Technical

WordPress Mixed Content Error After SSL: The Full Fix (2026)

By Daniel Reyes•October 8, 2026•3 min read

Disclosure: some links on this page are affiliate links. We may earn a commission at no extra cost to you. How we test and rate hosts.

Our top pick for most WordPress sites
Bluehost: free domain, free SSL, 24/7 support, 30-day money-back guarantee.
Check Bluehost Deal →

Mixed content = the page is https but some resources still load http. You enabled SSL, but old image URLs, scripts, and fonts still hardcode http:// - the browser shows a warning instead of a clean padlock. Fix the root: update every internal URL, not just the site setting.

Step 1: Set WordPress URLs to HTTPS

Foundation first - wp-admin > Settings > General: both "WordPress Address (URL)" and "Site Address (URL)" must start with https://. If they're still http, every internal link WordPress generates defaults to insecure. If wp-admin is inaccessible, set them in wp-config.php:

define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');

Step 2: Find What's Actually Loading HTTP

Before mass-replacing, see the offenders. Open the flagged page in Chrome, F12 > Console - mixed content warnings list every http URL. Typical patterns:

  • -Old uploads: http://yoursite.com/wp-content/uploads/... - search-replace fixes (step 3)
  • -Hardcoded theme/plugin assets: http:// in CSS files, widget code, or theme templates - manual fix (step 4)
  • -External resources: a third-party script or font loaded over http - update or remove it

For a site-wide scan, whynopadlock.com crawls a page and lists every insecure resource.

Step 3: Search-Replace the Database

The bulk fix - update every http://yourdomain.com URL in the database to https://. Use a serialization-safe tool: Better Search Replace plugin, or WP-CLI:

wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --dry-run
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com'

The --dry-run first shows how many replacements without changing anything. Never run a naive find-replace via SQL - WordPress stores serialized data that corrupts if you change the string length without updating the length field.

Step 4: Clean Hardcoded URLs in Files

Database clean but warnings persist? The URLs live in files, not the database. Check:

  • -Theme files: header.php, footer.php, style.css for hardcoded http:// image or script URLs
  • -Widgets and menus: manually-typed http:// links in Custom HTML widgets or customizer fields
  • -External scripts: a font, analytics snippet, or social embed loaded over http - update the URL or remove the script

Step 5: Plugin Shortcut (If Database Edit Is Risky)

Not comfortable running search-replace? SSL Insecure Content Fixer or Really Simple SSL rewrites http asset URLs to https on the fly. Faster, doesn't touch the database - but it's a mask, not a cure. The correct fix is updating the URLs; the plugin just hides them. Use it as a bridge while you clean the database properly.

Step 6: Force HTTPS + Verify

Once URLs are clean, force the redirect so no visitor hits http accidentally. In .htaccess:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Then verify: browse a few pages, check the padlock, run the site through whynopadlock or the SSL Labs test. Clean padlock everywhere = done.

SSL Without the Headaches

Bluehost ships free SSL that auto-installs on every domain - no cert juggling, no manual HTTPS forcing. The mixed content cleanup is still on you, but the certificate layer just works. From $3.99/mo.

Get Reliable Hosting

Related: redirect loop fix - 403 forbidden error - SSL certificates explained - security checklist.

Find Your Perfect Hosting Plan

What are you building?

Tell us about your project so we can match the perfect hosting plan.

Question 1 of 425% complete
Interactive Tool

Hosting Cost Calculator

See exactly how much you'll spend on hosting over time. Compare Bluehost vs popular alternatives and discover your potential savings.

Used to calculate transaction fees (Shopify charges 2% on sales)

Shopify Basic (3yr)
$1,044
Bluehost (3yr)
$444
You Save
$600
58% less than Shopify Basic

Frequently Asked Questions

What is a mixed content error in WordPress?

The page loads over HTTPS but requests some assets (images, scripts, CSS, fonts) over HTTP. Browsers show a warning ('not fully secure', padlock with alert) instead of a clean lock. It happens when content was uploaded before SSL was enabled and URLs stayed hardcoded as http.

What's the fastest fix for mixed content?

Install the SSL Insecure Content Fixer or Really Simple SSL plugin - it rewrites http asset URLs to https on the fly and fixes most cases in one click. For the permanent fix, run a database search-replace updating http://yoursite.com to https://yoursite.com.

Why do I still see warnings after enabling SSL?

Your SSL cert covers the connection, but the page still references old http:// URLs in the database and hardcoded in files. The padlock stays broken until every internal URL is updated - a plugin or search-replace handles the bulk, then manual cleanup for hardcoded theme/plugin URLs.

How do I find which resources are loading over http?

Open the page in Chrome, press F12, go to Console - mixed content warnings list every offending URL. Or use whynopadlock.com which scans the page and lists insecure resources. The URLs usually point to old uploads, hardcoded theme image paths, or external scripts.

Does the search-replace break serialized data?

It can - WordPress stores some data serialized (widgets, settings), and naive find-replace corrupts it. Use WP-CLI (wp search-replace) or a tool that handles serialization like Better Search Replace plugin - they update values correctly without breaking the data structure.

Do I need to fix hardcoded http links?

Yes - check your theme files, widgets, menus, and customizer settings for manually-typed http:// URLs to your own domain. These don't get caught by search-replace if they were added in code rather than the database. Update each to https://.

Ready to launch?

Get Bluehost from $3.99/month with a free domain, free SSL, and 30-day money-back guarantee.

Start for $3.99 →

Related Articles