Free tool
Mixed Content Checker
Find the images, scripts, stylesheets and frames still loading over plain http on a secure page, which is why the padlock disappears or the layout breaks.
What mixed content means
A page served over https promises that everything on it arrived securely. If the page then asks for an image or a script over plain http, that promise is broken for part of the page. Browsers used to allow it quietly, then with a warning, and now they block the dangerous half entirely. A script loaded over http can be replaced in transit by anyone sitting between your visitor and the server, which would let them run their own code on your site, so refusing it is the correct behaviour.
Why only part of the page breaks
Browsers split insecure content into two groups. Active content, which can change the page, covers scripts, stylesheets, frames and form submissions, and is blocked without asking. Passive content, which can only be displayed, covers images, video and audio, and is usually loaded with the padlock removed. This is why the symptom is so often partial: the text is fine, the layout is wrong, a slider does nothing, and the contact form posts to nowhere.
A form with an http action deserves particular attention. The page looks encrypted to the visitor, and everything they type is then sent in clear text. That is worse than an insecure page, because it is misleading.
Where these references come from
Almost always from a migration. A site that used to run on http gets a certificate, and every address written into posts, theme settings, widget text and the database stays as it was. The content was correct before the move and is wrong afterwards. Hand editing finds some of it and misses the rest, which is why a database wide search and replace is the only reliable approach, followed by clearing every cache in front of the site.
The upgrade-insecure-requests policy is worth knowing about as a stopgap. It tells the browser to retry insecure references over https automatically, which hides the symptom immediately. It only works where the other server actually supports https, and it leaves the wrong addresses in your content, so treat it as breathing room rather than a fix.