Skip to Content
OpportunitiesTechnicalIssue ReferenceSecurityHTTPS page loads files over HTTP

HTTPS page loads files over HTTP

What it is

The page is served over HTTPS, but its HTML loads one or more files from http:// addresses. This is called mixed content: the page itself travels encrypted, while those files do not and can be read or swapped on the way.

Why it matters

Browsers block most mixed content : most browsers block scripts, stylesheets and frames loaded over HTTP, so parts of the page can break or lose their styling. Chrome upgrades images, audio and video to HTTPS and drops any that have no HTTPS version, and browsers can mark the page as not fully secure. A script that was tampered with can change what the page shows or capture what visitors type. Crawlers that render the page may see the same broken version.

How Asky checks it

Asky reads the page’s raw HTML when its final URL is https://, and reports it when a file the browser loads starts with http://, in any letter case: the src of <script>, <img>, <iframe>, <frame>, <video>, <audio>, <source>, <track> and <embed>, srcset entries, <object data>, and <link> stylesheets, icons, preloads and manifests. Canonical and hreflang links are not counted. Not checked: CSS url() values, poster images, files added by JavaScript, and protocol-relative // addresses. One finding lists every address found. Links to http:// pages are a separate issue, and so is a page served over HTTP.

Reported as an error with high severity.

How to fix it

  1. Open the finding to see the list of http:// addresses.
  2. Check that each file loads over HTTPS, then change its address to https://. For files on your own site, a root-relative path such as /images/team.jpg works too.
  3. If a third-party file has no HTTPS version, host a copy yourself or replace the service.
  4. Fix the source rather than each page: a theme setting, an old embed code, or in WordPress a site address still set to http://. A search-and-replace in the database updates old post content.
  5. Open the page with the browser console showing: it lists mixed content of every kind, including the kinds Asky does not check.

Example

A page on https://example.com still loads a script and an image over HTTP:

<!-- Before --> <script src="http://example.com/js/chat-widget.js"></script> <img src="http://example.com/images/team.jpg" alt="Our support team"> <!-- After --> <script src="https://example.com/js/chat-widget.js"></script> <img src="/images/team.jpg" alt="Our support team">

← Back to Security

Last updated on