HTTPS & Mixed Content 101: Why That “Not Secure” Warning Is Scaring Away Customers

You’ve got an SSL certificate. Your site loads with the little padlock. Great, right? Not always. Plenty of small business sites still show a “Not Secure” warning or a broken padlock because of something called mixed content. Here’s what it is and how to fix it.

HTTPS vs. HTTP in plain English

HTTPS means the connection between your visitor’s browser and your website is encrypted. HTTP means it isn’t. Browsers like Chrome flag HTTP pages as “Not Secure,” and Google has used HTTPS as a ranking signal for years. If someone is about to fill out your contact form and sees that warning, they leave.

What is mixed content?

Mixed content happens when a page loads over HTTPS, but some of its pieces (images, scripts, stylesheets, fonts, embedded videos) are still being pulled from old http:// addresses. The page is only partly secure, so browsers may block those elements or drop the padlock.

It usually shows up after a site moves to HTTPS, or when old blog posts and pages still contain hard-coded http:// image links.

What it costs you

  • Lost trust: A warning next to your business name looks sketchy, especially on a form or checkout page.
  • Broken pages: Blocked images, missing fonts, or sliders that don’t load.
  • SEO drag: Google wants to send people to secure, working pages.

How to find mixed content

  1. Click the padlock in Chrome. If it says the connection isn’t fully secure, you have a problem.
  2. Open DevTools (right-click, Inspect, Console). Mixed content warnings are listed with the exact file causing them.
  3. Run a crawler like Screaming Frog, or a free online scanner, to check every page at once.

How to fix it

  • Update the links: Change http:// to https:// for images, scripts, and embeds. On WordPress, a search-and-replace plugin handles this in bulk (back up first).
  • Force HTTPS sitewide: Add a 301 redirect from every HTTP URL to its HTTPS version.
  • Check third-party widgets: Old chat tools, fonts, or review widgets may use insecure URLs. Update or replace them.
  • Update your canonical tags, sitemap, and Search Console property to the HTTPS version.

Keep an eye on your certificate

SSL certificates expire. If yours lapses, visitors get a full-page browser warning that’s far scarier than mixed content. Turn on auto-renewal and put the date on your calendar.

Don’t want to deal with this yourself?

Security and technical clean-up is part of what we handle for our clients. Check out our pricing to see how affordable a professionally managed site can be, or reach out to Ignitr Digital and we’ll take a look at your site.

Leave a Reply

Discover more from IGNITR

Subscribe now to keep reading and get access to the full archive.

Continue reading