Home / Check catalog / 7. Security & Privacy / 7.2 Mixed Content Checks

7.2 Mixed Content Checks

30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.

Page-Level Mixed Content — Detection, Blocking & Remediation

IDCheckPasses whenWeightRuns
7.2.01Detect active mixed content (scripts, iframes)NoneCriticalDeterministic
7.2.02Detect passive mixed content (images, video, audio)NoneCriticalDeterministic
7.2.03Validate browser blocks unsafe requestsBlockedHeavyDeterministic
7.2.04Validate no HTTP resources loaded via dynamic JSNoneHeavyDeterministic
7.2.05Detect mixed content hidden behind query paramsNoneHeavyDeterministic
7.2.06Detect images hard-coded as HTTPNoneMediumDeterministic
7.2.07Detect video/audio embeds using HTTPNoneMediumDeterministic
7.2.08Detect iframe sources over HTTPNoneMediumDeterministic
7.2.09Validate no HTTP protocol fallback behaviorsNoneMediumDeterministic
7.2.10Compute Page-Level Mixed Content Health ScoreFinalizedCriticalDeterministic

Resource-Level Security — CSS, JS, Fonts, Third-Party Assets

IDCheckPasses whenWeightRuns
7.2.11Validate all JS requests use HTTPSHTTPSHeavyDeterministic
7.2.12Validate all CSS requests use HTTPSHTTPSHeavyDeterministic
7.2.13Validate all font files loaded over HTTPSHTTPSHeavyDeterministic
7.2.14Detect HTTP analytics or tracking beaconsNoneMediumDeterministic
7.2.15Detect HTTP script loaders (tag managers, CDN loaders)NoneMediumDeterministic
7.2.16Detect HTTP CDN fallback linksNoneMediumDeterministic
7.2.17Validate map libraries load over HTTPSHTTPSMediumDeterministic
7.2.18Validate payment libraries loaded securelySecureMediumDeterministic
7.2.19Detect mixed content triggered by A/B testing toolsNoneMediumDeterministic
7.2.20Compute Resource Security Integrity ScoreFinalizedCriticalDeterministic

Downgrade Attack Prevention — HTTP Fallback, Blocklisting, Policy Control

IDCheckPasses whenWeightRuns
7.2.21Validate all HTTP→HTTPS upgrades forcedForcedHeavyDeterministic
7.2.22Validate Referrer-Policy prevents insecure leakageSecureHeavyDeterministic
7.2.23Validate CSP blocks HTTP resource loadingBlockedHeavyDeterministic
7.2.24Validate redirects do not briefly downgrade to HTTPNo downgradeMediumDeterministic
7.2.25Detect scripts that rewrite URLs to HTTPNoneMediumDeterministic
7.2.26Validate HSTS prevents protocol downgradeEnforcedMediumDeterministic
7.2.27Detect old plugins/themes calling HTTP APIsNoneMediumDeterministic
7.2.28Validate embedded third-party widgets enforce HTTPSEnforcedMediumDeterministic
7.2.29Detect mixed content caused by redirects between domainsNoneMediumDeterministic
7.2.30Compute Mixed Content Compliance Master ScoreFinalizedCriticalDeterministic

← 7.1 HTTPS / TLS Integrity7.3 CORS & Access-Control Exposure →

Run these checks on your site

A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.

See plans

Machine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).