WordPress
Fix WordPress Redirects & Mixed Content
Fix redirect loops, incorrect HTTP/HTTPS redirects, and mixed-content warnings after an SSL change or migration.
The Problem
After adding SSL or moving domains, WordPress often keeps calling some resources over the old protocol or URL — browsers show a "not secure" padlock and some assets quietly fail to load.
About this problem
WordPress stores its address in the siteurl and home options and also writes absolute URLs into post content, widgets, theme options and page builder data. When a site switches to HTTPS or changes domain, any of these can keep pointing at the old http address. Browsers then flag mixed content, and conflicting redirect rules in .htaccess, the server and a plugin can send visitors in a loop.
People usually look for this right after installing an SSL certificate or migrating, when the padlock shows a warning, images or scripts fail to load, or the browser reports too many redirects. Often the issue appears only on some pages.
What's Included
- Fixing site URL settings (siteurl/home) to the correct protocol and domain
- Resolving any redirect loop causing "too many redirects" errors
- Finding and fixing hardcoded HTTP references in the database/theme
- Confirming a clean SSL padlock with zero mixed-content warnings
What's NOT Included
- Purchasing or installing an SSL certificate (assumes one is already active)
- Fixing third-party embeds that force HTTP and can't be changed
- CDN-level redirect configuration
How It Works
- I check the siteurl and home values, and compare them with how the site is served, including any proxy or load balancer headers.
- I trace the redirect chain with a request tool to find where the loop or incorrect hop happens, across .htaccess, server config and plugins.
- I correct the redirect rules so there is one clean path to the preferred HTTPS address.
- I take a database backup, then run a serialization-safe search and replace to update hardcoded http references in posts, options and theme settings.
- I check theme files and widgets for hardcoded URLs and fix those that can be fixed.
- I crawl key pages and check the browser console to confirm there are no mixed-content warnings and a valid padlock.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I fix mixed content warnings in WordPress?
- Update the site URLs to HTTPS and replace old http references in the database and theme files. Then check pages in the browser for anything still loading insecurely.
- Why is my site showing too many redirects?
- Usually two rules fight each other, for example a plugin forcing HTTPS while the server or a proxy sends the request back. Tracing the chain finds which one.
- Do you install the SSL certificate?
- No, this service assumes a certificate is already active. Obtaining or installing one is separate.
- What about third-party embeds that only use HTTP?
- If they cannot be changed they may still cause warnings. I will point out any that I cannot fix.
- Do you configure the CDN redirects?
- CDN-level redirect configuration is excluded.
- Is a search and replace in the database safe?
- Done with a serialisation-aware tool and a backup first, it is a routine approach. I never use a plain text replacement on serialised data.