Skip to content
Flare Built
For new brokerages

Real Estate Website Security: We Checked 43 Brokerages

October 8, 2026·9 min read·Written by Flare Built
A stainless steel visitor call box at the entrance of a gated residential community, its plate reading VISITORS PRESS CALL and its screen reading ENTER CODE, with an iron gate and a street of stucco homes behind

Real estate website security starts with a few things every visitor's browser checks before your homepage appears. We read them for 43 Sacramento-area brokerage websites on October 8, 2026. Two fail a basic certificate check, one of them on a certificate that expired in May 2019. Seven still serve their homepage over plain HTTP, and four announce server software that is out of support or will be within three months.

It matters more this month than it did last month. Since Chrome 154, released September 22, Chrome has begun asking first-time visitors before it opens a site without working HTTPS.

What 43 brokerage homepages showed a browser

Certificate fails the browser's check

Sites2
What 43 brokerage homepages showed a browser

Homepage served over plain HTTP, with no redirect to HTTPS

Sites7
What 43 brokerage homepages showed a browser

None of three basic security headers (of the 38 we could read)

Sites12
What 43 brokerage homepages showed a browser

Server software out of security support, or within days of it

Sites2
What 43 brokerage homepages showed a browser

PHP 8.2, whose security fixes end December 31, 2026

Sites2
What 43 brokerage homepages showed a browser

Scripts loaded over plain HTTP, which browsers block

Sites1
What 43 brokerage homepages showed a browser

WordPress sites showing their version that run the current release

Sites4 of 4

The sample is the same 43 brokerages we timed on a phone, checked for email setup and read for their Google site name. The method is at the end, and no firm is named.

What Chrome now shows when HTTPS is missing

Chrome has labelled plain HTTP pages for years. In 2018 Google announced that "In Chrome 68, the omnibox will display "Not secure" for all HTTP pages."

Chrome 154 goes a step further. Its release notes list "Ask before HTTP on by default": "Chrome prompts users by default when they connect to a site over an insecure (http) connection." Google's enterprise notes describe it as rolling out gradually, for public sites only. When Google announced the plan, it said Chrome "will ask for the user's permission before the first access to any public site without HTTPS," and that it will not warn repeatedly about a site the person visits regularly.

Read that from a brokerage's side. The person who sees the warning is the one visiting you for the first time: a seller who found your name on Google, a buyer who clicked your listing. Your regulars may never see it.

What we found on 43 Sacramento brokerage sites

Two certificates that fail

One site presents a certificate that expired on May 30, 2019. The other presents a valid certificate issued for a different web address. Both sites still load over plain HTTP.

Neither has a working HTTPS version, so once Chrome's new default reaches a visitor's browser, a first visit starts with a warning. Google also treats it as a reason to index the insecure copy: its canonical URL guidance says it prefers HTTPS "except when ... The HTTPS page has an invalid SSL certificate," and that bad certificates "cause Google to prefer HTTP very strongly."

Seven homepages still answer on plain HTTP

Seven of the 43 serve their homepage at http:// instead of sending the visitor to https://. Five of them have working HTTPS and simply never redirect to it; the other two are the sites above. For the five, it is a single setting at the web host, and Chrome already tries HTTPS on its own, so the cost today is small. It is still the one fix on this list that takes a minute.

Software that announces its age

Most sites do not say what they run. Four do, in their response headers:

  • One announces PHP 7.4.33. PHP 7.4 reached end of life on November 28, 2022, and 7.4.33 was its last release. PHP has published no security fix for it since.
  • Two announce PHP 8.2, whose security support ends on December 31, 2026.
  • One announces Microsoft IIS 8.5, the version that ships with Windows Server 2012 R2. Microsoft ended extended support on October 10, 2023, and its last paid security updates end on October 13, 2026. IIS "follows the same lifecycle" as Windows, Microsoft says.

The good news is real: all four WordPress sites that show their version run 7.1.3, the current release. Someone is keeping them updated.

We did not test whether any of these sites can be broken into, and we are not saying any has been. We read what each one tells every visitor, and so does every automated scanner on the internet.

Scripts the browser refuses to load

One homepage loads three copies of a common script library, one of them from 2010, over plain HTTP from its HTTPS page. Browsers "block insecure requests" for scripts in that situation, per MDN, so whatever on the page depends on them does not run. Google lists the same thing, "insecure dependencies (other than images)," as a reason to prefer the HTTP version of a page.

The three headers most sites skip

Three short instructions a server can send with every page cost nothing and take a developer minutes:

  • Strict-Transport-Security tells browsers to use only HTTPS for your domain from then on. 22 of 38 send it.
  • X-Content-Type-Options stops a browser guessing what kind of file it was sent. 18 of 38.
  • X-Frame-Options stops another site loading yours inside a frame to trick visitors into clicking. 10 of 38.

Twelve of the 38 send none of the three. Nine send a fourth header, Content-Security-Policy, mostly a one-line rule, often added by their website builder. Ours does not send one yet.

Certificates now expire twice as often

The certificate authorities and the four big browser makers voted unanimously last year to shorten how long a website certificate can last. Under the current rules, a certificate issued since March 15, 2026 "MUST NOT have a Validity Period greater than 200 days." From March 15, 2027 the limit is 100 days, and from March 15, 2029 it is 47.

32 of the 41 working certificates in our sample already last 90 days or less, which means something renews them automatically. Three still carry year-long certificates issued before the change, and the next one each of them gets can last no more than 200 days. A certificate renewed by hand at 47 days would need replacing about eight times a year. The 2019 certificate above shows what happens when nobody is assigned to it.

Why it matters in real estate

The FBI's 2025 IC3 Annual Report puts reported real estate fraud losses at $275,110,419 in 2025, up from $173,586,820 in 2024. We covered the email side of protecting clients in our brokerage email records check. Your website is the other public thing a client uses to decide you are real, and a browser warning on the first visit is a poor start to a relationship that ends in a wire transfer.

If Google ever decides a site has been tampered with, it says so in the results: "You'll see the message "This site may be hacked" when we believe a hacker might have changed some of the existing pages on the site or added new spam pages."

Our own site

We ran the same check on www.flarebuilt.com. Its certificate renews automatically every 90 days, http:// redirects to https://, and it sends Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, a referrer policy and a permissions policy. Two gaps, which we would rather name than leave out: our Strict-Transport-Security header asks to be preloaded into browsers, but we have not yet submitted the domain to the preload list, and the site does not send a Content-Security-Policy, the hardest of these to get right on a modern site.

Real estate website security: the fix, in order

  1. Open your site at https:// in a private window. Click the padlock, check the expiry date and that the certificate names your address. If you get a warning instead, fix this before anything else.
  2. Make every version land on https://. http://, with and without www, should all redirect there. It is one setting at most hosts.
  3. Make certificate renewal automatic, and ask your host to confirm it in writing. With 200-day certificates today and 47-day certificates by 2029, nobody should be doing this by hand.
  4. Ask your host which server and PHP version your site runs. Anything past its security support date gets upgraded. PHP 8.2's ends December 31. While you are asking, have the version header turned off; nobody needs it announced.
  5. Keep WordPress, the theme and every plugin updated, as the four sites in our sample do.
  6. Add the three headers above, and fix anything loaded over http:// from an https:// page.
  7. Set up Google Search Console, so that if Google ever flags your site as hacked, you hear about it from Google rather than from a client.

What we would build

A brokerage site with HTTPS, automatic certificate renewal and the security headers in place from the first day, on a stack nobody has to patch by hand, that also loads fast on a phone and shows its license number. A launch site starts at $900 and is live in 48 hours, and a full brokerage site starts at $4,500 and is live in about a week, with Flare Care keeping it current for the months after.

If you want this check run on your site, tell us about your brokerage, or build your package in about two minutes.

How we checked

The sites are every live website from our two earlier Sacramento-area audits: brokerage corporations licensed in Sacramento County since 2024 (residential) and Sacramento-region corporations with Commercial or CRE in their licensed name (commercial), the same 43 as our speed, email and site name checks.

On October 8, 2026 we did three things for each, and nothing else: opened one secure connection to read the certificate, requested the plain-HTTP homepage to see whether it redirects, and read the HTTPS homepage's own response headers and code. No other pages were requested, nothing was logged into, and no software was probed. Three homepages answered automated requests with a bot challenge, so their headers are left out of the header counts, which is why those use 38 rather than 41.

What it cannot see: everything behind the homepage, including plugins, admin logins and the server itself. A site can pass every check here and still be compromised, and miss several of them and be fine. These are the parts any visitor's browser, and any stranger, can read.

Frequently asked questions

Is my website secure if it shows a padlock?

The padlock means the connection is encrypted and the certificate matches your address. It says nothing about the software running behind the site, which is where most other problems live. Of the 43 brokerage sites we checked, 41 had a working padlock, and one of those announces server software that stopped receiving security fixes in November 2022.

What does Chrome show for a website without HTTPS now?

Since Chrome 154, released September 22, 2026, Chrome 'prompts users by default when they connect to a site over an insecure (http) connection.' Google is rolling it out gradually. It asks before the first visit to a public site without HTTPS, and Google says it will not keep warning about a site the person visits regularly, so the people who see it most are first-time visitors.

How often do SSL certificates need to be renewed?

More often every year. Certificates issued since March 15, 2026 can last at most 200 days, from March 15, 2027 at most 100 days, and from March 15, 2029 at most 47 days, under the rules the certificate authorities and browsers voted for unanimously. Renewal has to be automatic; at 47 days, a hand-renewed certificate would need replacing about eight times a year.

Does HTTPS help my Google ranking?

Not directly, by Google's current account. It lists secure delivery as part of page experience but says aspects other than Core Web Vitals 'don't directly help your website rank higher.' A broken certificate does hurt, though: Google says bad certificates 'cause Google to prefer HTTP very strongly,' so it may index the insecure version of your page.

How do I check my own website's security?

Open your site at https:// in a private window and click the padlock to see the certificate's expiry date and the address it covers. Type your address with http:// and make sure it lands on https://. Then ask your web host which server and PHP version your site runs and whether certificate renewal is automatic.

See what your site tells referrals.
Get a free teardown.

A short, plain-language video showing where your site wins trust, where it loses the call, and what fixing it would look like. Yours to keep either way.

Start a project
Only 2 builds a month · 1 slot leftThe Love-It-Live GuaranteeThe On-Time Promise