Skip to content
Toolbench

Mixed Content Checker

Finds the http:// references that break an HTTPS page, and separates the ones browsers block outright from the ones they quietly upgrade.

Runs entirely in your browser

Loading tool...

How to use

  1. Open your page, view source, and paste the HTML here.
  2. Run the check.
  3. Fix everything under Blocked first — that is the part already broken for visitors.
  4. Copy the upgraded HTML to see what the fixed references look like.

Features

  • Tells blocked active content apart from silently upgraded passive content.
  • Reads srcset candidates and url() references in CSS, which an element-only scan misses.
  • Gives the https form of every reference as the fix.
  • Works on pasted HTML — nothing is fetched, and nothing is uploaded.

Frequently asked questions

Why does my padlock disappear on a page that looks fine?
Because passive mixed content usually still renders. The browser upgrades an insecure image to HTTPS and shows it, but the page is no longer wholly secure and the indicator changes. Active content behaves differently: a script loaded over HTTP is blocked outright, so the page loses behaviour without showing an error to the visitor.
Why paste HTML rather than enter a URL?
Because a server that fetches whatever URL a stranger types is a request-forgery hole — it can be pointed at addresses inside the network it runs in. This check needs no server at all, so the page is read in your browser and nothing is fetched.
Is a protocol-relative URL like //cdn.example.com safe?
It is not mixed content: it inherits the page’s scheme, so on an HTTPS page it loads over HTTPS. It is still worth replacing with an explicit https:// — the form is a leftover from when sites were served both ways, and it behaves differently when a page is opened from a local file.

Paste a response's headers and see which protections are missing — the ones that never show up as an error.

Build a CSP directive by directive, with the two mistakes that make a policy useless flagged as you make them.

Break a URL into its scheme, host, path, query parameters and fragment.

Mixed Content Checker — Find Insecure HTTP Resources