How to Fix Blocked Mixed Content Issue in WordPress

HomeBlogHow to Fix Blocked Mixed Content Issue in WordPress
How to Fix Blocked Mixed Content Issue in WordPress

An SSL certificate is only half the battle. After installing SSL in cPanel, visitors may still land on the old http:// address, or WordPress may load images, scripts, and stylesheets over insecure HTTP. This creates mixed content warnings, broken padlocks in browsers, and weaker SEO signals.

 

This comprehensive guide continues from installing an SSL certificate using cPanel. You will learn to force every request to HTTPS, update WordPress to use secure URLs, and eliminate mixed content that still points to http://.

 

Prerequisites and Pre-Flight Checklist

Before you begin, confirm the following:

Requirement

How to Verify

SSL is installed for your domain in cPanel

Check Let's Encrypt, AutoSSL, or purchased certificate status

HTTPS shows a valid padlock

Open https://yourdomain.com, it must show secure padlock, not "Not secure"

WordPress admin access

Log into https://yourdomain.com/wp-admin

File access ready

cPanel File Manager or FTP credentials available

 

Why HTTPS Redirect and Mixed Content Matter

  • SSL Certificate: Encrypts the connection between browser and server

  • HTTPS Redirect: Tells browsers and search engines that HTTPS is the canonical address

  • Mixed Content: Occurs when an HTTPS page still pulls assets (images, scripts, styles) over HTTP

 

The Issues and Errors

Modern browsers block or warn on mixed content assets, causing:

  • Pages to look broken even with SSL installed

  • "Not Secure" warnings in the address bar

  • Potential security vulnerabilities for logins and forms

  • Duplicate HTTP/HTTPS indexing in search engines

  • Weakened SEO signals

 

How to Fix

Fixing both HTTPS redirect and mixed content:

  • Keeps the padlock clean and trustworthy

  • Protects user logins and form submissions

  • Avoids duplicate content issues in search engines

  • Ensures all resources load securely

 

Force HTTPS Redirect in cPanel (.htaccess)

Most cPanel shared hosting plans use Apache servers. The cleanest server-side redirect method is through your site's .htaccess file.

Detailed Procedure

  • Log into your hosting account's cPanel dashboard

  • Navigate to the "Files" section

  • Click on "File Manager" icon

  • A new window or tab will open showing your file structure

  • Go to your site's document root directory

  • This is usually:

    • public_html (for main domain)

    • public_html/yourdomain.com (for addon domains)

    • public_html/subdirectory (for subdirectory installations)

  • Click "Settings" in the top-right corner of File Manager

  • Check "Show Hidden Files (dotfiles)"

  • Click "Save"

  • The .htaccess file should now be visible

  • Right-click on .htaccess

  • Select "Edit"

  • If prompted about encoding, click "Edit" again

  • If the file does not exist: Create a new file named .htaccess in the document root

 

Add these lines near the top of the file, before WordPress's own rewrite block:

 

apache

# Force HTTPS Redirect

RewriteEngine On

RewriteCond %{HTTPS} off

RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

 

Important Placement Note:

  • If WordPress already has a # BEGIN WordPress section, place the HTTPS rules above that block, not inside it

  • Saving inside the WordPress block can cause the rules to be overwritten when permalinks are flushed

  • The # BEGIN WordPress and # END WordPress markers are managed by WordPress

  • Click "Save Changes" button

  • Close the editor

  • Open a private/incognito browser window

  • Visit http://yourdomain.com

  • It should automatically redirect to https://yourdomain.com

 

Cloudflare Users: Critical Configuration

If you use Cloudflare as your CDN/DNS provider:

SSL Mode

Recommendation

Flexible

Avoid this mode causes redirect loops with .htaccess HTTPS rules

Full

Use after origin certificate is valid

Full (strict)

This is most secure option

How to Set Cloudflare SSL Mode:

  1. Log into Cloudflare dashboard

  2. Select your domain

  3. Go to SSL/TLS → Overview

  4. Set encryption mode to "Full" or "Full (strict)"

 

Update WordPress Site URL to HTTPS

WordPress stores your site address in the database. If these values still use http://, admin redirects, media URLs, and generated links will continue producing mixed content.

Through WordPress Admin

  • Navigate to https://yourdomain.com/wp-admin

  • Log in with your credentials

  • Go to Settings → General

 

Update Both URL Fields

Field

Correct Value

WordPress Address (URL)

https://yourdomain.com

Site Address (URL)

https://yourdomain.com

 

  • Use the exact domain you want as canonical

  • Choose either www or non-www not both

  • Do NOT mix: https://www. in one field and https:// without www in the other

  • Example of WRONG configuration:

    • WordPress Address: https://www.yourdomain.com

    • Site Address: https://yourdomain.com

  • Click "Save Changes" button

  • You may be asked to log in again

 

Emergency Database Fix (If Locked Out)

If you're locked out of admin due to a bad URL change:

  • Open cPanel File Manager

  • Navigate to your WordPress root directory

  • Right-click wp-config.php → Edit

 

Add these lines before the line that says /* That's all, stop editing! */:

 

php

define('WP_HOME', 'https://yourdomain.com');

define('WP_SITEURL', 'https://yourdomain.com');

 

  • Save the file

  • Log into WordPress admin

  • Correct Settings → General as described above

  • After confirming database values are correct in Settings → General

  • Return to wp-config.php

  • Remove the two define() lines you added

  • Save the file

 

Identify Mixed Content Warnings

Before fixing mixed content, you need to identify all instances.

Browser Develope

  • Visit your homepage over HTTPS

  • Right-click anywhere on the page

  • Select "Inspect" (Chrome/Edge) or "Inspect Element" (Firefox)

  • Click on the "Console" tab in Developer Tools

  • Look for messages containing:

    • "Mixed Content"

    • "Blocked"

    • http:// requests for images, CSS, or JavaScript

  • Click on the "Security" tab

  • Review any warnings about insecure content

  • Note which URLs are still using HTTP

  • Record the specific file paths

 

Common Sources of Mixed Content

Source

Description

Post/Page Content

Images inserted with full http:// links

Theme Options

Custom CSS or theme settings pointing to HTTP assets

Header/Footer Files

Old hardcoded URLs in header.php or footer.php

Plugins

Scripts loading from http:// CDNs or external sources

Widgets

Hardcoded HTTP links in widget content

Sliders

Slide images with HTTP URLs

Page Builders

Elementor, Divi, etc. storing absolute HTTP URLs

Custom Fields

Meta values containing HTTP URLs

 

Testing Multiple Pages

Test these pages to catch all mixed content:

  • Homepage

  • Blog post pages

  • Contact page

  • About page

  • Any page with images or embedded content

  • Archive pages

 

Replace HTTP URLs Inside WordPress

Plugins and CLI can be used for this process

Better Search Replace Plugin

For a full database replacement after SSL installation, use a proper search-replace tool that handles serialized data correctly.

Do NOT run raw SQL on wp_options or other tables unless you fully understand serialized data. Improper replacement can corrupt your database.

 

  • Go to Plugins → Add New

  • Search for "Better Search Replace"

  • Click "Install Now" then "Activate"

  • Go to Tools → Better Search Replace

Field

Value

Search for

http://yourdomain.com

Replace with

https://yourdomain.com

Select tables

Check all tables (or select specific ones)

Run as dry run

Check this first

 

  • Click "Run Search/Replace"

  • Review the match count results

  • Verify the matches are what you expect

  • Uncheck "Run as dry run"

  • Click "Run Search/Replace"

  • Wait for completion


If you also used www hostname, repeat with:

  • Search for: http://www.yourdomain.com

  • Replace with: https://www.yourdomain.com

 

Alternative Method: WP-CLI (SSH Required)

If you have SSH access:

 

bash

wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables --dry-run

wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --all-tables

wp search-replace 'http://www.yourdomain.com' 'https://www.yourdomain.com' --all-tables

 

Manual Fixes for Small Sites

  • Go to Media → Library

  • Click on each image

  • Verify the File URL uses HTTPS

  • Re-upload critical images if necessary

  • Edit each post/page

  • Switch to Code/HTML view

  • Find and replace http:// with https:// in image sources and links

  • Check header logo URL

  • Check background image URL

  • Review custom CSS for http:// references

  • Go to Appearance → Widgets

  • Review each widget for hardcoded HTTP links

  • Update image widgets, text widgets, and custom HTML widgets

  • Go to Appearance → Menus

  • Check custom links for HTTP URLs

  • Update to HTTPS

  • Elementor: Use Tools → Replace URL, then regenerate CSS

  • Divi: Check theme options for HTTP URLs

  • Beaver Builder: Review saved templates and modules

 

Post-Replacement Cleanup

  • If using a caching plugin (W3 Total Cache, WP Super Cache, etc.)

  • Purge/clear all caches

  • Log into Cloudflare if you use it

  • Go to Caching → Configuration

  • Click "Purge Everything"

  • Hard refresh: Ctrl + Shift + R (Windows) or Cmd + Shift + R (Mac)

 

Fix Remaining Theme and Plugin Mixed Content

If the Console still shows HTTP assets after database replacement:

 

Theme Troubleshooting

  • Go to Appearance → Themes

  • Activate "Twenty Twenty-Four" or another default theme

  • Check if warnings disappear

  • If warnings disappear → Problem is in your active theme's hardcoded URLs

  • If warnings persist → Problem is in plugins or other sources

  • Check header.php for hardcoded HTTP URLs

  • Check footer.php for HTTP script/style references

  • Review theme functions.php for enqueued HTTP resources

 

Plugin Troubleshooting

  • Go to Plugins → Installed Plugins

  • Deactivate all plugins

  • Reactivate one by one (or in small groups)

  • Check Console after each activation

  • Identify the plugin causing mixed content

  • Many older plugins hardcode HTTP CDN links

  • Update to latest versions

  • Check plugin settings for URL configurations

 

Third-Party Scripts and CDNs

  • Change http:// to https:// in script tags

  • Or use protocol-relative URLs: //cdn.example.com/script.js

  • Note: Only use protocol-relative URLs when the provider supports HTTPS

Old URL

New URL

http://fonts.googleapis.com/...

https://fonts.googleapis.com/...

http://ajax.googleapis.com/...

https://ajax.googleapis.com/...

http://code.jquery.com/...

https://code.jquery.com/...

 

Avoid "force HTTPS" browser plugins as your only long-term fix. They can:

  • Hide broken URLs from your view

  • Not affect what Google and other crawlers see

  • Leave insecure references in your HTML source

 

Confirm Redirects, Canonical Tags, and the Padlock

Test Redirects on your website

Test URL

Expected Result

http://yourdomain.com

301 redirect to https://yourdomain.com

http://www.yourdomain.com

Redirects consistently with preferred host

https://www.yourdomain.com

Resolves consistently with preferred host

 

  • Open homepage in browser

  • Confirm padlock icon appears

  • No "Not secure" warning

  • No mixed content warnings in Console

 

Check these pages for clean padlock:

  • Homepage

  • Blog post

  • Contact page

  • About page

  • Any page with forms

 

  • Right-click page → "View Page Source"

  • Search for http://yourdomain.com

  • It should NOT appear for local assets

  • External links to other sites may still use HTTP (this is okay)

  • If connected, log into Google Search Console

  • Monitor Coverage report for HTTP/HTTPS duplicates

  • Check after a few days for indexing changes

 

Optional Security Hardening: HSTS

Only enable HSTS after HTTPS works perfectly on all subdomains.

Add to .htaccess (after confirming HTTPS works):

 

apache

# HSTS (HTTP Strict Transport Security)

<IfModule mod_headers.c>

Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"

</IfModule>

 

HSTS Warnings:

  • Only enable when EVERY subdomain you use has valid SSL

  • Start with a short max-age (e.g., 300) for testing

  • Increase gradually (e.g., 31536000 = 1 year) once confirmed working

 

Common Problems and Quick Fixes

The usual problems that occur after HTTPS fix

Redirect Loop (ERR_TOO_MANY_REDIRECTS)

  • Browser shows "too many redirects" error

  • Page never loads

  • Usually Cloudflare Flexible SSL combined with origin HTTPS redirect

Fix:

  1. Set Cloudflare SSL to Full or Full (strict)

  2. OR temporarily remove the .htaccess HTTPS block

  3. Correct SSL mode in Cloudflare

  4. Re-add .htaccess rules

 

Admin Still Loads Over HTTP

  • WordPress admin shows "Not Secure"

  • Mixed content warnings in admin

Solution:

  1. Update Site URL settings (Step 2)

  2. Clear cookies for the domain

  3. Hard-refresh browser (Ctrl + Shift + R)

  4. If needed, add to wp-config.php:

php

define('FORCE_SSL_ADMIN', true);

 

Images Broken After Replace

  • Images show broken image icon

  • 404 errors for image files

Cause:

  • Accidentally replaced a CDN hostname

  • Replaced URLs that shouldn't have been changed

Fix:

  1. Restore from backup

  2. Replace ONLY your domain's HTTP URL

  3. Do NOT replace every http:// string in the database

 

SSL Secure on Homepage But Not /wp-admin

  • Homepage shows padlock

  • Admin area shows "Not Secure"

  • Certificate not covering all necessary domains

Solution:

  1. Install/repair certificate for:

    • Apex domain (yourdomain.com)

    • WWW subdomain (www.yourdomain.com)

    • Any admin subdomain you use

  2. Re-issue Let's Encrypt certificate to include all domains

 

Some Pages Still Show Mixed Content

  • Most pages secure

  • Specific pages show warnings

Solution:

  1. Check page-specific content (images, embeds)

  2. Review page builder settings for that page

  3. Check for custom fields with HTTP URLs

  4. Inspect widgets used only on those pages

 

Final Checks and Maintenance

You have completed the post-SSL steps that most WordPress sites miss:

  1. Server-side HTTPS redirect in cPanel .htaccess

  2. WordPress Address and Site Address set to HTTPS

  3. Database and content URLs upgraded from HTTP to HTTPS

  4. Theme/plugin mixed content cleared

  5. Browser padlock verified without warnings

  6. Redirects tested from HTTP to HTTPS

  7. Admin area loads securely

 

Keep SSL Renewal Active

  • Enable automatic SSL renewal in cPanel

  • Let's Encrypt certificates expire every 90 days

  • AutoSSL handles renewal automatically

  • Check renewal status periodically

 

Monitor for New Mixed Content

  • New plugins may introduce HTTP assets

  • Theme updates may change URLs

  • Regular Console checks recommended

 

Regular Audits

  • Monthly: Check homepage padlock

  • Quarterly: Full site scan for mixed content

  • After updates: Verify SSL still working

 

Additional Resources

  • If you need help installing SSL first, follow the guide on installing an SSL certificate using cPanel

  • Return to this article to finish redirect and mixed content cleanup

  • Contact your wordpress hosting provider if issues persist

Next Post
-