Do not link from HTTPS to HTTP

SkillDev tools

https-downgrade is an agent skill for auditing links and URLs for protocol consistency. It helps find HTTPS pages that link to HTTP destinations, hardcoded http:// URLs in a codebase, and mixed content issues. It is useful when migrating a si

Available today. Use it from your connected AI after setup.

Have an agent that can load skills, and access to the site's templates, content, or codebase to be audited.

Then ask your AI: use the Do not link from HTTPS to HTTP skill

What your AI can do with it

  • Scan <a href> attributes on HTTPS pages for URLs starting with http://
  • Flag internal links that should use https:// or a relative path
  • Flag external links to third-party sites still served over HTTP for review
  • Detect resource links (<img src>, <script src>, <link href>) pointing to HTTP URLs
  • Check JavaScript frameworks for http:// in fetch(), axios, or router navigation calls
  • Report counts of HTTP links by category and suggest fixes like relative paths or protocol-

Getting started

  1. Have an agent that can load skills, and access to the site's templates, content, or codebase to be audited.
  2. Add the https-downgrade skill to the agent's available skills.
  3. Ask the agent to audit the site's internal and external links for protocol consistency, or to review hardcoded http:// URLs in the codebase.
  4. Apply the suggested fixes, such as converting internal links to relative or HTTPS paths and updating stored URLs in the CMS or database.
  5. Verify results with a search such as grep -r 'href="http://' ./templates/ or a link auditing tool.

What this skill tells your AI

The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/https-downgrade/SKILL.md and read by ahel’s review.

Linking from a secure HTTPS page to an HTTP destination creates a mixed content situation that browsers warn users about or block entirely. It also means the linked page does not receive the ranking signal passed through the HTTPS referrer. For internal links, it can cause redirect loops or broken navigation.

Quick Reference

  • All internal links on an HTTPS page must point to HTTPS URLs — HTTP links trigger mixed content warnings
  • External links to HTTP destinations break the security chain and may be blocked by browsers
  • Use protocol-relative URLs (//example.com) or absolute HTTPS URLs — never hardcode http:// for internal links

Check

On pages served over HTTPS, scan all <a href> attributes for URLs starting with http:// (not https://). Flag: (1) Internal links using http:// that should use https:// or a relative path. (2) External links to third-party sites still on HTTP (flag for review — the destination may not support HTTPS). (3) Resource links (<img src>, <script src>, <link href>) pointing to HTTP URLs — these cause active mixed content warnings.

Fix

  1. Audit all <a href> values in templates and content for http:// links.
  2. For internal links: change http://yourdomain.com/path to /path (relative) or https://yourdomain.com/path.
  3. For external links: check if the destination supports HTTPS; update to https:// if so.
  4. For resource links (scripts, styles, images): always use https:// or protocol-relative //.
  5. In your CMS or database: run a search-and-replace to update stored HTTP URLs to HTTPS.
  6. Set up a server-level redirect from HTTP to HTTPS to catch any remaining HTTP URLs in user-generated content.
  7. Verify with: grep -r 'href="http://' ./templates/ or use a link auditing tool.

Explain

HTTPS is a confirmed Google ranking factor. When an HTTPS page links to HTTP resources or destinations, it downgrades the secure context, triggering browser warnings and potentially blocking content. For internal links, HTTP destinations mean an extra redirect (HTTP→HTTPS) on every navigation, slowing page loads. The ranking signal passed via the link's referrer is also diminished when crossing from HTTPS to HTTP.

Code Review

Parse all <a href>, <img src>, <script src>, and <link href> attributes. Flag any value starting with http:// (not https:// or a relative path). In JavaScript frameworks, also check for http:// in fetch(), axios, or router navigation calls. Report the count of HTTP links by category (internal, external, resource).


For full implementation details, code examples, and framework-specific guidance, see references/rule.md.

Rule page: https://frontendchecklist.io/en/rules/seo/https-downgrade

Signals

GitHub stars
74k
Forks
7k
Last commit
Aug 2026

Questions

Why should an HTTPS page never link to HTTP?
Linking from HTTPS to HTTP creates a mixed content situation that browsers warn users about or block. It also means the linked page does not receive the ranking signal passed through the HTTPS referrer, and internal HTTP links can cause redirect loops or broken navigation.
What should internal links use instead of http://?
Use relative paths (e.g. /path), absolute HTTPS URLs, or protocol-relative URLs (//example.com). Never hardcode http:// for internal links.
Advanced
Item type
skill
Key
https-downgrade
Source
github.com/thedaviddias/front-end-checklist