How to fix mixed content ("not fully secure") on WordPress

What mixed content is

Your page loads over https://, but something on it (an image, a stylesheet, a script, a font) is still linked with http://. Browsers either show a warning padlock or block the item, so images vanish and layouts break.

It happens after adding SSL to a site that was built on http://, or after moving a site to a new domain. The certificate is fine; the links inside your content are the problem.

Before starting, make sure the padlock is valid on a plain page. If the certificate itself is wrong, see Why does my website say "Not secure"?

Step 1: Fix the WordPress address

  1. In WordPress go to Settings → General.
  2. Make sure both WordPress Address (URL) and Site Address (URL) start with https://.
  3. Save. Log in again if prompted.

This fixes links WordPress generates itself, but not links stored in your posts and settings.

Every post, page, widget and theme option saved while the site was http:// still contains http://yourdomain. Replace them all at once.

  1. Back up first. A search-and-replace touches every table.
  2. Install and activate the Better Search Replace plugin (or an equivalent).
  3. Go to Tools → Better Search Replace.
  4. Search for: http://example.co.za. Replace with: https://example.co.za. Use your domain, and include www. if your site uses it.
  5. Select all tables.
  6. Leave Run as dry run? ticked and click Run. It reports how many cells would change.
  7. Untick dry run and run it again for real.
  8. Repeat for http://www.example.co.za if you didn't include www above.

Remove the plugin afterwards.

Step 3: Clear caches

  • WordPress caching plugin: purge all (LiteSpeed Cache: LiteSpeed Cache → Toolbox → Purge All).
  • Cloudflare, if you use it: Caching → Purge Everything.
  • Your browser: reload in a private window.

Most sites are fixed at this point. If a warning remains, continue.

Step 4: Find what's left

  1. Open the affected page in Chrome or Firefox.
  2. Press F12 to open developer tools and click the Console tab.
  3. Reload the page. Mixed content lines say something like "Mixed Content: The page was loaded over HTTPS, but requested an insecure image 'http://…'". The URL tells you what and where.
What the URL points to Where to fix it
An image or logo you uploaded Appearance → Customize → Site Identity or header settings: re-select the image
A font or script from a third party The theme or plugin setting where you pasted the embed code. Change http:// to https://
Something in a page builder (Elementor, WPBakery, Divi) Open the builder, find the element, re-link the image. Elementor also has Elementor → Tools → Replace URL
A hard-coded link in the theme's files Ask the theme's developer, or use a child theme
An http:// link in a widget or menu Appearance → Widgets / Menus
Content from another site that has no HTTPS Download the image and upload it to your own media library

Step 5: A safety net

  • Cloudflare users: turn on SSL/TLS → Edge Certificates → Automatic HTTPS Rewrites.
  • Everyone else: a plugin such as Really Simple SSL can rewrite http:// to https:// as pages are served. It's a patch, not a fix; the database replace above is the fix.

Finally, make sure every visitor lands on https://. See How to force my website to use HTTPS.

Still stuck?

Open a support ticket and include:

  • The domain and one page address that still shows the warning.
  • The exact mixed-content lines from the browser console (copy the text).
  • What you've already done: URL settings, search-replace (and with which values), caches purged.
  • Whether you use Cloudflare or a caching plugin.

Did this answer it?