Cloudflare
Security & compliance
Releases
Stability
Automatic HTTPS Rewrites off (mixed-content risk)
Part of the Edge TLS posture check · fix arrives as a guide
What it is
Automatic HTTPS Rewrites is off.
Why it matters
Pages served over HTTPS that reference http:// subresources trigger mixed-content blocking, so images and scripts silently fail to load. Users see a broken page rather than a security warning.
How to fix it
Enable Automatic HTTPS Rewrites so Cloudflare upgrades those references at the edge, and fix the underlying hardcoded http:// URLs in your templates so the rewrite is a safety net rather than the mechanism.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.