What is mixed content, and why does it break secure pages?
Mixed content is a secure page that still asks for some of its parts over the old, insecure connection. Browsers refuse the risky parts outright and quietly patch the rest, so the page you tested on your own machine can arrive at a visitor with pieces missing.
What it actually is
A page is not one file. It is a document plus the scripts, styles, frames, images and video it pulls in. HTTPS protects the document, and the padlock promises that everything else came over the same protected line. Mixed content is a page that keeps that promise for the document and breaks it for one of the pieces: an address written years ago with http at the front, still sitting in a template.
Why it matters
Browsers treat the two kinds of piece differently, and both cost you. Anything that can change how the page behaves, such as a script, a stylesheet or an embedded frame, is simply refused, so a form stops working or a layout falls apart with no error a visitor can see. Images and media are upgraded to the secure address automatically, which works until the place hosting them does not answer securely, and then they vanish. Either way the page a machine renders is not the page you designed.
What good looks like
Every piece the page pulls in travels over the same secure connection as the page itself, whether it lives on your own site or on someone else's. Nothing depends on a browser rescuing an old address, and nothing that a visitor needs is quietly dropped on the way.
Being honest about it
The serious half of this is the refused half: a blocked script or stylesheet is real breakage, and we treat it that way. An old image address that browsers upgrade for you is a smaller thing and we say so — it usually works, and the risk is only that it stops working the day the other host changes. A page that is not served securely at all is a different problem, owned by the HTTPS check rather than this one.
Where most sites go wrong
Almost always it is history. A site moves to HTTPS and the new pages are clean, but an embed added to an old article, a theme setting that stored a full address, or a third-party widget written for an older web still asks for http. It only shows on the pages that carry it, which is why it survives so long: the homepage is fine, and the broken page is the one nobody opens.
Not sure where yours stands?
A free scan checks this and everything else in about 20 seconds — no signup. Or if it's already flagged and you'd rather it were simply handled, we do that too.
Flagged for this one? We handle it. No pitch, just a plain-English chat.
Book a call