# Moving WordPress to HTTPS without leaving mixed content behind

> Installing an SSL certificate isn’t enough to make a WordPress site fully work over HTTPS. Hardcoded http:// URLs in content and stored in the site’s options keep loading unsecured resources, which the browser flags or blocks as mixed content.

- Source canonique : [https://allaux.fr/en/wordpress-woocommerce/migration/https-contenu-mixte](https://allaux.fr/en/wordpress-woocommerce/migration/https-contenu-mixte)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> With the certificate in place, replace http://yourdomain with https://yourdomain across the whole database using a serialisation-aware tool, then reload a page and open the browser Console tab: it lists the assets still requested over http, almost always images hard-coded in the content or in theme settings. Then add the permanent redirect to https in .htaccess, not only in a plugin.

## What the certificate alone doesn’t fix

The certificate encrypts the connection between browser and server, but it doesn’t change anything in the database. Two core settings, siteurl and home in the wp_options table, define the site’s reference address: if they stay on http://, WordPress keeps generating some of its links without the secure protocol. On top of that, there are http:// URLs hardcoded in post content (images inserted with their full address, internal links) and ones stored in serialised theme or widget settings, which follow the same serialisation mechanism as a host or domain change — I cover that mechanism in depth on the dedicated hosting migration page; the logic here is identical.

Mixed content occurs precisely when a page served over https:// tries to load a resource still on http:// (an image, a script, a stylesheet): the browser blocks the resource or shows a warning in the address bar, which visually breaks the page or triggers a security alert for the visitor.

On a WooCommerce shop, moving to HTTPS isn’t only a matter of visual trust: some payment gateways require an encrypted connection to work at all and simply block the checkout until the certificate is active, which makes this job a priority on a live shop rather than a plain brochure site. Once mixed content is fixed, I add the HSTS header (Strict-Transport-Security) so browsers always prefer the encrypted connection on that domain, reducing the risk of an accidental fallback to HTTP.

## How I move a site to HTTPS cleanly

1. **Installing the certificate** — I set up the SSL/TLS certificate with the host or via a service like Let’s Encrypt, and check it covers every subdomain in use.
2. **Forcing the http to https redirect** — I configure the redirect at server level (.htaccess on Apache, a server block on Nginx) so no page remains reachable over http://, including API and webhook endpoints used by payment extensions.
3. **Updating siteurl, home and the content** — I fix these two options along with every http:// URL stored in content and serialised data, using the right tool — the same one used for a host or domain change.
4. **Hunting down remaining mixed content** — I open the browser console on the main pages to spot resources still called over http:// (often external images or a forgotten third-party script) and fix them one by one.
5. **Updating Search Console** — I add the https:// property in Search Console, which is treated as a separate address from the http:// version, to keep tracking indexing correctly.

## Back up before touching siteurl and home

> A mistake on these two options can make the admin area unreachable. I back up the database before any change and keep direct database access (phpMyAdmin or command line) to fix things manually if something locks up.

## Going further

- **General guide: moving a site to HTTPS** — The general method, valid for any CMS, with less WordPress-specific detail. ([/guides/passer-site-en-https](/guides/passer-site-en-https))
- **Migrating hosting without downtime** — The full detail of the serialisation mechanism referred to on this page. ([/wordpress-woocommerce/migration/hebergeur-sans-interruption](/wordpress-woocommerce/migration/hebergeur-sans-interruption))
- **Changing domain name without losing your rankings** — Another URL change that follows the same correction and verification logic. ([/wordpress-woocommerce/migration/changement-nom-domaine](/wordpress-woocommerce/migration/changement-nom-domaine))
- **Understanding PHP serialisation** — The full definition of the mechanism that makes a plain SQL replace dangerous. ([/glossaire/serialisation](/glossaire/serialisation))

## FAQ

### Is the SSL certificate enough to secure my site?

It encrypts the connection, but doesn’t fix any URL stored as http:// in the database or content. Without that fix, the site is reachable over https:// but shows mixed content warnings.

### What exactly is mixed content?

It’s when a page loaded over https:// calls a resource still on http:// (image, script, stylesheet). The browser blocks or flags that resource, which visually breaks the page or triggers a security warning.

### Do I need to create a new Search Console property?

Yes, Google treats https://mysite.co.uk as a separate address from http://mysite.co.uk. I add the new property and check the sitemap correctly points to the https:// URLs.

### Will my rankings drop after switching to HTTPS?

With 301 redirects correctly set up from every http:// URL to its https:// equivalent, the impact stays limited. The real risk comes from uncorrected mixed content, which can degrade the user experience.

### Do I need a special tool to fix http:// URLs in the content?

Yes, a plain SQL replace damages serialised data. I use the same kind of tool as for a hosting change, covered in detail on the dedicated page.
