ServerNeed — This Year's Best Offers For You

ServerNeed — More Than Hosting
Tutorials

How to Force HTTPS and Fix Mixed Content Warnings

Redirect every visitor to HTTPS and clear "Not secure" mixed content warnings step by step, in cPanel, with .htaccess, in WordPress and behind a CDN, without creating redirect loops.

5 min read 1 view
Padlock and chain on a blue gate
Table of Contents
  1. Step 1: Confirm the certificate works
  2. Step 2: Redirect HTTP to HTTPS
  3. Step 3: Update the site's own URLs
  4. Step 4: Find remaining mixed content
  5. Step 5: Enable HSTS (later)
  6. Troubleshooting
  7. Worked example: tracing a missing padlock
  8. Checklist after switching to HTTPS
  9. Frequently Asked Questions
  10. Related reading
  11. Sources

Once an SSL certificate is installed, two jobs remain: redirect all HTTP requests to HTTPS (with a single 301 redirect), and fix mixed content, meaning pages loaded over HTTPS that still pull images, scripts or styles over plain HTTP. Mixed content makes browsers show warnings or block resources, so pages look broken or "Not secure".

Step 1: Confirm the certificate works

Visit https://yourdomain.com and https://www.yourdomain.com. Both should load with a valid certificate. If not, see how to install a free SSL certificate in cPanel.

Step 2: Redirect HTTP to HTTPS

Option A: cPanel's setting

On many servers, cPanel → Domains has a Force HTTPS Redirect toggle for each domain. Turn it on. This is the simplest option.

Option B: .htaccess (Apache and LiteSpeed)

Add these lines at the top of .htaccess in your site root (above any CMS rules):

RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

To also send everyone to one hostname (for example without www), combine the redirect:

RewriteEngine On
RewriteCond %{HTTPS} !=on [OR]
RewriteCond %{HTTP_HOST} ^www\.example\.com$ [NC]
RewriteRule ^ https://example.com%{REQUEST_URI} [L,R=301]

Replace example.com with your domain. See the WordPress .htaccess file for where to place rules in WordPress.

Option C: Behind a CDN or proxy

If the site is behind Cloudflare or another proxy, the server may see every request as HTTP, so an .htaccess redirect can loop. Use the proxy's own "Always use HTTPS" setting, and set the SSL mode so the proxy connects to your server over HTTPS (Full or Full (strict) in Cloudflare). See how to set up Cloudflare DNS.

Test with http:// addresses: there should be exactly one redirect, to the final https:// URL.

Step 3: Update the site's own URLs

WordPress

  1. In Settings → General, set both WordPress Address and Site Address to https://.
  2. Update links stored in content. Use a search-replace tool that handles serialised data, such as WP-CLI:
wp search-replace 'http://example.com' 'https://example.com' --skip-columns=guid
  1. Check theme options, page-builder settings and widgets, which sometimes store full URLs.

Other sites

Update the base URL in your application's configuration, and replace hard-coded http:// links in templates with https:// or relative links.

Step 4: Find remaining mixed content

  1. Open a page, then the browser's developer tools (Console tab). Mixed content warnings list the exact URLs.
  2. Fix the source of each one:
    • images or files on your site linked with http://;
    • scripts or styles from third parties that support HTTPS (change to https://);
    • third-party resources that do not support HTTPS (replace or remove them);
    • CSS files with url(http://...) backgrounds.
  3. Repeat on a few page types (home, post, product, checkout).

Step 5: Enable HSTS (later)

Once everything works over HTTPS for a while, add the Strict-Transport-Security header so browsers always use HTTPS. Start with a short duration. See HTTP security headers explained.

Troubleshooting

Problem Fix
"Too many redirects" Two redirect rules conflict, or a proxy causes a loop; keep one redirect, fix proxy SSL mode
Padlock missing on some pages Mixed content on those pages; check the console
Login redirect loop in WordPress Site URLs still use http://; see WordPress login problems
Images broken after switching Hard-coded http:// image URLs; run a search-replace

Worked example: tracing a missing padlock

A business site shows "Not secure" only on its blog posts. The steps to fix it:

  1. Open a blog post, then DevTools → Console. The warning reads: Mixed Content: The page was loaded over HTTPS, but requested an insecure image 'http://example.com/wp-content/uploads/2022/05/banner.jpg'.
  2. The image URL is stored inside old post content, inserted before the site moved to HTTPS.
  3. A database search-replace from http://example.com to https://example.com (with a tool that handles serialised data) updates every old post at once.
  4. One warning remains: a font loaded with http:// in the theme's custom CSS field. Changing it to https:// fixes the last item.
  5. Purging the page cache and CDN cache, then reloading, shows the padlock on every page.

The console always names the exact resource, so the work is usually finding where that URL is stored: post content, theme settings, widgets, or a plugin's options.

Checklist after switching to HTTPS

  • http:// and http://www. both redirect with a single 301 to the final HTTPS address
  • The CMS's site URL settings use https://
  • No mixed-content warnings on the main page types
  • Canonical tags and the XML sitemap use https:// URLs
  • Analytics and Search Console use the HTTPS property
  • External links you control (social profiles, directories) updated to HTTPS

Frequently Asked Questions

Does forcing HTTPS affect SEO?

A single 301 redirect from HTTP to HTTPS is the recommended approach; search engines consolidate signals on the HTTPS URLs.

Can I use a plugin instead?

Plugins can force HTTPS and rewrite URLs on the fly, but fixing URLs at the source is cleaner and faster.

See what is SSL/TLS and how does HTTPS work. Free SSL is included with the ServerNeed shared hosting plans.

HTTPS is one of the ten practices in website security basics.

Sources

Last updated 7 October 2026

View All Articles