An SSL certificate is the foundation of a secure website, but simply having one doesn’t guarantee a “Clean” security status. Even with HTTPS enabled, your browser may show a “Not Secure” warning or a broken padlock. This is known as Mixed Content, and it occurs when a secure HTTPS page tries to load images, scripts, or videos over an unencrypted HTTP connection.
The Insecure Content Warning plugin is a specialized tool designed to prevent these errors at the source-the content creation process.
Table of Contents
What is the Insecure Content Warning Plugin?
This free plugin acts as a “security gatekeeper” for the WordPress Gutenberg editor. Instead of fixing errors after they happen, it scans your posts and pages in real-time as you write them.
If you accidentally paste a link to an image or script that starts with http://, the plugin will flag it immediately. Most importantly, it can be configured to prevent publication until the insecure link is fixed, ensuring your visitors never see a security warning.
How the Plugin Protects Your Website
When a browser loads a site over HTTPS, it expects every single piece of data on that page to be encrypted. If even one image is loaded via http://, the browser’s “security chain” is broken.
- User Trust: Visitors are often wary of sites that trigger “Insecure Content” pop-ups.
- SEO Impact: Search engines like Google prioritize fully secure sites. Mixed content can negatively impact your ranking.
- Automation: The plugin removes the need for manual “view source” checks by highlighting problematic blocks directly in the editor.
Installation and Activation
Because the plugin is designed for simplicity, it requires no complex configuration on the mybox infrastructure.
- Log in to your WordPress dashboard.
- Go to Plugins > Add New.
- Search for “Insecure Content Warning” (by 10up).
- Click Install and then Activate.
Once active, the plugin begins working immediately. There are no settings menus to navigate; it integrates directly into the Gutenberg sidebar and the publishing workflow.
Advanced: Fixing Existing Errors via WP-CLI
If you have a large site with hundreds of existing posts, manually editing each one is impractical. For mybox users with SSH access, you can use WP-CLI to fix these links in bulk.
Using the command line, you can find and replace all http:// instances of your own domain with https://:
Bash
wp icw fix --all --post_type=page
Note: Always perform a full database backup before running bulk search-and-replace commands.
Best Practices and Troubleshooting
1. Check the Browser Console If your site still shows a warning after fixing your links, press F12 (or Right-Click > Inspect) and go to the Console tab. It will list the exact URL of the resource that is still being loaded over HTTP.
2. Update External Resources Sometimes the insecure content comes from a third-party widget or an old tracking script. Check if the provider offers an https:// version of their code. Most modern services have supported HTTPS for years.
3. Use Relative Paths When possible, use relative paths (e.g., /images/logo.png) instead of absolute URLs (http://yourdomain.com/images/logo.png). Relative paths automatically use whatever protocol (HTTP or HTTPS) the main page is using.
Summary
The Insecure Content Warning plugin is a proactive tool for maintaining the integrity of your mybox hosted website. By catching protocol mismatches during the editing phase, you ensure a professional, secure experience for your users and maintain your standing with search engines.