches the HTML and your browser scans it for http:// URLs in src, href, srcset, poster, data and action attributes and in inline CSS url() values, then classifies them as active (blocked) or passive (upgraded or warned) mixed content, with CSV export.

Instant Results

Live checks in seconds

Nothing Stored

No logs of what you check

No Sign-Up

Free, no credits or email

Suggest a Feature or Improvement for Mixed Content Checker

Need custom options, higher limits, or extra format support? Let our engineering team know!

How to use Mixed Content Checker

  1. 1Enter the HTTPS page URL.
  2. 2Review active mixed content first — it's blocked by browsers.
  3. 3Change each URL to https:// or a relative path.
  4. 4Re-scan, and add upgrade-insecure-requests as a safety net.

Active vs passive mixed content

Active content (scripts, stylesheets, iframes, fonts, XHR) could let an attacker take over the page, so browsers block it outright — often breaking layouts or features. Passive content (images, audio, video) is now automatically upgraded to HTTPS by Chrome and Firefox, and blocked if the HTTPS version doesn't exist.

Mixed content often hides in old blog posts, theme files, database-stored URLs after migrating to HTTPS, and third-party embeds.

Fixing it

Update URLs to https:// (search-and-replace in your database after a migration), use protocol-relative or relative paths for your own assets, and add Content-Security-Policy: upgrade-insecure-requests. Check the certificate itself with the SSL Checker.

Frequently Asked Questions

Why does my page still show mixed content warnings?

Resources added by JavaScript after load aren't in the HTML we scan. Check the browser's DevTools console for “Mixed Content” messages.

What do you do with the domains and URLs I check?

Our server performs the lookup once and returns the result to your browser. We don't store the addresses you check or build a history. Private and internal addresses are blocked.

Is it free? Do I need an account?

It's completely free with no sign-up and no daily credits.

Guides & Tutorials

Related Tools