Skip to content
GET /api/v1/check-mixed-content

Mixed Content Checker

Scan any HTTPS page for mixed content issues. Find HTTP resources (images, scripts, stylesheets, iframes) loaded on HTTPS pages that cause browser security warnings or get blocked entirely.

url required

HTTPS URL to scan for mixed content

X-Sandbox-Remaining: - get an api key

returns

data.mixed_content
Each insecure resource with URL, type, tag, severity and line.
data.has_mixed_content
True when the page loads anything over plain HTTP.
data.summary
Active and passive counts, plus resources by type.
data.mixed_content_count
Number of insecure resources found.
data.total_resources
Total resources scanned on the page.
data.is_https
False when the page itself isn't served over HTTPS.
response awaiting request sending
Fill in the fields and send a request. The response lands here.

Run it from your code

A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.

$ curl -s "https://apixies.io/api/v1/check-mixed-content?url=https://example.com" \
    -H "X-API-Key: $APIXIES_KEY" | jq '.data.mixed_content'

[]

questions

What's the difference between active and passive mixed content?

Active mixed content (scripts, stylesheets, iframes) is blocked by browsers because it can modify the page. Passive mixed content (images, video, audio) shows a warning but may still load.

What if the page isn't HTTPS?

The tool reports that the page isn't served over HTTPS and notes that mixed content doesn't apply. Mixed content is only an issue when an HTTPS page loads HTTP resources.

Does it follow links to other pages?

No. It only scans the single URL you provide. It checks the HTML source for resource references but doesn't crawl to other pages.

cookies

We use analytics cookies to see how the site gets used. Nothing loads until you accept. Privacy policy