Browser inspection and extraction

Free Webpage Mixed Content Finder.

Insecure resource references visible in accessible page data.

Review insecure resource references with their page context and collect the evidence needed for a targeted correction.

Chrome extension + account required.
25 free automation tasks/month across tools. Browser-provider limits apply.

WHAT TO HAVE READY

HTTPS page resource URLs.

YOUR STARTING POINT

A task you can make yours.

Copy it here. Paste it into WebAct when you are ready.

This page prepares your prompt. The task runs in WebAct.

01

Make the task yours.

Review the prompt above. Add your goal and any requirements that matter.

02

Bring it to WebAct.

Open the source page, activate WebAct and select the relevant readable content. Paste the task and provide any additional source material it requests.

03

Check the useful part.

The result covers the readable content you provide or select. Expand the relevant page sections first and check that the output includes the records you intended.

A PRACTICAL GUIDE

How to use the Webpage Mixed Content Finder.

An insecure resource reference is a finding to inspect in context. Browser handling differs by resource type and policy, so do not equate every reference with an exploitable vulnerability.

Make the workflow fit your task.

Identify insecure resource URLs referenced by an HTTPS page and classify their type and location. Distinguish a source reference from an observed network request or browser block. Verify an HTTPS replacement actually exists before recommending a URL change.

What you provide
HTTPS page resource URLs.
What you get
Insecure resource references visible in accessible page data.

See the input and the result.

Illustrative input and output · a teaching example, not a live WebAct run

Example input

HTTPS source page https://example.com/ contains <script src="http://assets.example.com/app.js"></script>. No network or console observations supplied.

Completed example

Resource: http://assets.example.com/app.js
Type: script loaded into an HTTPS page.
Finding: insecure script reference requiring mixed-content review.
Observed browser outcome: not supplied.
Next check: inspect the console/request and verify a supported HTTPS asset URL before changing the reference.
Download this example

Load this input into the prompt, then copy it to WebAct to try the task. Your result may differ from the illustration.

Decisions and troubleshooting.

Should every http link on an HTTPS page be classified as mixed content?

Ordinary navigation links differ from resources loaded into the page. Classify the reference according to how the browser uses it.

Why does replacing http with https still break the asset?

The destination may not serve that resource over HTTPS. Test the supported endpoint and certificate rather than assuming a scheme change is enough.

Try it with your own source.

Replace the example with your material in the task prompt. Keep the requirements you need, then copy the task into WebAct.

Customize and copy the task ↑
BEFORE YOU BEGIN

Using WebAct.

The prompt and example are available here. Run your task in the WebAct Chrome extension.

Is this tool free?

You can copy and edit the prompt here for free. To use it with WebAct, install the Chrome extension, create and verify your account, and connect an available browser ChatGPT session. The Free plan includes 25 user-started automation tasks per calendar month, shared across tools. Ordinary browser Chat is separate; provider limits apply.

Learn about shared context in our privacy policy and choosing Chat or Task.

FROM A PROMPT TO YOUR OWN WORK

Bring the task to your page.

Install WebAct, add your source material and make the result yours.

Install WebAct