# The padlock disappeared after moving to HTTPS

> The certificate is valid, the site answers over HTTPS, and yet the padlock is crossed out or carries a warning. This is not a certificate problem: the page, served securely, is fetching part of its content over an insecure address. The browser flags it, and sometimes blocks the element outright.

- Source canonique : [https://allaux.fr/en/problemes/contenu-mixte-apres-passage-en-https](https://allaux.fr/en/problemes/contenu-mixte-apres-passage-en-https)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Open the browser console: every offending resource is listed with its full http:// address, which points straight at the file or database row to fix. On WordPress, rewrite the addresses with a search-replace tool that handles serialised data, then check wp_options.siteurl and home. On PrestaShop, check PS_SSL_ENABLED and PS_SHOP_DOMAIN_SSL in ps_configuration.

## Two levels of severity

Browsers distinguish passive mixed content — images, video, audio — from active mixed content — stylesheets, scripts, embedded frames. The first is displayed but downgrades the security indicator. The second is blocked outright, because a script loaded in the clear could be swapped in transit.

That explains a confusing symptom: after moving to HTTPS, the layout collapses or a feature stops responding although nothing was changed in the code. The file exists, it is simply refused by the browser. The browser console then names each blocked resource precisely.

## Where the remaining HTTP addresses hide

1. **In descriptions entered in the admin** — This is the most frequent source and the longest to clean: years of product pages containing images pasted with their full http address.
2. **In the CMS settings** — The shop address is stored in the database. While it stays on http, some generated links stay there too, including inside emails.
3. **In the theme and modules** — An address hard-coded in a template or stylesheet escapes any database replacement.
4. **In third-party scripts** — Old tracking tags, fonts, maps, libraries called from an external service that no longer offers a secure version.
5. **In the stylesheets themselves** — A background image declared over http inside a CSS file does not appear in the page source: only the browser console shows it.

## A database replacement is not a trivial operation

> Some data is stored serialised, with the length of each string recorded alongside it. Simply replacing "http://" with "https://" changes that length and makes the data unreadable, breaking whole sets of settings. The job needs a tool that recomputes the lengths.

## What is left to check

Once mixed content is dealt with, two points finish the job. The permanent redirect from the insecure address to the secure one must be single and direct: a chain of cascading redirects dilutes the signal sent to search engines and slows every visit. And the addresses declared in the sitemap, the canonical tags and the tracking configuration must all use the secure version, otherwise statistics split in two.

Check internal links written out in full too: they force a pointless redirect on every click.

On a multilingual site, each language version has its own addresses to check.

## Carry on with the right page

- **HTTPS and mixed content on WordPress** — The WordPress case in detail, including serialised data. ([/wordpress-woocommerce/migration/https-contenu-mixte](/wordpress-woocommerce/migration/https-contenu-mixte))
- **Moving a site to HTTPS** — The full procedure when the migration is not finished yet. ([/guides/passer-site-en-https](/guides/passer-site-en-https))
- **Serialisation explained** — Why a raw replacement in the database breaks certain settings. ([/glossaire/serialisation](/glossaire/serialisation))
- **The 301 redirect** — How to set up a clean permanent redirect to HTTPS. ([/glossaire/redirection-301](/glossaire/redirection-301))

## FAQ

### Is mixed content dangerous for my customers?

The real risk is limited for an image, serious for a script: a file loaded in the clear can be modified in transit. That is exactly why browsers block scripts and let images through.

### Can I force the browser to load everything securely?

There is a directive asking the browser to retry any HTTP resource over HTTPS. That is a useful transitional patch, not a fix: if the resource does not exist securely, it still disappears.

### Why does the problem only affect some pages?

Because mixed content usually comes from entered content, which differs from page to page. Automatically generated pages are clean.

### Do I need to rebuild the site to move properly to HTTPS?

No. It is a cleanup and configuration job, not a rebuild. The duration depends mostly on how much old content needs correcting.

### Can mixed content hurt my search ranking?

What weighs most is address consistency: two versions of the same site reachable, or cascading redirects. Mixed content itself mainly damages visible trust.
