Ciao,
se da Chrome vai su Visualizza, Opzioni per gli sviluppatori, Strumenti per gli sviluppatori, vedi da quali link non https cerca di caricare contenuti.
Secondo me è sostanzialmente il font.
Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:300,400'. This content should also be served over HTTPS.
(index):109 Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:100,400'. This content should also be served over HTTPS.
(index):111 Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:200,400'. This content should also be served over HTTPS.
(index):113 Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:300,400,800'. This content should also be served over HTTPS.
(index):115 Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:600,400,300'. This content should also be served over HTTPS.
(index):117 Mixed Content: The page at 'https://carlomazzetti.eu/' was loaded over HTTPS, but requested an insecure stylesheet 'http://fonts.googleapis.com/css?family=Open+Sans:300,400'. This content should also be served over HTTPS.