sandywp / plugins / http-https-remover

SSL Mixed Content Fix

4.1 out of 5 stars. 4.1 34 reviews

A fix for mixed content! This Plugin creates protocol relative urls by removing http + https from links. Works in Front- and Backend!

Launch a sandbox with this plugin → No signup.
Ready in seconds.

v3.2.8 8,000+ installs WP 4.6+

your-sandbox.sandywp.com/wp-admin
SSL Mixed Content Fix running inside a SandyWP sandbox

What you get inside

1 screen
  • The Sourcecode of the Website will look like this!

About this plugin

Try it out on your free dummy site: Click here => https://tastewp.com/plugins/http-https-remover.
(this trick works for all plugins in the WP repo – just replace “wordpress” with “tastewp” in the URL)

UPDATE: This plugin will be maintained again! It changed ownership and we’re currently collecting ideas how to further improve it. If you have any cool ideas, please let us know in Support Forum. Thank you!

Major updated in the latest release (3.0):
– Plugin has a proper settings page now
– Many bugs fixed
– Code optimized, causing performance to increase a lot

Main features:

  • Works in Front- and Backend
  • Makes every Plugin compatible with https
  • Compatible with WPBakery & Disqus
  • Fixes Google Fonts issues
  • Makes your website faster

What does this Plugin do?

With protocol relative url’s you simply leave off the http: or https: part of the resource path. The browser will automatically load the resource using the same protocol that the page was loaded with.

For example, an absolute url may look like

src="http://domain.com/script.js"

If you were to load this from a https page the script will not be loaded – as non-https resources are not loaded from https pages (for security reasons).

The protocol relative url would look like

src="//domain.com/script.js"

and would load if the web page was http or https.

Tipp: Check your Settings -> General page and make sure your WordPress Address and Site Address are starting with “https”.
Add the following two lines in your wp-config.php above the line that​ says “Stop Editing Here”:

define('FORCE_SSL', true);
define('FORCE_SSL_ADMIN',true);

What is Mixed Content?

Mixed content occurs when initial HTML is loaded over a secure HTTPS connection, but other resources (such as images, videos, stylesheets, scripts) are loaded over an insecure HTTP connection. This is called mixed content because both HTTP and HTTPS content are being loaded to display the same page, and the initial request was secure over HTTPS. Modern browsers display warnings about this type of content to indicate to the user that this page contains insecure resources.

Note: You should always protect all of your websites with HTTPS, even if they don’t handle sensitive communications.

Example

Without Plugin:
src=”http://domain.com/script01.js”
src=”https://domain.com/script02.js”
src=”//domain.com/script03.js”

With Plugin:
src=”//domain.com/script01.js”
src=”//domain.com/script02.js”
src=”//domain.com/script03.js”

If using Cache Plugins

If the plugin isn’t working like expected please purge/clear cache for the changes to take effect!

Questions

How do I know if my site has mixed content?

If a green padlock appears, then your site is secure with no mixed content.
In Chrome or Safari, there will be no padlock icon in the browser URL field with mixed content.
In Firefox the padlock icon will reflect a warning with mixed content.

What if I am using a CDN?

Change all your CDN references to load with // (this will adapt based on how the page is loaded)

4.1

34 reviews

  • 5 ★ 25
  • 4 ★ 1
  • 3 ★ 1
  • 2 ★ 2
  • 1 ★ 5

Ratings come from WordPress.org. SandyWP does not collect its own reviews.

sandywp / also on the shelf

Try another plugin

Spin up a real WordPress site in seconds.

Test plugins, build a demo, hand a client a link — then squash it and start again. No local setup, no Docker.