Mixed Content Checker
Scan any HTTPS page for mixed content issues. Find HTTP resources (images, scripts, stylesheets, iframes) loaded on HTTPS pages that cause browser security warnings or get blocked entirely.
HTTPS URL to scan for mixed content
returns
- data.mixed_content
- Each insecure resource with URL, type, tag, severity and line.
- data.has_mixed_content
- True when the page loads anything over plain HTTP.
- data.summary
- Active and passive counts, plus resources by type.
- data.mixed_content_count
- Number of insecure resources found.
- data.total_resources
- Total resources scanned on the page.
- data.is_https
- False when the page itself isn't served over HTTPS.
Fill in the fields and send a request. The response lands here.
Run it from your code
A temporary key takes one request and lasts seven days at 20 calls a day. Register and it becomes 75 a day, still free.
$ curl -s "https://apixies.io/api/v1/check-mixed-content?url=https://example.com" \ -H "X-API-Key: $APIXIES_KEY" | jq '.data.mixed_content' []
questions
What's the difference between active and passive mixed content?
Active mixed content (scripts, stylesheets, iframes) is blocked by browsers because it can modify the page. Passive mixed content (images, video, audio) shows a warning but may still load.
What if the page isn't HTTPS?
The tool reports that the page isn't served over HTTPS and notes that mixed content doesn't apply. Mixed content is only an issue when an HTTPS page loads HTTP resources.
Does it follow links to other pages?
No. It only scans the single URL you provide. It checks the HTML source for resource references but doesn't crawl to other pages.