Mixed content alerts
We continuously check whether your HTTPS site loads resources over insecure HTTP — images, scripts, styles, iframes, fonts. Such mixed content is marked 'not secure' by browsers or blocked outright, and part of the page breaks. If it appeared after an edit or a new widget, you get an alert. Honestly upfront: this is detection and alerting, not fixing — replacing links with https or removing the insecure resource is up to you or your team.
Mixed content alerts — overview

Mixed content alerts is an ongoing (monthly) service: we regularly check agreed pages for mixed content — resources loaded over http:// on an https-secured page (images, scripts, styles, media, iframes, fonts, requests). We distinguish active mixed content (scripts/iframes — usually blocked by the browser, functionality breaks) from passive (images/media — a warning and a risk). When new mixed content appears after a deploy, a template edit or a connected third-party widget, an alert arrives with which page and which resource. Honestly about the essence: this is detection and alerting, NOT fixing — we do not edit the HTML, rewrite links to https or remove insecure resources for you; remediation is done by your team or by us separately. Honestly about the method and coverage: the check runs on agreed pages and on what actually loads on visit; content loaded dynamically only on certain user actions or from rare scenarios can be missed — coverage depends on what we see during the check. There can also be third-party causes: an external provider's widget or script pulls an http resource itself — this is visible in the alert, but we cannot influence someone else's code. Coverage is the configured pages; someone must react to an alert. An important boundary: this is mixed-content control, not a security audit, not server/HTTPS configuration and not markup fixing. If the site is small, static and has long been fully on https without third-party widgets, continuous monitoring may be overkill — a one-time check is enough. Picture this: instead of 'after connecting a new widget the browser showed a lock with a warning and some scripts stopped working, and it was noticed late' you get an alert on the day of the change. The base price starts from 6,000 ₽ per month; it depends on the number of pages and the check frequency.
Problems we solve
- After edits or a new widget an insecure http resource appears on an HTTPS page.
- The browser shows 'not secure' or blocks some content, and the cause is unclear.
- You are not sure the whole site honestly runs over https without exceptions.
- You learn about mixed content from users or the browser console by chance.
What's included in the Mixed content alerts service
- Regular check of agreed pages for mixed content
- Distinguishing active (scripts/iframes) from passive (images/media)
- Which resource and on which page loads over http
- Control of appearance after deploys/edits/third-party widgets
- Alerts on new mixed content
- Monthly continuous operation
- An indication of the source — your code or a third-party widget
- An alert channel of your choice (email, messenger, webhook)
What you get
- You learn about mixed content on the day it appears
- You see which resource and where loads insecurely
- You know whether it is an active blocking case or passive
- You know what to replace or remove (the fix — by you/team)
How the work goes: steps
- We agree on pages, check frequency and the alert channel; collect access if needed
- We set up regular checking of loaded resources for http
- We launch monitoring, keep the page list current on changes
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Will you fix the mixed content?
No. We detect and notify with details (page and resource), but we do not edit the HTML, rewrite links to https or remove insecure resources. Remediation is done by your team or by us separately.
Will you catch every case?
Not guaranteed. The check sees what actually loads on agreed pages on visit; content loaded dynamically only on certain actions or from rare scenarios can be missed. Coverage depends on what we see during the check.
What if a third-party widget pulls the http resource?
It is visible in the alert, but we cannot influence someone else's code — the widget settings or the widget itself will have to change (on your side or with the provider). We only show the source of the problem.
About the provider
The «Mixed content alerts» service is provided by PDV Expert — a team specialising in «Diagnostics & monitoring». We work under contract and deliver a written report with recommendations.