Insecure Content Warning (by 10up) is a specialized, preventive security plugin designed to maintain a perfect “green padlock” status on your website. As of April 2026 (v1.2.x), it is a critical tool for sites running WordPress 7.0, as modern browsers have become significantly more aggressive in blocking “mixed content” (HTTP resources on HTTPS pages).
While other plugins try to “fix” insecure links as they load for the visitor, this plugin works at the source: the content editor. It prevents editors from even publishing a post if it contains insecure elements.
Table of Contents
What is Insecure Content Warning?
This plugin is a quality-control gatekeeper. When an author or editor adds an image, video, or script using an http:// address on an https:// site, the plugin flags it immediately.
- Proactive Blocking: It physically prevents the “Publish” or “Update” button from working until the insecure content is addressed.
- Editor Integration: Works seamlessly with the Block Editor (Gutenberg) and the Classic Editor.
- Zero Configuration: There are no complex settings panels; simply activate it, and it begins protecting your mybox site.
How It Works: Detection and Repair
The plugin scans the HTML of your post in real-time. If it finds a resource (like an image from an old library or an external embed) that uses an insecure protocol, a warning banner appears at the top of the editor.
- The Flag: A list of all insecure URLs is displayed.
- The “Fix It” Button: For many internal resources, the plugin offers a “Fix It” button that automatically updates the protocol to HTTPS.
- Manual Correction: If the resource is external and doesn’t support HTTPS, the editor must manually remove or replace the element before the post can be published.
Key Requirements (2026)
- WordPress Version: Requires WordPress 6.6 or higher (optimized for 7.0).
- PHP Version: Requires PHP 7.4+ (Recommended: PHP 8.3/8.5 on mybox).
- SSL Status: Your website must already have a valid SSL certificate and be running on HTTPS (both front and back end).
Insecure Content Warning vs. SSL Fixer Plugins
It is important to understand the difference between this plugin and “frontend fixers” like SSL Insecure Content Fixer:
| Feature | Insecure Content Warning (10up) | SSL Insecure Content Fixer |
| Approach | Preventive: Blocks publication of bad code. | Reactive: Fixes bad code as the page loads. |
| Performance | High: No impact on visitor load times. | Moderate: Adds a small processing delay. |
| Database | Fixes the data inside the database. | Leaves bad data in the DB; fixes it on-the-fly. |
| Ideal For | Editorial teams and new content. | Legacy sites with thousands of old HTTP links. |
WP-CLI and Admin Support
For administrators managing large-scale migrations to HTTPS on mybox, the plugin includes powerful WP-CLI commands to audit and fix content in bulk:
wp icw fix --all– Scans and attempts to fix all insecure content across the entire site.wp icw fix --post_type=page– Targets only specific content types.wp icw fix [ID] --dry-run– Previews the changes for a specific post without saving them.
Benefits for SEO and Security
In 2026, search engines and browsers treat mixed content as a serious security failure.
- SEO: Google’s ranking algorithms penalize sites that trigger “Not Secure” warnings.
- User Trust: Visitors are likely to leave a site immediately if their browser displays a “Your connection to this site is not fully secure” message.
- Security: Mixed content can be exploited via “Man-in-the-Middle” (MitM) attacks to inject malicious scripts into otherwise secure pages.
Summary
Insecure Content Warning is an essential part of an “HTTPS Hygiene” strategy. By forcing authors to fix links at the moment of creation, you ensure your mybox site stays clean, professional, and secure without needing heavy frontend “fixer” plugins that can slow down your site.