Vovy finds every http:// link loading on your https site, switches them to secure URLs, and gets the padlock back in the address bar.
My site shows a mixed content error and images won't load
How it works
- Read the mixed content errors: Vovy opens the console and lists each "Mixed Content: the page was loaded over HTTPS, but requested an insecure resource" message.
- Explain why the browser blocks them: A secure page loading an unsecured file is like locking the front door and leaving a window open. Browsers block scripts and API calls outright.
- Find the http links in your code: Cursor searches your code, env variables and database content for hardcoded http:// URLs, including image links stored in tables.
- Switch them to https: It updates the links and env values, and if you use Cloudflare, can turn on Automatic HTTPS Rewrites as a safety net.
- Confirm the padlock: Vovy reloads and shows the Security panel in DevTools reporting the page as secure, with no warnings.
What you provide
- Your live URL
- Your project open in Cursor
What you get
- Every insecure request found
- Links fixed in code and config
- Secure padlock restored
FAQ
What if the image host doesn't support https?
Then download the image and host it yourself, in your project or a storage bucket, rather than loading it from an insecure site.
Does this affect SEO?
Google prefers HTTPS pages, and broken images or scripts hurt the experience. Fixing it removes both problems.
Why did it start after I added a custom domain?
Often an env variable like API_URL still says http:// or points to an old address. Vovy checks those first.
Related tasks
All tasks