Mixed Active Content
1 Intentional IssuesServed over HTTPS, pulling a script, a stylesheet and an iframe over plain HTTP.
#66Issue #66: no_mixed_active — HTTPS page loading script/stylesheet/iframe over http://
Embedded widget over http://
Three confirmed active subresources: script[src], link[rel=stylesheet][href] and iframe[src].
Why this is not on /security-headers
That page is the existing fixture for the header-level findings (HSTS, CSP, Referrer-Policy, X-Frame-Options) and for passive mixed content. Adding active subresources there would have merged two separate conditions onto one URL, and a regression in either would have been indistinguishable in the report.