How to Force HTTPS and Fix Mixed Content Warnings
Redirect every visitor to HTTPS and clear "Not secure" mixed content warnings step by step, in cPanel, with .htaccess, in WordPress and behind a CDN, without creating redirect loops.

Table of Contents
- Step 1: Confirm the certificate works
- Step 2: Redirect HTTP to HTTPS
- Step 3: Update the site's own URLs
- Step 4: Find remaining mixed content
- Step 5: Enable HSTS (later)
- Troubleshooting
- Worked example: tracing a missing padlock
- Checklist after switching to HTTPS
- Frequently Asked Questions
- Related reading
- Sources
Once an SSL certificate is installed, two jobs remain: redirect all HTTP requests to HTTPS (with a single 301 redirect), and fix mixed content, meaning pages loaded over HTTPS that still pull images, scripts or styles over plain HTTP. Mixed content makes browsers show warnings or block resources, so pages look broken or "Not secure".
Step 1: Confirm the certificate works
Visit https://yourdomain.com and https://www.yourdomain.com. Both should load with a valid certificate. If not, see how to install a free SSL certificate in cPanel.
Step 2: Redirect HTTP to HTTPS
Option A: cPanel's setting
On many servers, cPanel → Domains has a Force HTTPS Redirect toggle for each domain. Turn it on. This is the simplest option.
Option B: .htaccess (Apache and LiteSpeed)
Add these lines at the top of .htaccess in your site root (above any CMS rules):
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
To also send everyone to one hostname (for example without www), combine the redirect:
RewriteEngine On
RewriteCond %{HTTPS} !=on [OR]
RewriteCond %{HTTP_HOST} ^www\.example\.com$ [NC]
RewriteRule ^ https://example.com%{REQUEST_URI} [L,R=301]
Replace example.com with your domain. See the WordPress .htaccess file for where to place rules in WordPress.
Option C: Behind a CDN or proxy
If the site is behind Cloudflare or another proxy, the server may see every request as HTTP, so an .htaccess redirect can loop. Use the proxy's own "Always use HTTPS" setting, and set the SSL mode so the proxy connects to your server over HTTPS (Full or Full (strict) in Cloudflare). See how to set up Cloudflare DNS.
Test with http:// addresses: there should be exactly one redirect, to the final https:// URL.
Step 3: Update the site's own URLs
WordPress
- In Settings → General, set both WordPress Address and Site Address to
https://. - Update links stored in content. Use a search-replace tool that handles serialised data, such as WP-CLI:
wp search-replace 'http://example.com' 'https://example.com' --skip-columns=guid
- Check theme options, page-builder settings and widgets, which sometimes store full URLs.
Other sites
Update the base URL in your application's configuration, and replace hard-coded http:// links in templates with https:// or relative links.
Step 4: Find remaining mixed content
- Open a page, then the browser's developer tools (Console tab). Mixed content warnings list the exact URLs.
- Fix the source of each one:
- images or files on your site linked with
http://; - scripts or styles from third parties that support HTTPS (change to
https://); - third-party resources that do not support HTTPS (replace or remove them);
- CSS files with
url(http://...)backgrounds.
- images or files on your site linked with
- Repeat on a few page types (home, post, product, checkout).
Step 5: Enable HSTS (later)
Once everything works over HTTPS for a while, add the Strict-Transport-Security header so browsers always use HTTPS. Start with a short duration. See HTTP security headers explained.
Troubleshooting
| Problem | Fix |
|---|---|
| "Too many redirects" | Two redirect rules conflict, or a proxy causes a loop; keep one redirect, fix proxy SSL mode |
| Padlock missing on some pages | Mixed content on those pages; check the console |
| Login redirect loop in WordPress | Site URLs still use http://; see WordPress login problems |
| Images broken after switching | Hard-coded http:// image URLs; run a search-replace |
Worked example: tracing a missing padlock
A business site shows "Not secure" only on its blog posts. The steps to fix it:
- Open a blog post, then DevTools → Console. The warning reads: Mixed Content: The page was loaded over HTTPS, but requested an insecure image 'http://example.com/wp-content/uploads/2022/05/banner.jpg'.
- The image URL is stored inside old post content, inserted before the site moved to HTTPS.
- A database search-replace from
http://example.comtohttps://example.com(with a tool that handles serialised data) updates every old post at once. - One warning remains: a font loaded with
http://in the theme's custom CSS field. Changing it tohttps://fixes the last item. - Purging the page cache and CDN cache, then reloading, shows the padlock on every page.
The console always names the exact resource, so the work is usually finding where that URL is stored: post content, theme settings, widgets, or a plugin's options.
Checklist after switching to HTTPS
-
http://andhttp://www.both redirect with a single 301 to the final HTTPS address - The CMS's site URL settings use
https:// - No mixed-content warnings on the main page types
- Canonical tags and the XML sitemap use
https://URLs - Analytics and Search Console use the HTTPS property
- External links you control (social profiles, directories) updated to HTTPS
Frequently Asked Questions
Does forcing HTTPS affect SEO?
A single 301 redirect from HTTP to HTTPS is the recommended approach; search engines consolidate signals on the HTTPS URLs.
Can I use a plugin instead?
Plugins can force HTTPS and rewrite URLs on the fly, but fixing URLs at the source is cleaner and faster.
Related reading
See what is SSL/TLS and how does HTTPS work. Free SSL is included with the ServerNeed shared hosting plans.
HTTPS is one of the ten practices in website security basics.
Sources
Last updated 7 October 2026



