My site thinks it’s secure when it is fact not

wp_config was set up to force SSL by overwriting $_SERVER[‘HTTPS’], I respolved the issue.

I assume someone was trying to make SSL work behind the proxy at one point.

It would actually be a much better solution ( specifically for asset links ) to use the double slash //