The padlock disappeared after moving to HTTPS
The certificate is valid, the site answers over HTTPS, and yet the padlock is crossed out or carries a warning. This is not a certificate problem: the page, served securely, is fetching part of its content over an insecure address. The browser flags it, and sometimes blocks the element outright.
Two levels of severity
Browsers distinguish passive mixed content — images, video, audio — from active mixed content — stylesheets, scripts, embedded frames. The first is displayed but downgrades the security indicator. The second is blocked outright, because a script loaded in the clear could be swapped in transit.
That explains a confusing symptom: after moving to HTTPS, the layout collapses or a feature stops responding although nothing was changed in the code. The file exists, it is simply refused by the browser. The browser console then names each blocked resource precisely.
Where the remaining HTTP addresses hide
-
In descriptions entered in the admin
This is the most frequent source and the longest to clean: years of product pages containing images pasted with their full http address.
-
In the CMS settings
The shop address is stored in the database. While it stays on http, some generated links stay there too, including inside emails.
-
In the theme and modules
An address hard-coded in a template or stylesheet escapes any database replacement.
-
In third-party scripts
Old tracking tags, fonts, maps, libraries called from an external service that no longer offers a secure version.
-
In the stylesheets themselves
A background image declared over http inside a CSS file does not appear in the page source: only the browser console shows it.
What is left to check
Once mixed content is dealt with, two points finish the job. The permanent redirect from the insecure address to the secure one must be single and direct: a chain of cascading redirects dilutes the signal sent to search engines and slows every visit. And the addresses declared in the sitemap, the canonical tags and the tracking configuration must all use the secure version, otherwise statistics split in two.
- Check internal links written out in full too: they force a pointless redirect on every click.
- On a multilingual site, each language version has its own addresses to check.
Carry on with the right page
-
HTTPS and mixed content on WordPress
The WordPress case in detail, including serialised data.
-
Moving a site to HTTPS
The full procedure when the migration is not finished yet.
-
Serialisation explained
Why a raw replacement in the database breaks certain settings.
-
The 301 redirect
How to set up a clean permanent redirect to HTTPS.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.