Cloudflare Security & compliance Releases Stability

Automatic HTTPS Rewrites off (mixed-content risk)

Part of the Edge TLS posture check · fix arrives as a guide

What it is

Automatic HTTPS Rewrites is off.

Why it matters

Pages served over HTTPS that reference http:// subresources trigger mixed-content blocking, so images and scripts silently fail to load. Users see a broken page rather than a security warning.

How to fix it

Enable Automatic HTTPS Rewrites so Cloudflare upgrades those references at the edge, and fix the underlying hardcoded http:// URLs in your templates so the rewrite is a safety net rather than the mechanism.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.