Skip to Content

HTTP links on an HTTPS page

What it is

The page is served over HTTPS, yet some of its links to your own pages are written with http://, as in http://example.com/pricing. Usually the address was pasted before the site moved to HTTPS, or a template builds links from an old site address setting.

Why it matters

Unless the site uses HSTS, following the link starts with an unencrypted request, which HTTPS exists to prevent  others on the network from reading or tampering with, before your server redirects it to HTTPS. Visitors and crawlers pay an extra round trip on every such link, and the link names an address you no longer use. Where the server has no redirect, visitors stay on the insecure version and browsers mark it as not secure.

How Asky checks it

Asky reads the page’s links from its raw HTML; JavaScript links are not seen. A link is reported when it is written as http:// on the page’s own host and the page’s final URL, after any redirect, is https://. Links to other hosts, including the other www form of your domain, are not checked. Scripts, images, stylesheets and frames loaded over http:// are reported as mixed content instead. The HTTP to HTTPS hop is not also reported as a link to a redirect. It runs in full-site and selected-page audits with Link analysis on that reached every page without blocks or errors; error pages are skipped.

Reported as a warning with medium severity.

How to fix it

  1. Change each link to https://, or better, to a relative path such as /pricing, which follows whatever protocol the page uses.
  2. Search your content for your domain written with http:// and replace it in one pass. In WordPress, check that both addresses under Settings, General start with https://, then run a search and replace over the database.
  3. Fix links in menus, footers and reusable blocks in the template, so every page is corrected at once.
  4. Keep the site-wide 301 from HTTP to HTTPS in place for links on other sites and old bookmarks.

Example

An older post on https://example.com/blog/pricing-guide still carries a link from before the move to HTTPS:

<!-- Before --> <a href="http://example.com/pricing">Compare plans</a> <!-- After --> <a href="/pricing">Compare plans</a>

← Back to Links

Last updated on