How To Fix Mixed Content Error in aaPanel (2026 Guide)
Seeing this in your browser console?
⚠ “Mixed Content: The page was loaded over HTTPS, but requested an insecure resource…”
If you’re running your website on:
This guide will help you fix it permanently.
—
🧠 What Is Mixed Content?
Mixed content happens when:
✔ Your website loads over HTTPS
❌ But some resources load over HTTP
Example:
$$
https://yourdomain.com
$$
But image loads as:
$$

$$
Modern browsers block these insecure resources.
—
🚨 Why Mixed Content Happens in aaPanel
Common triggers:
Installing SSL after site was already live
Connecting to Cloudflare
Hardcoded HTTP links in database
Old theme files
CDN misconfiguration
Manual redirect conflicts
—
✅ Step-by-Step Fix (2026 Method)
—
🟢 STEP 1: Confirm Proper SSL Setup



4
Check:
✔ SSL installed in aaPanel
✔ Let’s Encrypt active
✔ Cloudflare SSL mode = Full (Strict)
✔ HTTPS works without warnings
Never use Flexible SSL.
—
🟢 STEP 2: Force HTTPS Properly
Inside aaPanel:
Website → Settings → Redirect
Enable:
$$
HTTP → HTTPS
$$
⚠ Avoid duplicate redirect rules in .htaccess and Nginx.
—
🟢 STEP 3: Replace HTTP Links in Database (Most Important)
If using WordPress:
Many links may still be:
$$
http://yourdomain.com
$$
Replace with:
$$
https://yourdomain.com
$$
You can:
✔ Use search & replace plugin
✔ Or run SQL query:
$$
UPDATE wp_options
SET option_value = replace(option_value, ‘http://yourdomain.com’, ‘https://yourdomain.com’);
$$
Backup database first.
—
🟢 STEP 4: Fix Hardcoded Links in Theme Files
Check:
header.php
footer.php
CSS files
JavaScript files
Replace all:
$$
http://
$$
With:
$$
https://
$$
—
🟢 STEP 5: Fix External CDN Resources
Sometimes problem comes from:
Ensure all external resources support HTTPS.
—
🟢 STEP 6: Clear Cache Everywhere
After fixes:
✔ Clear browser cache
✔ Clear Cloudflare cache
✔ Clear CMS cache
✔ Restart Nginx in aaPanel
Cached content often causes false mixed warnings.
—
🔥 Advanced Fix (Nginx Users)
Add this in Nginx config:
$$
add_header Content-Security-Policy upgrade-insecure-requests;
$$
This forces browser to upgrade HTTP resources automatically.
Restart Nginx afterward.
—
🔎 How To Verify Fix
Open:
Right-click → Inspect → Console
No more:
$$
Mixed Content warnings
$$
Padlock should show:
🔒 Secure connection
—
⚡ Quick Fix Checklist
| Fix | Done |
| SSL installed | ✅ |
| Full (Strict) SSL | ✅ |
| HTTPS redirect enabled | ✅ |
| Database links updated | ✅ |
| Hardcoded links fixed | ✅ |
| External resources secure | ✅ |
| Cache cleared | ✅ |
—
🚀 Best Practice Setup (Stable 2026)
✔ Let’s Encrypt installed
✔ Nginx recommended
✔ Full (Strict) SSL in Cloudflare
✔ Avoid Flexible mode
✔ Update database after SSL activation
—
Web Development #aaPanel #MixedContent #HTTPSFix #Cloudflare #SSLSetup #VPSHosting #WebSecurity