About Mixed Content Checker
After a move to HTTPS, a missing padlock usually means mixed content: files the page still loads over plain http://. This mixed content checker reads your HTTPS page and lists them. Active content, meaning scripts, stylesheets, iframes, objects and form targets, is blocked by browsers and can break the page. Passive content, such as images, video and audio, srcset entries and CSS url() references in the page, costs you the padlock.
For the first 40 addresses found, the checker also tests whether the same file works over https://. Those you can fix by changing http:// to https:// in your templates, database or CDN settings, while the rest need a new source or a copy on your own server. Export the list as CSV for whoever maintains the site. An http:// address you enter is checked as https://. To make sure HTTP itself redirects to HTTPS, use the Redirect Checker.
How to use Mixed Content Checker
- 1Enter the HTTPS page
Paste the page address, and an http:// address is checked as https://.
- 2Click Check
We read the HTML and collect every http:// resource in it.
- 3Review the list
Each entry shows its type, whether browsers block it and whether it works over HTTPS.
- 4Fix and export
Switch the links to https://, or download the list as CSV for your developer.
Why use Cubfile for this
- Active and passive
Scripts, styles, frames, objects and forms, plus images, media, srcset and CSS url().
- HTTPS tested for you
The first 40 insecure addresses are tried over https:// automatically.
- Blocked or downgraded
See which files browsers block outright and which only cost you the padlock.
- CSV export
Hand the full list to a developer or work through it in a spreadsheet.