Plugin info

Total downloads: 8,171
Active installs: 70
Total reviews: 6
Average rating: 5
Support threads opened: 0
Support threads resolved: 0 (0%)
Available in: 1 language(s)
Contributors: 2
Last updated: 1/19/2015 (3999 days ago)
Added to WordPress: 12/15/2014 (11 years old)
Minimum WordPress version: 4.0.1
Tested up to WordPress version: f
Minimum PHP version: f

Maintenance & Compatibility

Maintenance score

Possibly abandoned • Last updated 3999 days ago • 6 reviews

22/100

Is HTTPS Mixed Content Detector abandoned?

Possibly abandoned (last update 3999 days ago).

Compatibility

Requires WordPress: 4.0.1
Tested up to: f
Requires PHP: f

Similar & Alternatives

Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.

Simple HTTPS
Rating 5.0/5 (1 reviews)Active installs 400
HTTPS Domain Alias
Rating 5.0/5 (5 reviews)Active installs 40
Security Headers
Rating 5.0/5 (8 reviews)Active installs 4,000
TLS 1.2 Compatibility Test
Rating 4.1/5 (14 reviews)Active installs 2,000

Description

When deploying a TLS enabled website, you must ensure that all content loaded on the site is loaded from secure origin.
If your content is loaded from an insecure source, the security of your whole site is compromised and modern browsers
will downgrade your website’s security rating.

The HTTPS Mixed Content Detector plugin attempts to identify sources of mixed content warnings. The plugin will examine
content loaded from the site when admins are viewing the site. Any content that violates the policy of loading content
that originates from “https:” resources will trigger an error and that resource will be logged. Viewing the log will
allow you to examine the site for any warnings and remove them before they cause problems for your website.

Installation

This section describes how to install the plugin and get it working.

  1. Upload https-mixed-content-detector to the /wp-content/plugins/ directory
  2. Activate the plugin through the ‘Plugins’ menu in WordPress
  3. Browse your site as an admin
  4. View the reports listed in the “Content Security Policy Reports” page in the admin
  5. Delete each violation report log as you fix it
  6. Rinse and repeat until your site is free of violation reports

Frequently Asked Questions

No FAQ available

Review feed

George Stephanis
11/7/2016

Super useful for sites transitioning to HTTPS

Tremendously useful.

Screenshots

  1. Content Security Policy reports are collected in the Content Security Policy Reports list table.

    Content Security Policy reports are collected in the Content Security Policy Reports list table.

  2. Information about Content Security Policy reports is available via WP CLI.

    Information about Content Security Policy reports is available via WP CLI.

Changelog

1.2.0

  • Add check for violation locations
  • Add sampling mode for examining non-logged in traffic
  • Add more content shown in the WP list table

1.1.0

  • Add check for HTTPS domain when logging violation
  • Add list, resolve, remove and unresolve WP CLI commands
  • Update CSP directives to be more specific

1.0.2

  • Remove false positives from the log

1.0.1

  • Limit logging to work only for admins

1.0.0

  • Initial release