Skip to content

Fix: Load Unsafe Scripts in the Chrome browser

When Chrome blocks HTTP resources on an HTTPS page, it shows a 'Load unsafe scripts' warning. On modern Chrome the address bar padlock is gone, and the allow option now lives in Site settings. Here is the current procedure on desktop and Android.

Allowing unsafe scripts is fine on a page you trust. Skip it on banking, checkout, or login pages, where the warning exists for a real reason.

In this guide, I have covered:

How to Load Unsafe Scripts in Chrome

Chrome blocks scripts served over plain http:// on an HTTPS page. You’ll see a “Load unsafe scripts” warning. The old shield icon is gone. The allow control now lives in Site settings.

  1. Open the HTTPS page that is blocking the scripts.
  2. Click the Tune icon tune icon on the left side of the URL bar. 
  3. In the popup, click Site settings. A new tab opens with that site's permission list.
  4. Scroll to the Permissions section and find Insecure content.
  5. Click the dropdown next to it and switch it from Block (default) to Allow.
  6. Return to the original tab and refresh the page. The previously blocked scripts, images, or styles now load.

You’ll know it worked when the “Not secure” or “Loaded over an insecure connection” indicator disappears from the address bar, and the page renders the missing images, scripts, or styles. If nothing changes, make sure you selected Allow rather than Ask, and reload the tab.

Why Chrome Shows the “Load Unsafe Scripts” Warning

Chrome shows this warning because of mixed content protection. A page is served over https:// but pulls scripts, styles, images, or iframes from http://, an attacker on the network can swap those insecure files and read anything you submit on the page. To stop that, Chrome blocks the unsafe requests by default and surfaces the prompt you are looking at. The older broken shield icon on HTTPS pages came from this same check.

The warning can also fire on a trustworthy site if a single plugin, ad network, theme, or extension injects an http:// resource, so even a clean site can trigger it if it has not finished migrating every asset to HTTPS. If you want the full background on what HTTPS actually protects, see our guide on what an SSL certificate does.

How to Allow Insecure Content on Chrome for Android

On Android, you allow insecure content through Chrome’s site permissions list.

  1. Open Chrome on Android and load the page that is blocking scripts.
  2. Tap the three-dot menu vertical 3-dots icon in the top right and choose Settings.
  3. Tap Site settings.
  4. Scroll to Permissions and tap Insecure content.
  5. Tap the site you want to allow, then turn the toggle on so it shows Allowed instead of Blocked.
  6. Go back and reload the page.

You’ll know it worked when the page reloads without the “Site is not fully secure” banner, and the previously missing scripts or images appear. If you also need to control site wide JavaScript, our guide to enabling or blocking JavaScript on Chrome Android walks through that.

Should You Load Unsafe Scripts?

Only when you trust the page completely. Mixed content blocking exists because an HTTP resource can be tampered with in transit, and any form on that page (search, login, comment, payment) can leak through that hole.

alert icon

ALERT: If the page is a banking site, a checkout form, a login screen, or anything that asks for a password, card number, or personal information, leave the block in place and leave the site.

For everyday reading, content blogs, and small business sites, allowing the scripts once is usually low risk. Just know that Chrome will keep a small “Not secure” tag on the page while the permission is on, so you can see at a glance that the connection is no longer fully encrypted. The exception that is worth using this on is when you control the page yourself and need to confirm what is being blocked while debugging.

How to Check If a Site’s Connection Is Secure

You can verify a site’s certificate without leaving the page. Click the tune icon next to the URL and read the connection status in the popup. If it says “Connection is secure,” the certificate is valid. If it says “Connection is not secure” or “Your connection to this site is not private,” the certificate is missing, expired, or mistrusted, and you should not load unsafe scripts on it.

For deeper certificate details, open Site settings from the same popup and scroll to Privacy and security. You can also walk through Chrome’s full site information and settings panel if you want a full tour.

BrowserHow SSL Certificate Details in Chrome browser

How Site Owners Can Fix Mixed Content Warnings

If you own the site showing the warning, you can fix it permanently. The fix is rarely to allow the unsafe content; the fix is to remove every http:// reference and serve the page fully over HTTPS.

  • Migrate the site to https://. Free certificates are available through Let’s Encrypt, Cloudflare, and most modern hosts.
  • Update every link, image, script, stylesheet, and iframe on the page to use https://. Mixed content warnings disappear once nothing references the plain HTTP protocol.
  • Find the offending resources in Chrome DevTools. Open More tools > Developer tools > Console and look for “Mixed Content: The page at ‘https://...‘ was loaded over HTTPS, but requested an insecure image ‘http://...‘.” The exact file is listed there.
  • Avoid third party ad networks, plugins, or nulled scripts that load resources over HTTP. They are the most common cause of mixed content warnings on otherwise clean sites.
  • Run regular server scans with anti-malware tools so an injected script cannot quietly add http:// tags back into your pages.
  • Keep your CMS, plugins, and themes updated.

Once every asset is served over HTTPS, reload the page in Chrome and the “Load unsafe scripts” prompt will not come back.

Disclosure: This page may contain affiliate links, which means we may receive compensation for your purchases; of course at no extra cost to you (indeed, you may get special discounts).
Kushal Azza

Kushal Azza

Kushal Azza is a Google Certified Analytics & IT Professional, Digital Content Creator, and Go-To Digital Marketer. He has over a decade of experience solving tech problems, troubleshooting, and innovating digital solutions. Follow him on Twitter and LinkedIn.

Please share the article if you find it helpful:

10 comments and feedback

  1. My WordPress blog gives me error message like This page is tring to load scripts from unauthenticated source.
    So, i try to find out why this happen and how to solve it?
    And finally comes to this article.
    Thank you for posting such great and useful article.

  2. I doubt very much if the BBC iplayer is the problem with Unauthenticated Sources and suspect the problem is something else, in my case

    1. Yes, Brian – that could be a possible issue. Check if the BBC iPlayer is playing through https:// URL using inspect element or source code.

    1. I’d suggest checking your Google Chrome console to understand what exactly is causing the issue here.
      Google Toolbar > View > Developer > JavaScript Console

Leave a thought or feedback

Please leave a descriptive comment or feedback with your real name. Our human moderator vets every comment, and it may take 24 to 48 hours to get published or rejected.
Your email address will not be published, and we will never spam your inbox. Required fields are marked *