Mixed Content Checker
SecurityFind HTTP resources loaded on HTTPS pages. Detect active and passive mixed content issues.
Find HTTP resources loaded on HTTPS pages. Detect active and passive mixed content issues.
Get access to all 150+ tools with higher limits. Start with 100 free credits — no credit card required.
curl -X POST "https://krawly.io/api/v1/tools/mixed-content-checker/" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_KEY" \
-d '{"url": "https://example.com"}'Mixed Content Checker scans HTTPS pages for HTTP resources (images, scripts, iframes) that compromise security. Active mixed content (scripts) is especially dangerous.
Check DMARC, SPF, and DKIM DNS records for any domain to assess email authentication and prevent spoofing.
Analyze Content Security Policy headers. Check for unsafe-inline, unsafe-eval, and wildcards.
Analyze cookies set by a website. Check Secure, HttpOnly, SameSite flags and compliance issues.
Test CORS configuration for vulnerabilities. Check wildcard, null origin, and credential leaks.