Make sure you embed the HTTPS version of the URL and in case you use custom BBCode, it should embed as HTTPS and not HTTP.
You can also try adding <meta http-equiv="Content-Security-Policy" content="upgrade-insecure-requests"> to the headinclude template.