Launch offer: 3-day trial for $1, then $39/mo. Cancel anytime.

Technical SEO

Mixed Content

Last updated

What is Mixed Content?

Mixed content occurs when an HTTPS page loads resources (images, scripts, stylesheets, iframes) over HTTP rather than HTTPS. This creates a security vulnerability because the insecure resources can be intercepted and modified by attackers, undermining the security guarantees of HTTPS. Browsers handle mixed content in two ways: "passive" mixed content (images, audio, video) is typically loaded with a warning, while "active" mixed content (scripts, iframes) is blocked entirely in modern browsers.

Mixed content commonly occurs after an HTTP-to-HTTPS migration when internal links, image `src` attributes, or hardcoded third-party resource URLs still use `http://`. It can also arise from third-party embeds or ad networks that serve resources over HTTP. Resolving it requires updating all insecure resource references to use HTTPS or protocol-relative URLs.

Why it matters for SEO

Mixed content compromises the security benefits of HTTPS and triggers browser warnings that erode user trust. Blocked active mixed content can break page functionality entirely. From an SEO perspective, security and user experience signals — including HTTPS integrity — are factored into Google's Page Experience ranking signals.

Example

After moving to HTTPS, a blog's articles still embed images with src="http://cdn.example.com/photo.jpg". Browsers flag the pages as not fully secure, and some block insecure scripts entirely, breaking a comment widget. A search-and-replace updating those resource URLs to https:// removes the warnings and restores the widget.

Put the theory to work

LazySEO researches keywords, writes SEO articles and publishes them to your site on a schedule.

Start $1 Trial$1 today, then $39/mo. Cancel anytime.