WordPress Mixed Content Error After SSL: The Full Fix (2026)
Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.
Mixed content = the page is https but some resources still load http. You enabled SSL, but old image URLs, scripts, and fonts still hardcode http:// - the browser shows a warning instead of a clean padlock. Fix the root: update every internal URL, not just the site setting.
Step 1: Set WordPress URLs to HTTPS
Foundation first - wp-admin > Settings > General: both "WordPress Address (URL)" and "Site Address (URL)" must start with https://. If they're still http, every internal link WordPress generates defaults to insecure. If wp-admin is inaccessible, set them in wp-config.php:
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
Step 2: Find What's Actually Loading HTTP
Before mass-replacing, see the offenders. Open the flagged page in Chrome, F12 > Console - mixed content warnings list every http URL. Typical patterns:
- -Old uploads:
http://yoursite.com/wp-content/uploads/...- search-replace fixes (step 3) - -Hardcoded theme/plugin assets:
http://in CSS files, widget code, or theme templates - manual fix (step 4) - -External resources: a third-party script or font loaded over http - update or remove it
For a site-wide scan, whynopadlock.com crawls a page and lists every insecure resource.
Step 3: Search-Replace the Database
The bulk fix - update every http://yourdomain.com URL in the database to https://. Use a serialization-safe tool: Better Search Replace plugin, or WP-CLI:
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com'
The --dry-run first shows how many replacements without changing anything. Never run a naive find-replace via SQL - WordPress stores serialized data that corrupts if you change the string length without updating the length field.
Step 4: Clean Hardcoded URLs in Files
Database clean but warnings persist? The URLs live in files, not the database. Check:
- -Theme files: header.php, footer.php, style.css for hardcoded http:// image or script URLs
- -Widgets and menus: manually-typed http:// links in Custom HTML widgets or customizer fields
- -External scripts: a font, analytics snippet, or social embed loaded over http - update the URL or remove the script
Step 5: Plugin Shortcut (If Database Edit Is Risky)
Not comfortable running search-replace? SSL Insecure Content Fixer or Really Simple SSL rewrites http asset URLs to https on the fly. Faster, doesn't touch the database - but it's a mask, not a cure. The correct fix is updating the URLs; the plugin just hides them. Use it as a bridge while you clean the database properly.
Step 6: Force HTTPS + Verify
Once URLs are clean, force the redirect so no visitor hits http accidentally. In .htaccess:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Then verify: browse a few pages, check the padlock, run the site through whynopadlock or the SSL Labs test. Clean padlock everywhere = done.
SSL Without the Headaches
Bluehost ships free SSL that auto-installs on every domain - no cert juggling, no manual HTTPS forcing. The mixed content cleanup is still on you, but the certificate layer just works. From $3.99/mo.
Get Reliable HostingRelated: redirect loop fix - 403 forbidden error - SSL certificates explained - security checklist.
What are you building?
Tell us about your project so we can match the perfect hosting plan.
Hosting Cost Calculator
See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.
Used to calculate transaction fees (Shopify charges 2% on sales)
Frequently Asked Questions
What is a mixed content error in WordPress?
The page loads over HTTPS but requests some assets (images, scripts, CSS, fonts) over HTTP. Browsers show a warning ('not fully secure', padlock with alert) instead of a clean lock. It happens when content was uploaded before SSL was enabled and URLs stayed hardcoded as http.
What's the fastest fix for mixed content?
Install the SSL Insecure Content Fixer or Really Simple SSL plugin - it rewrites http asset URLs to https on the fly and fixes most cases in one click. For the permanent fix, run a database search-replace updating http://yoursite.com to https://yoursite.com.
Why do I still see warnings after enabling SSL?
Your SSL cert covers the connection, but the page still references old http:// URLs in the database and hardcoded in files. The padlock stays broken until every internal URL is updated - a plugin or search-replace handles the bulk, then manual cleanup for hardcoded theme/plugin URLs.
How do I find which resources are loading over http?
Open the page in Chrome, press F12, go to Console - mixed content warnings list every offending URL. Or use whynopadlock.com which scans the page and lists insecure resources. The URLs usually point to old uploads, hardcoded theme image paths, or external scripts.
Does the search-replace break serialized data?
It can - WordPress stores some data serialized (widgets, settings), and naive find-replace corrupts it. Use WP-CLI (wp search-replace) or a tool that handles serialization like Better Search Replace plugin - they update values correctly without breaking the data structure.
Do I need to fix hardcoded http links?
Yes - check your theme files, widgets, menus, and customizer settings for manually-typed http:// URLs to your own domain. These don't get caught by search-replace if they were added in code rather than the database. Update each to https://.
Ready to launch?
Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.
Related Articles
Bluehost vs Competitors: The Technical Deep Dive
We ran 47 benchmarks over 90 days. Here's the raw data on why Bluehost dominates.
Fix ERR_TOO_MANY_REDIRECTS in WordPress (2026): The 6 Real Causes
ERR_TOO_MANY_REDIRECTS means an infinite redirect loop. Match your Site URLs, fix Cloudflare SSL mode, reset .htaccess, kill plugin conflicts - step-by-step with code.
WordPress 403 Forbidden Error: 7 Fixes That Actually Work (2026)
403 means the server understood you but refuses to serve the page. Fix file permissions (755/644), regenerate .htaccess, kill security plugin blocks - in the right order.
Fix 502 Bad Gateway in WordPress (2026): Diagnose First, Then Fix
502 means the gateway got a bad response from your server - usually PHP timeouts, CDN issues, or overload. A 9-step diagnostic workflow from browser checks to server logs.
Fatal Error: Maximum Execution Time Exceeded - 6 Fixes (2026)
max_execution_time kills slow updates at 30-60s. Fix the culprit plugin/theme first, then raise the limit via wp-config, .htaccess or php.ini - with exact code.
HTTP Error Uploading Images in WordPress: 9 Fixes Ranked (2026)
The vague 'HTTP error' on image upload usually means memory limits or Imagick. Fix order: rename the file, bump memory, force GD library, check permissions - with code.