Knowledgebase

Preventing Mixed Content in New Content Print

  • sslcertificateshttps, https, security, plugins, themes, guide, howto, solution
  • 0

Stopping it happening again.

WHERE IT COMES FROM

Someone pasting an image URL copied from an http source An embed code copied from an old tutorial A theme or plugin setting entered with an http URL An external service referenced insecurely

PRACTICAL PREVENTION

Ensure the site address in the application is the https form, so generated links are correct Use the media library rather than pasting external image URLs When embedding from another service, copy the current code from that service rather than reusing old code Check the console after publishing anything with embedded content

FOR TEAMS

Tell whoever writes content: if you paste a URL beginning http, change it to https and check it still works. If it does not, host the resource yourself.

A PERIODIC CHECK

Run a mixed content scan quarterly, alongside your other maintenance. It takes minutes and catches anything introduced since.

WITH UPGRADE-INSECURE-REQUESTS

The header mitigates accidental introductions, but the underlying content is still wrong. Treat it as a net, not a cure.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot