You've activated SSL and waited for it to take effect, which is usually within 30 minutes and occasionally up to 2 hours. But the browser still shows "Not secure" or a warning icon instead of a padlock. In most cases the certificate is fine. The problem is mixed content.
Mixed content means the page itself loads over https://, but some of the files it uses still load over http://. A single insecure image, stylesheet or script is enough for the browser to mark the page as not fully secure. Insecure scripts and stylesheets are often blocked completely, which can break your layout.
Step 1: Find the insecure files
- Browser developer tools: open the page, press
F12(orCmd+Option+Ion a Mac) and open the Console tab. Each insecure file is listed with a "Mixed Content" warning. - Online checker: enter the page address at https://www.whynopadlock.com to get a list of the files causing the problem.
- View the source: search the page's HTML for
http://insrc=andhref=attributes.
The usual culprits are images, CSS files, JavaScript files, fonts and embedded videos or iframes.
Step 2: Change the links to HTTPS
For files on your own site, use either relative paths, which automatically follow the page's protocol:
/images/logo.png /includes/script.js
or full addresses that start with https://:
https://example.com/images/logo.png https://example.com/includes/script.js
For files loaded from other sites, such as a CDN, font service or widget, change the address to https:// and check that the provider supports it. Nearly all do. If one doesn't, host the file yourself or find a replacement.
WordPress sites
- Go to Settings → General and make sure both the WordPress Address and Site Address start with
https://. - Update old
http://links saved in your database, such as images in posts and page-builder content. Use a search-and-replace plugin such as Better Search Replace, or run WP-CLI if you use it:wp search-replace 'http://example.com' 'https://example.com' --all-tables. Take a backup first. - Check your theme and page builder settings, and any custom HTML widgets, for hard-coded
http://links. - If you want a plugin to handle this, a maintained SSL plugin such as Really Simple Security can rewrite insecure links automatically.
Quick safety net
This line in your site's .htaccess file tells modern browsers to upgrade insecure requests to HTTPS automatically:
Header always set Content-Security-Policy "upgrade-insecure-requests"
This only works for resources that are available over HTTPS. It is a safety net, not a replacement for fixing the links.
Still not secure?
- Make sure the certificate is active in StackCP under Security → SSL/TLS.
- Clear your site cache (caching plugin or CDN) and your browser cache, then test in a private window.
- Turn on Force HTTPS so visitors can't end up on the
http://version.
Need help?
If something doesn't work as described, open a support ticket from your FimuroHost client area or message us on WhatsApp at 01818160926. Please include your domain name so we can check your account quickly.
Categories
Written by
FimuroHost Team
Technical Writer