How to fix mixed content ("not fully secure") on WordPress
What mixed content is
Your page loads over https://, but something on it (an image, a stylesheet, a script, a font) is still linked with http://. Browsers either show a warning padlock or block the item, so images vanish and layouts break.
It happens after adding SSL to a site that was built on http://, or after moving a site to a new domain. The certificate is fine; the links inside your content are the problem.
Before starting, make sure the padlock is valid on a plain page. If the certificate itself is wrong, see Why does my website say "Not secure"?
Step 1: Fix the WordPress address
- In WordPress go to Settings → General.
- Make sure both WordPress Address (URL) and Site Address (URL) start with
https://. - Save. Log in again if prompted.
This fixes links WordPress generates itself, but not links stored in your posts and settings.
Step 2: Replace old links in the database
Every post, page, widget and theme option saved while the site was http:// still contains http://yourdomain. Replace them all at once.
- Back up first. A search-and-replace touches every table.
- Install and activate the Better Search Replace plugin (or an equivalent).
- Go to Tools → Better Search Replace.
- Search for:
http://example.co.za. Replace with:https://example.co.za. Use your domain, and includewww.if your site uses it. - Select all tables.
- Leave Run as dry run? ticked and click Run. It reports how many cells would change.
- Untick dry run and run it again for real.
- Repeat for
http://www.example.co.zaif you didn't includewwwabove.
Remove the plugin afterwards.
Step 3: Clear caches
- WordPress caching plugin: purge all (LiteSpeed Cache: LiteSpeed Cache → Toolbox → Purge All).
- Cloudflare, if you use it: Caching → Purge Everything.
- Your browser: reload in a private window.
Most sites are fixed at this point. If a warning remains, continue.
Step 4: Find what's left
- Open the affected page in Chrome or Firefox.
- Press F12 to open developer tools and click the Console tab.
- Reload the page. Mixed content lines say something like "Mixed Content: The page was loaded over HTTPS, but requested an insecure image 'http://…'". The URL tells you what and where.
| What the URL points to | Where to fix it |
|---|---|
| An image or logo you uploaded | Appearance → Customize → Site Identity or header settings: re-select the image |
| A font or script from a third party | The theme or plugin setting where you pasted the embed code. Change http:// to https:// |
| Something in a page builder (Elementor, WPBakery, Divi) | Open the builder, find the element, re-link the image. Elementor also has Elementor → Tools → Replace URL |
| A hard-coded link in the theme's files | Ask the theme's developer, or use a child theme |
An http:// link in a widget or menu |
Appearance → Widgets / Menus |
| Content from another site that has no HTTPS | Download the image and upload it to your own media library |
Step 5: A safety net
- Cloudflare users: turn on SSL/TLS → Edge Certificates → Automatic HTTPS Rewrites.
- Everyone else: a plugin such as Really Simple SSL can rewrite
http://tohttps://as pages are served. It's a patch, not a fix; the database replace above is the fix.
Finally, make sure every visitor lands on https://. See How to force my website to use HTTPS.
Still stuck?
Open a support ticket and include:
- The domain and one page address that still shows the warning.
- The exact mixed-content lines from the browser console (copy the text).
- What you've already done: URL settings, search-replace (and with which values), caches purged.
- Whether you use Cloudflare or a caching plugin.
Did this answer it?