Insecure resources on a secure page

30.6%

of the 3,044 free scans considered in the last 30 days raised this finding. That is 931 scans across 920 distinct sites. 95% interval 27.7% to 33.6%.

What it means

A secure page that loads even one resource over plain http breaks the padlock and the guarantee behind it.

How to fix it

Find the http:// resource on the page and change it to https://, or host it yourself. One insecure image is enough to break the padlock on the whole page.

How to check it yourself

Open DevTools, go to Console, and reload the page on https. A mixed-content warning names any resource still loading over plain http.

What fixed looks like

The DevTools console reloads clean, with no mixed-content warning and no broken padlock.

How we measured this

Go Voltic scans a site and records which findings it raises. The share above is over every free four-page scan in the last 30 days that loaded at least one page, which is 3,044 scans. Deep scans of paid reports and of the research sweep read a site at a different depth and are a separate population, never in this denominator. It is not a survey and it is not an estimate: it is a count of what our own scanner found. Sites are counted once each in the distinct-sites figure, so a site scanned twice does not weigh double there.

The interval is a 95% Wilson interval. A share printed without its sample size reads as certainty and is indistinguishable from a guess, so both are always shown. Figures on this page were computed on 2026-09-08.

The same share sits beside every other finding on the benchmarks page, which also carries the whole table as CSV and JSON and says how to cite it.

Check your own site

The free scan reads four pages and reports every finding it raises, including this one. It takes about ten seconds and asks for nothing but the address.

Run a free scan