How to Fix WordPress ERR_TOO_MANY_REDIRECTS — Complete Guide
ERR_TOO_MANY_REDIRECTS means WordPress is stuck in a redirect loop — usually caused by a…
WordPress Mixed Content Error HTTPS
A mixed content error appears when your WordPress site runs on HTTPS but still attempts to load certain resources — images, stylesheets, or JavaScript files — over the old, unencrypted HTTP protocol. Browsers either block those resources silently or replace the padlock icon in the address bar with a warning symbol, signaling to visitors that the page isn’t fully secure.
From a visitor’s perspective, this might show up as broken images, unstyled page sections, or JavaScript-powered features that stop responding. Even when the visual damage looks minor, the security warning alone is enough to shake user trust — and modern browsers like Chrome now actively label these pages as “Not Fully Secure.”
This error is especially common right after migrating a WordPress site from HTTP to HTTPS, or after installing an SSL certificate without updating the URLs already stored inside the WordPress database.
http://, WordPress generates HTTP links for all internal content automatically.http:// to https://. Click Save Changes.
You should see: The settings page reloads and both URL fields now display the https:// version of your domain.
wp-config.php file via FTP or your host’s file manager and add this line just before the “That’s all, stop editing!” comment:
define('FORCE_SSL_ADMIN', true);
You should see: Your WordPress admin panel loads exclusively over HTTPS from this point on.
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --skip-columns=guid
No WP-CLI? Install the free Better Search Replace plugin — it does the exact same thing safely from inside your dashboard.
You should see: A results table showing how many rows were updated across your database tables (posts, postmeta, options, etc.).
.htaccess file in your site’s root folder and insert this block above the existing WordPress rewrite rules:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
You should see: Any attempt to visit the HTTP version of your site immediately redirects to HTTPS with a 301 status.
F12 to launch DevTools, and click the Console tab. Look for lines flagged as “Mixed Content.” Each warning names the exact HTTP resource still causing the problem. Fix those URLs individually in your theme files, the media library, or the offending plugin’s settings.
You should see: A clean console with no mixed content warnings and a solid padlock icon in the browser address bar.
--skip-columns=guid from the WP-CLI command: The guid column stores permanent post identifiers. Replacing those values breaks RSS feeds and can create duplicate content issues that are painful to untangle.Get free WordPress & AI tips
Join 500+ readers. No spam, unsubscribe anytime.
Yes, indirectly. Google uses HTTPS as a ranking signal, and mixed content warnings undermine that signal by showing your page isn’t fully secure. Chrome also displays visible warnings that can increase bounce rates, which compounds the SEO impact over time.
Absolutely. The free version of the Better Search Replace plugin handles the full database URL replacement from inside the WordPress dashboard — no SSH or WP-CLI knowledge required. It’s a reliable choice for shared hosting environments.
Head to Chrome DevTools (F12), open the Console tab, and look for “Mixed Content” warning messages. Each one tells you the exact URL of the resource still loading over HTTP. Common culprits at this stage are external fonts, embedded YouTube thumbnails, or an old plugin that hardcodes its asset path.
No. Free SSL certificates issued by Let’s Encrypt work perfectly well — the browser doesn’t care whether you paid for the certificate or not, only that it’s valid. Most modern hosting providers include a free Let’s Encrypt certificate directly in their control panel under the SSL or Security section.