Mixed Content Cleanup: SSL and HTTPS for Bloggers
SSL and HTTPS for bloggers: run a Padlock Sweep for mixed content—http images, old embeds, and redirects—without treating HTTPS as an SEO trophy.

The padlock is not a trophy. SSL / HTTPS means the browser and the server agreed on encryption. Mixed content means you spoiled that agreement with one leftover http:// image.
This page is a Padlock Sweep for small blogs. It is not why Google isn’t indexing your pages and not a hosting bake-off. Get a certificate from your host first—see Web Hosting for Small Blogs if you do not even have HTTPS on the plan.
Official reference: Google Search Central on HTTPS. Feature names in plugins change; the browser error text is the ground truth.
Disclosure: Security and CDN products are commercial. CashPilot may earn a commission through links we add later. No invented “HTTPS boosts rankings 5%” claims.
Table of contents
- Certificate vs mixed content
- Active vs passive mixed content
- The Padlock Sweep
- WordPress leftovers that survive plugins
- Search-replace that should not happen
- CDN and Flexible SSL
- FAQ
Certificate vs mixed content
No padlock / “Not secure” on the whole site: the certificate is missing, expired, or the visitor is still on http:// without a redirect.
Padlock with a warning, or blocked images: the HTML is HTTPS, but an asset is not. That is mixed content.
Fix the first problem at the host (issue/renew cert, force HTTPS). Let’s Encrypt explains that many hosts run ACME for you—you usually click a panel toggle, not a command line. Fix the second problem in content, theme, and embeds.
Chrome’s address bar and DevTools → Console will name the blocked URL. Trust that more than a plugin dashboard.
Active vs passive mixed content
Browsers treat mixed content in two buckets. MDN’s mixed content page is the readable spec-level summary.
Active mixed content is the dangerous class: scripts, iframes, stylesheets, some XHR. Modern browsers typically block these on HTTPS pages. A leftover HTTP analytics script can silently fail.
Passive mixed content is images, video, and audio. The page may still load, but the padlock looks wrong and some browsers will block or upgrade the request. A 2018 hero image saved as http://yoursite.com/wp-content/uploads/... is the usual blog version of this.
If pages are indexed but look broken to users, that is a trust problem, not an orphan page problem.
The Padlock Sweep
Work top to bottom. Stop when the console is quiet on three key URLs: home, one post, one image-heavy post.
PADLOCK SWEEP
1. Cert live? Host panel → HTTPS on
2. Redirect http → https (host or server)
3. Search old http://yourdomain in posts
4. Theme hardcoded http in header/footer
5. Embeds old players, maps, ads
6. Console zero mixed-content errors
Do not “fix” a third-party script by loading it over HTTP. Replace the embed or drop it.
WordPress leftovers that survive plugins
Typical leftovers:
- Media library URLs saved as
http://from an old Site URL - A page builder background image
- A custom logo path in the customizer
- An ad or affiliate script still on HTTP
- A widget that hard-codes an old feed or badge
Site URL and Home URL in Settings → General should both be https://. A force-HTTPS plugin can help redirects. It cannot invent an HTTPS version of a dead HTTP CDN.
After cleanup, spot-check Core Web Vitals. Some “fixes” load a second copy of every image.
Search-replace that should not happen
Backup first—see blog backup basics. Then run a careful replace only for your own hostname.
Do not blindly replace every http:// in the database. Payment APIs, some older embed endpoints, and plugin license servers may still be HTTP-only. Breaking those strings does not “complete HTTPS”; it breaks checkout or updates.
If only one old post is broken, edit that post. Sitewide replace is for when Search shows dozens of your own http:// media URLs.
CDN and Flexible SSL
If Cloudflare (or similar) sits in front, Flexible SSL can create mixed content: the visitor sees HTTPS, the origin still serves HTTP assets that rewrite badly. Cloudflare’s own encryption modes prefer Full or Full (strict) when the origin certificate is valid. Flexible is for origins that cannot do TLS yet.
Job map: Cloudflare for Small Blogs.
When the console is quiet, stop. The padlock’s job is to disappear so readers can finish the post.
FAQ
What is mixed content on a blog?
The page is HTTPS, but some files still load over HTTP. Browsers may block them or break the padlock. Fix the asset URL, not by turning HTTPS off.
Does HTTPS alone rank a new blog?
No. It is a baseline. Helpful content still does the ranking work. See Google’s HTTPS documentation.
Is this the same as the indexing guide?
No. This page is padlock cleanup only. Indexing blocks belong on the other URL.
Do I need to buy an SSL certificate?
Most small-blog hosts include a free certificate. Confirm on the host’s official SSL help. Let’s Encrypt is the usual issuer behind that toggle.
Should I use Cloudflare Flexible SSL forever?
No. Move to Full (strict) once the origin has a valid cert. Flexible is a crutch and can create mixed content.
Will a plugin fix everything?
It can force redirects. Hard-coded HTTP assets still need a URL fix. Check the console after.
What if only one old post is broken?
Fix that post’s media. Sitewide replace only your own hostname, after a backup.
Where does Google document HTTPS?
Search Central — HTTPS. Treat plugin marketing copy as secondary.
Keep learning
More guides in the same topic lane.
Word to PDF or Compress PDF: Which Job?
Word to PDF exports DOCX to a fixed PDF; Compress PDF shrinks a PDF you already have. Match the job to Word source files versus overweight PDF attachments.
Word OCR or PDF OCR: Which Job?
Word OCR recovers text from image-heavy DOCX files; PDF OCR adds search layers to scan PDFs. Choose by whether the client keeps Word or stays in PDF.
PDF to PPTX or Protect PDF: Which Job?
PDF to PPTX rebuilds slides for editing in PowerPoint; Protect PDF adds a password to a finished PDF. Pick by whether they need slides or a locked PDF packet.