Do not link from HTTPS to HTTP
SkillDev toolshttps-downgrade is a skill for auditing links and URLs for protocol consistency. It finds internal and external links that still use http://, helps when migrating a site from HTTP to HTTPS, and reviews hardcoded URLs in a codebase that may use http:// instead of https://.
Use Do not link from HTTPS to HTTP in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Do not link from HTTPS to HTTP and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Do not link from HTTPS to HTTP skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Have the site or codebase you want to audit available for review.
What your AI can do with it
- Audits a site's internal and external links for protocol consistency
- Supports migrating a site from HTTP to HTTPS
- Reviews hardcoded URLs in a codebase for http:// usage
- Flags URLs that use http:// instead of https://
Getting started
- Have the site or codebase you want to audit available for review.
- Add the https-downgrade skill to your agent's available skills.
- Ask the agent to audit links for protocol consistency, review hardcoded http:// URLs, or help with an HTTP to HTTPS migration.
What this skill tells your AI
The instructions your AI receives, as published by thedaviddias/front-end-checklist in skills/https-downgrade/SKILL.md and read by ahel’s review.
Linking from a secure HTTPS page to an HTTP destination creates a mixed content situation that browsers warn users about or block entirely. It also means the linked page does not receive the ranking signal passed through the HTTPS referrer. For internal links, it can cause redirect loops or broken navigation.
Quick Reference
- All internal links on an HTTPS page must point to HTTPS URLs — HTTP links trigger mixed content warnings
- External links to HTTP destinations break the security chain and may be blocked by browsers
- Use protocol-relative URLs (
//example.com) or absolute HTTPS URLs — never hardcodehttp://for internal links
Check
On pages served over HTTPS, scan all <a href> attributes for URLs starting with http:// (not https://). Flag: (1) Internal links using http:// that should use https:// or a relative path. (2) External links to third-party sites still on HTTP (flag for review — the destination may not support HTTPS). (3) Resource links (<img src>, <script src>, <link href>) pointing to HTTP URLs — these cause active mixed content warnings.
Fix
- Audit all
<a href>values in templates and content forhttp://links. - For internal links: change
http://yourdomain.com/pathto/path(relative) orhttps://yourdomain.com/path. - For external links: check if the destination supports HTTPS; update to
https://if so. - For resource links (scripts, styles, images): always use
https://or protocol-relative//. - In your CMS or database: run a search-and-replace to update stored HTTP URLs to HTTPS.
- Set up a server-level redirect from HTTP to HTTPS to catch any remaining HTTP URLs in user-generated content.
- Verify with:
grep -r 'href="http://' ./templates/or use a link auditing tool.
Explain
HTTPS is a confirmed Google ranking factor. When an HTTPS page links to HTTP resources or destinations, it downgrades the secure context, triggering browser warnings and potentially blocking content. For internal links, HTTP destinations mean an extra redirect (HTTP→HTTPS) on every navigation, slowing page loads. The ranking signal passed via the link's referrer is also diminished when crossing from HTTPS to HTTP.
Code Review
Parse all <a href>, <img src>, <script src>, and <link href> attributes. Flag any value starting with http:// (not https:// or a relative path). In JavaScript frameworks, also check for http:// in fetch(), axios, or router navigation calls. Report the count of HTTP links by category (internal, external, resource).
For full implementation details, code examples, and framework-specific guidance,
see references/rule.md.
Rule page: https://frontendchecklist.io/en/rules/seo/https-downgrade
Signals
- GitHub stars
- 74k
- Forks
- 7k
- Last commit
- Oct 2026
Questions
- When should this skill be used?
- Use it when auditing a site's internal and external links for protocol consistency, migrating a site from HTTP to HTTPS, or reviewing hardcoded URLs in a codebase that may use http:// instead of https://.
- Can it check both internal and external links?
- Yes, it audits a site's internal and external links for protocol consistency.
- Does it work on code as well as websites?
- Yes, it can review hardcoded URLs in a codebase that may use http:// instead of https://.
Advanced
- Item type
- skill
- Key
https-downgrade- Source
- github.com/thedaviddias/front-end-checklist
github.com/thedaviddias/front-end-checklist