Definition · Security Headers
What is Mixed Content?
A page delivered over HTTPS but pulling in resources over HTTP is only as secure as its weakest request. The document itself is protected, while the subresources travel in the clear where they can be read and — more importantly — rewritten in transit. The browser’s padlock would be misleading, so browsers intervene.
Active and passive
Active mixed content can alter the page’s behaviour or access its DOM: scripts, stylesheets, iframes, fetch/XMLHttpRequest calls, web workers. An attacker who substitutes one of these effectively controls the page, which is equivalent to cross-site scripting with no application bug required. Browsers block this outright, and have done for years; the resource simply does not load and a console error is recorded.
Passive mixed content cannot script the page but can still mislead or leak: images, audio, video. Modern browsers automatically attempt to upgrade these requests to HTTPS, and block them if the upgrade fails, so a site relying on HTTP images will show them missing rather than insecure.
Where it comes from
Hard-coded http:// URLs in templates, content databases and legacy marketing pages are the usual source, along with third-party widgets and analytics snippets that predate the migration to HTTPS. Old CMS content is particularly stubborn, because the URLs live in stored article bodies rather than in code. Authors sometimes “fix” a blocked resource by proxying it, which preserves the underlying trust problem.
Fixing it
Rewrite absolute http:// URLs to https://, or to protocol-relative or root-relative paths where the resource is first-party. For large content sets, a database-wide search and replace is usually the practical route, followed by a crawl to catch what was missed.
Content-Security-Policy: upgrade-insecure-requests instructs the browser to upgrade subresource requests automatically, which is a useful transition measure while content is being cleaned up — but it is a mitigation, not a fix, since anything not reachable over HTTPS will still fail. Adding block-all-mixed-content behaviour or a reporting-only CSP gives visibility into which pages remain affected.
Mixed content also interacts with HSTS: once a host is covered by an HSTS policy, requests to it are upgraded before they leave the browser, so first-party mixed content quietly disappears while third-party references remain.
Related concepts
See HTTP to HTTPS redirect, subresource integrity, CSP, TLS and security headers.