Mixed content
Secure pages should load every image, script, stylesheet, and other resource over a secure connection. Silktide reports resources that a secure page loads insecurely, a problem known as mixed content.
Mixed content happens when a page served over references a resource with a plain http:// URL:
<!-- Insecure resource on a secure page -->
<script src="http://example.com/analytics.js"></script>
<!-- Serve the same resource securely -->
<script src="https://example.com/analytics.js"></script>
Why this matters
Browsers treat mixed content as a security risk. Active mixed content (scripts, stylesheets, iframes) is blocked outright by modern browsers, which can silently break page functionality. Passive mixed content (images, audio, video) may still load but triggers warnings and removes the padlock users expect from a secure site.
A single insecure resource also undermines the encryption itself: it can be read or tampered with in transit, exposing visitors on the page you promised was secure. And because your own browser may behave differently from your visitors', these failures are easy to miss manually.
How to fix it
- Change each flagged URL from
http://tohttps://. Almost every service now supports HTTPS, so usually only the URL needs updating. - Where the resource is on your own site, use relative URLs (
/images/logo.png) so it automatically inherits the page's scheme. - If a third-party resource is not available over HTTPS, replace it or host a copy yourself - browsers will not make an exception for it.
- Search your templates and database for hard-coded
http://URLs; old content is the most common source.
How Silktide tests this
- Test only pages served over HTTPS.
- Inspect the URLs of loaded resources:
srcon images, scripts, iframes, audio, video, sources, tracks, and embeds;dataon objects; andactionon forms. - Inspect
<link>elements only when theirrelloads a resource (such asstylesheet,preload,prefetch,icon,manifest). Navigational links likecanonicalandalternateare not loaded resources, so they are skipped. - Flag each element whose URL starts with
http://, individually, so it can be highlighted on the page.
Troubleshooting
The page looks fine in my browser
Some browsers automatically upgrade some mixed content to HTTPS or block it without visible errors, so a page can look fine while being broken or warned about elsewhere. Check the browser console, which lists mixed content explicitly.