Introduction
After installing an SSL certificate, your website may still display a warning such as:
Not Secure
or
Mixed Content
within your web browser.
This occurs when some parts of the website are loading securely using HTTPS while other resources continue loading using HTTP.
This guide explains how to identify and resolve mixed content issues in WordPress.
What Is Mixed Content?
Mixed content occurs when a secure HTTPS page loads resources using insecure HTTP URLs.
Examples include:
- Images
- JavaScript files
- CSS files
- Fonts
- Videos
Modern browsers may block these resources or display security warnings.
Example of Mixed Content
Secure page: https://yourdomain.co.za
Insecure image: http://yourdomain.co.za/image.jpg
Because the image loads using HTTP, the browser may display a security warning.
Step 1 – Verify SSL Is Working
Open your browser and visit: https://yourdomain.co.za (Replace yourdomain.co.za with your own domain name.)
Check whether:
- The website loads successfully.
- HTTPS appears in the address bar.
- A padlock icon is displayed.
If HTTPS does not load, the SSL certificate may not be installed correctly.
Step 2 – Check the WordPress Website Address
Log into WordPress.
Open your browser and visit: https://yourdomain.co.za/wp-admin
Enter your WordPress username and password.
Click: Log In
Click: Settings
Then click: General
Verify the Following Settings
Locate: WordPress Address (URL)
Ensure it uses: https://
Example: https://yourdomain.co.za
Locate: Site Address (URL)
Ensure it also uses: https://
Example: https://yourdomain.co.za
Click: Save Changes
Step 3 – Clear Website Cache
If your website uses caching:
Clear:
- Website cache
- Plugin cache
- Browser cache
Refresh the website and test again.
Step 4 – Check Images and Content
Older content may still contain HTTP links.
Edit affected pages.
Locate any links beginning with:
http://
Replace them with:
https://
Update the page.
Step 5 – Review Theme and Plugin Settings
Some themes and plugins store their own URLs.
Review:
- Theme settings
- Slider plugins
- Gallery plugins
- Page builders
Ensure URLs use HTTPS where applicable.
Step 6 – Check Browser Developer Tools
Modern browsers can identify mixed content.
Open the affected page.
Press:
F12
Click: Console
Review any mixed content warnings displayed.
The browser may indicate exactly which files are loading insecurely.
Step 7 – Test the Website
Visit several pages on your website.
Verify:
- The padlock icon remains visible.
- No "Not Secure" warning appears.
- Images load correctly.
- Styles and functionality work correctly.
Common Causes
Old HTTP Links
Pages created before SSL installation often contain HTTP links.
Theme Settings
Themes may contain hard-coded URLs that still reference HTTP.
Plugin Configuration
Plugins sometimes store image, script or file URLs separately from WordPress settings.
Cached Content
Website caches may continue serving older HTTP references.
Website Migration
Migrated websites often contain outdated URLs that require updating.
Best Practices
To avoid mixed content issues:
- Install SSL certificates before building the website where possible.
- Always use HTTPS URLs.
- Keep WordPress updated.
- Keep plugins updated.
- Test the website after SSL installation.
Related Articles
- How to Enable HTTPS on Your Website
- How to Fix Common SEO Problems in WordPress
- How to Change Your WordPress Website URL
- How to Verify Your Website with Google Search Console
When to Contact Support
Contact support if:
- HTTPS is not loading.
- The SSL certificate appears invalid.
- Mixed content warnings continue after updating URLs.
- Multiple websites are affected.
Provide:
- The website address.
- Screenshots of the warning.
- Details of any recent website migrations or SSL changes.
Conclusion
Mixed content warnings occur when secure HTTPS pages load resources using insecure HTTP URLs.
By ensuring WordPress, plugins, themes and content all use HTTPS, you can eliminate security warnings and provide visitors with a secure browsing experience.


