What is mixed content?
Mixed content is when a TLS (
https) website loads non-TLS (
http) resources. The latter will significantly reduce the protection provided by TLS on the parent website as it can be easily intercepted, modified and used for active attacks against the user.
Historically most websites were delivered over plaintext HTTP, without any encryption and server authentication, and TLS (then called SSL) was an expensive option reserved for e-commerce websites. As Internet became less safer place there was a trend to migrate all websites to TLS, especially with introduction of free TLS certificates and decrease in the cost of computing power.