The mixed content SEO question usually comes up straight after a move to HTTPS. The certificate is installed, the redirects are live, and yet the browser shows a warning or a page looks broken. The cause is almost always a handful of resources still being requested over plain HTTP.
The damage is practical rather than algorithmic. What a browser does with those resources decides whether your page works, and a page that does not work cannot hold the visitors it ranks for.
What mixed content is
The definition from web.dev’s article What is mixed content? is precise: “A page has mixed content when its initial HTML is loaded over a secure HTTPS connection, but other resources (such as images, videos, stylesheets, and scripts) are loaded over an insecure HTTP connection.”
The page itself is secure. The problem is what it pulls in. An image hard-coded with an http:// address in an old post, a script from a third-party service, a font file referenced in a stylesheet: each one is a request the browser has to decide what to do with.
Hosts and CDNs cannot spot this for you by default, because the HTML they deliver is valid. The insecure address is just text inside it until a browser tries to fetch it, which is why the problem so often survives a migration that looked finished.

Passive and active mixed content
Browsers treat mixed content in two groups, and the difference decides how much damage it does.
| Type | Resources | What browsers do | Effect on the page |
|---|---|---|---|
| Passive (upgradable) | Images, video, audio | Chrome “automatically upgrades passive mixed content” to HTTPS | Usually fine; breaks if the file is not available over HTTPS |
| Active (blockable) | Scripts, stylesheets, iframes | “Most browsers already block this type of content by default.” | Missing styles, broken menus, forms or embeds that fail |
Passive content is the forgiving case. If the image server also answers on HTTPS, the upgrade succeeds and nobody notices. If it does not, the image simply fails to load, which leaves a gap in the page.

Active content is the serious one. A blocked stylesheet can leave a page unstyled. A blocked script can take out navigation, a cookie banner, a checkout or the analytics you rely on to notice any of this. These failures are silent from the server’s side; the HTML is delivered perfectly and the breakage happens in the visitor’s browser.
The mixed content SEO risk: users, not a penalty
There is no published Google penalty for mixed content, and it would be wrong to claim a specific ranking cost. The risk runs through what happens on the page.
- Broken layouts and features. Visitors who land on an unstyled or half-working page leave, and the page fails at the job it ranks for.
- Browser warnings. Security indicators that the page is not fully secure undermine trust, particularly on pages that ask for personal details.
- Rendering gaps. If a script that builds part of the content is blocked, that content may be missing for everyone requesting the page securely.

That last point is worth checking on JavaScript-heavy pages. If important text or links depend on a script loaded over HTTP, test whether they appear at all in the rendered page. Content that never loads cannot be seen by visitors, and there is no reason to assume it fares better elsewhere.
How to find mixed content
Start with the browser. Open a page, open the developer tools console, and reload. Mixed content produces warnings or errors that name each insecure URL, which tells you exactly what to fix on that template.
For a whole site, use a crawler that reports insecure resources on HTTPS pages, or search your database and templates for hard-coded http:// references to your own domain. On older sites, most offenders sit in post content written before the move, theme files and widget code.

Check third-party embeds separately. Old video players, ad tags and badges are frequent sources, and you cannot fix their servers; you can only change the URL you use or replace the embed.
Prioritise by consequence rather than by count. One blocked script on a checkout or lead form matters more than fifty old images in archive posts. Work through the templates that carry your most important traffic first, then sweep the long tail.
How to fix it
The permanent fix is to change every resource URL to HTTPS. For your own files, that usually means a search-and-replace in the database plus a pass through theme and plugin settings. On a CMS, check the configured site address too: if it still reads http://, the system will keep generating insecure links to your own files however often you clean the content. Fix the setting first, then the stored URLs, then any hard-coded references in theme files. For example, an image reference like this:
becomes:

As a safety net, web.dev describes the upgrade-insecure-requests Content Security Policy directive, which tells the browser to request HTTP resources over HTTPS instead. It can be sent as a response header or added to the page head:
The directive only helps if the resource exists at the HTTPS address. Treat it as cover while you clean up, not a replacement for correct URLs. It also does nothing for third-party hosts that do not support HTTPS at all; those resources will still fail, and the only fix is a different source or removing the embed.

Fix it as part of the HTTPS move
Mixed content is cheapest to fix during the switch to HTTPS, when you are already touching redirects and canonical URLs. Our site migration SEO guide covers that wider checklist, and the same clean-up applies if you are standardising hostnames at the same time, as described in www vs non-www.
Make the HTTP to HTTPS redirects permanent, so search engines move their signals to the secure URLs; the difference is explained in 301 vs 302 redirects. Then update internal links to point straight at HTTPS addresses rather than relying on the redirect for every click.
One limitation is worth stating. A clean console on the pages you test does not prove the site is clean. Mixed content often hides in rarely visited templates, old archive posts and embeds that only load in certain conditions. Re-crawl the full site after the migration, and again after any theme change or new third-party tool, because new insecure references tend to arrive with them.
Frequently asked questions
Does mixed content hurt SEO?
Not through a known penalty. It hurts through broken styles and scripts, missing content and browser warnings, all of which damage the experience of visitors you rank for.
What is the difference between passive and active mixed content?
Passive content is images, video and audio, which Chrome automatically upgrades to HTTPS. Active content is scripts, stylesheets and iframes, which most browsers block by default.
Is upgrade-insecure-requests enough to fix mixed content?
It is a useful safety net, but only works where the resource is available over HTTPS. Changing the URLs themselves is the permanent fix.
How do I find mixed content on my site?
Check the browser console on key templates, then crawl the site for insecure resources and search your database and theme files for http:// references.
The takeaway Mixed content breaks pages before it affects rankings. Change resource URLs to HTTPS, use upgrade-insecure-requests as a backstop, and re-crawl after every migration.

