How to Fix Mixed Content and 'Not Secure' Warnings in WordPress

Introduction

After installing an SSL certificate, your website may still display a warning such as:

Not Secure

or

Mixed Content

within your web browser.

This occurs when some parts of the website are loading securely using HTTPS while other resources continue loading using HTTP.

This guide explains how to identify and resolve mixed content issues in WordPress.


What Is Mixed Content?

Mixed content occurs when a secure HTTPS page loads resources using insecure HTTP URLs.

Examples include:

  • Images
  • JavaScript files
  • CSS files
  • Fonts
  • Videos

Modern browsers may block these resources or display security warnings.


Example of Mixed Content

Secure page:  https://yourdomain.co.za

 

Insecure image:  http://yourdomain.co.za/image.jpg

 

Because the image loads using HTTP, the browser may display a security warning.


Step 1 – Verify SSL Is Working

Open your browser and visit:  https://yourdomain.co.za   (Replace yourdomain.co.za with your own domain name.)

Check whether:

  • The website loads successfully.
  • HTTPS appears in the address bar.
  • A padlock icon is displayed.

If HTTPS does not load, the SSL certificate may not be installed correctly.


Step 2 – Check the WordPress Website Address

Log into WordPress.

Open your browser and visit:  https://yourdomain.co.za/wp-admin 

Enter your WordPress username and password.

Click: Log In

Click: Settings

Then click: General


Verify the Following Settings

Locate: WordPress Address (URL)

Ensure it uses: https://

Example: https://yourdomain.co.za


Locate: Site Address (URL)

Ensure it also uses: https://

Example: https://yourdomain.co.za

Click: Save Changes


Step 3 – Clear Website Cache

If your website uses caching:

Clear:

  • Website cache
  • Plugin cache
  • Browser cache

Refresh the website and test again.


Step 4 – Check Images and Content

Older content may still contain HTTP links.

Edit affected pages.

Locate any links beginning with:

 
http://
 

Replace them with:

 
https://
 

Update the page.


Step 5 – Review Theme and Plugin Settings

Some themes and plugins store their own URLs.

Review:

  • Theme settings
  • Slider plugins
  • Gallery plugins
  • Page builders

Ensure URLs use HTTPS where applicable.


Step 6 – Check Browser Developer Tools

Modern browsers can identify mixed content.

Open the affected page.

Press:

F12

Click: Console

Review any mixed content warnings displayed.

The browser may indicate exactly which files are loading insecurely.


Step 7 – Test the Website

Visit several pages on your website.

Verify:

  • The padlock icon remains visible.
  • No "Not Secure" warning appears.
  • Images load correctly.
  • Styles and functionality work correctly.

Common Causes

Old HTTP Links

Pages created before SSL installation often contain HTTP links.


Theme Settings

Themes may contain hard-coded URLs that still reference HTTP.


Plugin Configuration

Plugins sometimes store image, script or file URLs separately from WordPress settings.


Cached Content

Website caches may continue serving older HTTP references.


Website Migration

Migrated websites often contain outdated URLs that require updating.


Best Practices

To avoid mixed content issues:

  • Install SSL certificates before building the website where possible.
  • Always use HTTPS URLs.
  • Keep WordPress updated.
  • Keep plugins updated.
  • Test the website after SSL installation.

Related Articles

  • How to Enable HTTPS on Your Website
  • How to Fix Common SEO Problems in WordPress
  • How to Change Your WordPress Website URL
  • How to Verify Your Website with Google Search Console

When to Contact Support

Contact support if:

  • HTTPS is not loading.
  • The SSL certificate appears invalid.
  • Mixed content warnings continue after updating URLs.
  • Multiple websites are affected.

Provide:

  • The website address.
  • Screenshots of the warning.
  • Details of any recent website migrations or SSL changes.

Conclusion

Mixed content warnings occur when secure HTTPS pages load resources using insecure HTTP URLs.

By ensuring WordPress, plugins, themes and content all use HTTPS, you can eliminate security warnings and provide visitors with a secure browsing experience.

  • ssl troubleshooting, not secure warning, website troubleshooting, wordpress troubleshooting
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

What to Do If You Forget Your WordPress Password

Introduction If you cannot log into your WordPress website because you have forgotten your...

What to Do If You Are Locked Out of WordPress

Introduction There are several reasons why you may be unable to access your WordPress...

How to Fix a White Screen in WordPress

Introduction A white screen in WordPress, often referred to as the White Screen of Death (WSOD),...

How to Disable a WordPress Plugin When You Cannot Log In

Introduction Sometimes a plugin can cause problems that prevent you from accessing either your...

How to Recover a Deleted Page or Post in WordPress

Introduction Accidentally deleting a page or post is a common mistake in WordPress....