WordPress Security

WordPress Mixed Content: 38.1% of Sites Still Fail Clean HTTPS

📊 38.1% of scanned small-business WordPress sites failed the mixed content check. (Based on 65690 scans across 37513 unique small-business WordPress sites, June 19 – July 19, 2026)

Security grade distribution chart — Scan-Insights-Mixed Content

The Number: 38.1% Failures on Mixed Content

65690 automated website security scans were run on 37513 unique small-business WordPress sites in the past 30 days. Of sites where the mixed content check was measured, 38.1% did not fully pass.
This means more than a third of sites are delivering content over HTTPS and HTTP at the same time, creating avoidable exposure and undercutting the security promise of SSL.

Mixed content failures indicate that, despite using HTTPS, some images, scripts, or other resources are loading insecurely (HTTP). The problem is widespread—and stubbornly persistent even as site owners invest in SSL certificates.

What the Mixed Content Check Means

Mixed content occurs when a web page, loaded via HTTPS, also includes resources (documents, images, scripts, or iframes) loaded over unencrypted HTTP.
This opens two primary gaps:

  • Downgrade risk: Attackers with network access (public Wi-Fi, compromised routers) can tamper with or modify insecure resources, even if the main page is encrypted.
  • Browser warnings: Modern browsers block or warn about mixed content, eroding visitor trust and potentially breaking site appearance or functionality.

The mixed content check in these scans verified that all resource loads—images, JavaScript, CSS, embeds—use HTTPS, not just the main page.

Why does it matter? Mixed content defeats the privacy and integrity guarantees of HTTPS, can trigger visible browser errors, and is an easily-scanned signal that a site isn’t fully secured.

WordPress Security by the Numbers

Across all 65690 scans of small-business WordPress sites in the last 30 days, the average overall security score was 39.8%. Mixed content wasn’t the only gap, but it remains a major one.

Grade Distribution

Grade Graded Scans % of Scans
A 196 0.3%
B+ 883 1.3%
B 441 0.7%
C+ 12716 19.4%
C 5317 8.1%
D 13660 20.8%
F 23881 36.4%

Very few sites reached top security grades, and more than a third received an F.

Check Pass Rates (Last 30 Days)

Check Good (%)
Security Headers 0.4%
Content Security Policy 0.0%
Cookie Security 79.3%
Mixed Content 61.9%
Server Banner Hide 1.6%

Only 61.9% of recent scans earned a “Good” on the mixed content check, meaning 38.1% failed.

Who Is Most at Risk

Industries and Site Types Most Affected

Mixed content issues affect non-technical site owners disproportionately—especially small businesses and solo operators managing their own WordPress sites.
Agencies reusing insecure themes or plugins, and site builds with legacy image galleries or embedded widgets, are also common sources.

Typical examples:

  • Local businesses with WordPress sites containing old image or video embeds
  • Agencies managing large portfolios, where full SSL conversion for all resources is overlooked
  • E-commerce stores with external payment or chat scripts still using HTTP links

The risk is higher for sites with frequently updated content, third-party embeds, or DIY migration from HTTP to HTTPS without strict scanner checks.

Why Mixed Content Gaps Persist

Enabling HTTPS—by installing an SSL certificate—has become a near-universal baseline. But most WordPress sites stop there, leaving legacy HTTP resource links embedded in posts, themes, or plugins.
Automatic mixed content rewriting is fragile and can’t always cover all cases (especially with hardcoded URLs, offsite embeds, or direct database imports).

WordPress media, builder plugins, and third-party widgets often default to whatever protocol is originally set, multiplying the paths for mixed content to return.
This means even diligent site owners may miss misconfigured banners, images, or scripts unless running a full website security scan for HTTP resource calls.

Failure to fully resolve mixed content leads to visible browser warnings and a loss of user trust—problems that are measurable, not theoretical.

The Attack Vector: How Mixed Content Becomes an Issue

A mixed content warning is often more than a cosmetic gap. Attackers can target these weaknesses using passive interception.

How attacks unfold:

  1. Target identification: Automated scanners crawl the web looking for WordPress sites with mixed content gaps.
  2. Downgrade & injection: On public or compromised networks, an attacker can intercept insecure (HTTP) scripts or images and inject malicious content—ads, redirects, crypto miners, or worse.
  3. Resulting risk: Even if your checkout or forms use HTTPS, loading a single HTTP image or script undermines the security boundary for the entire page.

Real-world context:
While not tied to a single headline CVE, the pattern is well-documented—mixed content is frequently listed in the OWASP Top 10 as a cause of weak transport layer protection, and is a common precursor to content injection attacks.

What You Can Do

Rescuing your site from mixed content is achievable, often in under an hour with the right workflow.

  • Run a security scan for mixed content
    Use an external website security scan to find every HTTP resource call. Don’t rely on “site looks fine” or browser views alone.
    Estimated time: 5 minutes

  • Search and replace hardcoded HTTP URLs
    Update WordPress media links, menu entries, and theme/plugin settings to use https:// for images, stylesheets, scripts, and embeds.
    Estimated time: 15–40 minutes, depending on site size

  • Configure automatic HTTPS enforcement
    Use plugins or server rules (such as HSTS) to block insecure resource loads and force HTTPS throughout.
    Estimated time: 10–20 minutes

  • Update or replace problematic plugins and widgets
    Remove or upgrade any themes, widgets, or plugins inserting HTTP resources by default.
    Estimated time: 10–30 minutes

After remediation, re-scan your site to confirm all resources load securely.

Final Thoughts

38.1% of recent small-business WordPress sites failed the mixed content check—an avoidable risk that directly undercuts the protection you expect from SSL.

A mixed content issue can be quietly persistent, but it’s also one of the fastest, most visible wins for building trust with your visitors and protecting your site’s integrity.

Don’t guess—scan your WordPress site now for mixed content gaps and take one practical step toward strong, consistent website security.

Back to blog
Share:

More on this topic

Want a quick security check?

Run a free scan and get your security grade in minutes.

Run Free Scan