Why No Padlock is a handy, focused mixed-content checker. MySSL finds the same insecure HTTP resources, then also grades your SSL/TLS, security headers and email — and keeps monitoring your certificate. All free.
No card. Scanning needs no signup; an account adds re-scans and expiry alerts.
whynopadlock.com is a mixed-content scanner: paste an HTTPS URL and it lists the insecure http:// sub-resources — images, scripts, stylesheets, fonts — that stop the page being fully secure and drop the padlock, and it shows your certificate's expiry date. For that specific "why isn't my padlock showing?" question, it's quick and purpose-built.
It is, by design, narrower than a full scanner. It doesn't give a full TLS protocol/cipher grade, it doesn't grade your security headers or email authentication, and it doesn't monitor. MySSL includes the same mixed-content detection and wraps the rest of your security posture around it.
| Capability | MySSL.info | Why No Padlock |
|---|---|---|
| Mixed-content / insecure-resource scan | Yes | Yes — its focus |
| Certificate expiry shown | Yes | Yes |
| Price | Free | Free |
| Full SSL/TLS grade (A+ → F) | Yes | No |
| HTTP security headers grade | Yes | No |
| Email auth (SPF / DKIM / DMARC) | Yes | No |
| Certificate Transparency log search | Yes | No |
| Continuous monitoring + expiry alerts | Yes | No — one-off |
| Free JSON API | Yes | No |
https:// and re-scan to confirm the padlock is back.If your only question is "which resource is stopping my padlock from showing?", Why No Padlock is a fast, single-purpose answer and there's nothing wrong with using it for exactly that. Reach for MySSL when you want the mixed-content answer plus your SSL grade, headers, email checks and ongoing monitoring in one place.
whynopadlock.com is a focused mixed-content scanner. You give it an HTTPS URL and it lists the insecure HTTP sub-resources — images, scripts, stylesheets, fonts — that stop your page being fully secure and remove the padlock, and it also shows your certificate's expiry date. It does that one job well.
Both are free. MySSL also detects mixed content — http:// sub-resources loaded on an https page — but as part of a broader scan that also grades your SSL/TLS configuration, your HTTP security headers and your email authentication.
No — its focus is mixed content plus basic certificate information, not a full TLS protocol and cipher grade or a security-headers grade. If you only need to find the resource breaking your padlock, it's a quick, purpose-built tool. If you want a complete picture, MySSL gives an A+ to F SSL grade and a security-headers grade alongside the mixed-content check.
No — it's a one-off check you run by hand. MySSL can monitor on a schedule and alert you before a certificate expires or if a grade drops, via email, Slack, Discord, Telegram or webhook.
Yes. MySSL's security-headers 'deeper analysis' flags http:// sub-resources loaded on an https page, so you get the same mixed-content detection — plus the certificate, headers and email checks — in a single report.
Usually one insecure sub-resource — a single HTTP image, script or stylesheet on an otherwise HTTPS page — is enough to trigger a 'not fully secure' state and drop the padlock. Both tools list those resources so you can switch them to HTTPS; MySSL then also checks your certificate, headers and email in the same pass.
We're new and growing — your feedback helps us improve.