HTTPS resource security audit

Mixed Content Checker

Detect insecure resources that browsers may block or downgrade before they break page functionality and trust.

Scans returned HTML and inline CSS; client-rendered resources are not executed.

✓ Free to use ✓ No account required ✓ Up to 20 redirect hops
1

Inspect mixed HTTP resources on HTTPS pages

It inventories page resources and reports absolute HTTP images, scripts, stylesheets, frames, media and links embedded in the secure page.

2

Interpret the result

Replace each insecure reference with a verified HTTPS URL or remove the dependency, then retest the rendered production page.

3

Prioritize fixes

The static scan does not execute JavaScript, inspect every imported stylesheet or prove that an HTTP resource was loaded by the browser.

How to interpret mixed HTTP resources on HTTPS pages

It inventories page resources and reports absolute HTTP images, scripts, stylesheets, frames, media and links embedded in the secure page. The static scan does not execute JavaScript, inspect every imported stylesheet or prove that an HTTP resource was loaded by the browser.

What the tool evaluates

It inventories page resources and reports absolute HTTP images, scripts, stylesheets, frames, media and links embedded in the secure page.

  • It inventories page resources and reports absolute HTTP images, scripts, stylesheets, frames, media and links embedded in the secure page.
  • Replace each insecure reference with a verified HTTPS URL or remove the dependency, then retest the rendered production page.
  • The static scan does not execute JavaScript, inspect every imported stylesheet or prove that an HTTP resource was loaded by the browser.

Problems and next steps

Replace each insecure reference with a verified HTTPS URL or remove the dependency, then retest the rendered production page.

Frequently asked questions

What does this tool check?

It inventories page resources and reports absolute HTTP images, scripts, stylesheets, frames, media and links embedded in the secure page.

How should I use the result?

Replace each insecure reference with a verified HTTPS URL or remove the dependency, then retest the rendered production page.

What are the limits?

The static scan does not execute JavaScript, inspect every imported stylesheet or prove that an HTTP resource was loaded by the browser.

Related URL tools and guides