↑ ↓ select, Enter open, Esc close

Find mixed content in the HTML of an HTTPS page

Adjust the values, the command updates live
user@server
curl -s https://example.com/ | tr '\n' ' ' | grep -oiE '(src|srcset|data-src)="http://[^"]+"|<link[^>]+href="http://[^"]+"|url\(.?http://[^)]+\)' | sort -u

Searches the HTML for resources loaded via http://: src, srcset, <link href> and url() in inline CSS. Browsers block such content or show a warning, which costs trust and breaks the layout. Typical after switching to HTTPS when old URLs remain in the database.

Note: <link href="http://..."> also matches canonical or hreflang links, which are not mixed content. Resources referenced from external CSS and JS files are not covered. For WordPress, the entry on switching from http to https with WP-CLI helps.

Also searched as

  • find mixed content command line
  • padlock missing in browser
  • find http images on https page
  • fix mixed content warning

Related one-liners

All in SEO checks

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.