Real estate website security starts with a few things every visitor's browser checks before your homepage appears. We read them for 43 Sacramento-area brokerage websites on October 8, 2026. Two fail a basic certificate check, one of them on a certificate that expired in May 2019. Seven still serve their homepage over plain HTTP, and four announce server software that is out of support or will be within three months.
It matters more this month than it did last month. Since Chrome 154, released September 22, Chrome has begun asking first-time visitors before it opens a site without working HTTPS.
Certificate fails the browser's check
Homepage served over plain HTTP, with no redirect to HTTPS
None of three basic security headers (of the 38 we could read)
Server software out of security support, or within days of it
PHP 8.2, whose security fixes end December 31, 2026
Scripts loaded over plain HTTP, which browsers block
WordPress sites showing their version that run the current release
| What 43 brokerage homepages showed a browser | Sites |
|---|---|
| Certificate fails the browser's check | 2 |
| Homepage served over plain HTTP, with no redirect to HTTPS | 7 |
| None of three basic security headers (of the 38 we could read) | 12 |
| Server software out of security support, or within days of it | 2 |
| PHP 8.2, whose security fixes end December 31, 2026 | 2 |
| Scripts loaded over plain HTTP, which browsers block | 1 |
| WordPress sites showing their version that run the current release | 4 of 4 |
The sample is the same 43 brokerages we timed on a phone, checked for email setup and read for their Google site name. The method is at the end, and no firm is named.
What Chrome now shows when HTTPS is missing
Chrome has labelled plain HTTP pages for years. In 2018 Google announced that "In Chrome 68, the omnibox will display "Not secure" for all HTTP pages."
Chrome 154 goes a step further. Its release notes list "Ask before HTTP on by default": "Chrome prompts users by default when they connect to a site over an insecure (http) connection." Google's enterprise notes describe it as rolling out gradually, for public sites only. When Google announced the plan, it said Chrome "will ask for the user's permission before the first access to any public site without HTTPS," and that it will not warn repeatedly about a site the person visits regularly.
Read that from a brokerage's side. The person who sees the warning is the one visiting you for the first time: a seller who found your name on Google, a buyer who clicked your listing. Your regulars may never see it.
What we found on 43 Sacramento brokerage sites
Two certificates that fail
One site presents a certificate that expired on May 30, 2019. The other presents a valid certificate issued for a different web address. Both sites still load over plain HTTP.
Neither has a working HTTPS version, so once Chrome's new default reaches a visitor's browser, a first visit starts with a warning. Google also treats it as a reason to index the insecure copy: its canonical URL guidance says it prefers HTTPS "except when ... The HTTPS page has an invalid SSL certificate," and that bad certificates "cause Google to prefer HTTP very strongly."
Seven homepages still answer on plain HTTP
Seven of the 43 serve their homepage at http:// instead of sending the visitor to https://. Five of them have working HTTPS and simply never redirect to it; the other two are the sites above. For the five, it is a single setting at the web host, and Chrome already tries HTTPS on its own, so the cost today is small. It is still the one fix on this list that takes a minute.
Software that announces its age
Most sites do not say what they run. Four do, in their response headers:
- One announces PHP 7.4.33. PHP 7.4 reached end of life on November 28, 2022, and 7.4.33 was its last release. PHP has published no security fix for it since.
- Two announce PHP 8.2, whose security support ends on December 31, 2026.
- One announces Microsoft IIS 8.5, the version that ships with Windows Server 2012 R2. Microsoft ended extended support on October 10, 2023, and its last paid security updates end on October 13, 2026. IIS "follows the same lifecycle" as Windows, Microsoft says.
The good news is real: all four WordPress sites that show their version run 7.1.3, the current release. Someone is keeping them updated.
We did not test whether any of these sites can be broken into, and we are not saying any has been. We read what each one tells every visitor, and so does every automated scanner on the internet.
Scripts the browser refuses to load
One homepage loads three copies of a common script library, one of them from 2010, over plain HTTP from its HTTPS page. Browsers "block insecure requests" for scripts in that situation, per MDN, so whatever on the page depends on them does not run. Google lists the same thing, "insecure dependencies (other than images)," as a reason to prefer the HTTP version of a page.
The three headers most sites skip
Three short instructions a server can send with every page cost nothing and take a developer minutes:
- Strict-Transport-Security tells browsers to use only HTTPS for your domain from then on. 22 of 38 send it.
- X-Content-Type-Options stops a browser guessing what kind of file it was sent. 18 of 38.
- X-Frame-Options stops another site loading yours inside a frame to trick visitors into clicking. 10 of 38.
Twelve of the 38 send none of the three. Nine send a fourth header, Content-Security-Policy, mostly a one-line rule, often added by their website builder. Ours does not send one yet.
Certificates now expire twice as often
The certificate authorities and the four big browser makers voted unanimously last year to shorten how long a website certificate can last. Under the current rules, a certificate issued since March 15, 2026 "MUST NOT have a Validity Period greater than 200 days." From March 15, 2027 the limit is 100 days, and from March 15, 2029 it is 47.
32 of the 41 working certificates in our sample already last 90 days or less, which means something renews them automatically. Three still carry year-long certificates issued before the change, and the next one each of them gets can last no more than 200 days. A certificate renewed by hand at 47 days would need replacing about eight times a year. The 2019 certificate above shows what happens when nobody is assigned to it.
Why it matters in real estate
The FBI's 2025 IC3 Annual Report puts reported real estate fraud losses at $275,110,419 in 2025, up from $173,586,820 in 2024. We covered the email side of protecting clients in our brokerage email records check. Your website is the other public thing a client uses to decide you are real, and a browser warning on the first visit is a poor start to a relationship that ends in a wire transfer.
If Google ever decides a site has been tampered with, it says so in the results: "You'll see the message "This site may be hacked" when we believe a hacker might have changed some of the existing pages on the site or added new spam pages."
Our own site
We ran the same check on www.flarebuilt.com. Its certificate renews automatically every 90 days, http:// redirects to https://, and it sends Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, a referrer policy and a permissions policy. Two gaps, which we would rather name than leave out: our Strict-Transport-Security header asks to be preloaded into browsers, but we have not yet submitted the domain to the preload list, and the site does not send a Content-Security-Policy, the hardest of these to get right on a modern site.
Real estate website security: the fix, in order
- Open your site at
https://in a private window. Click the padlock, check the expiry date and that the certificate names your address. If you get a warning instead, fix this before anything else. - Make every version land on
https://.http://, with and withoutwww, should all redirect there. It is one setting at most hosts. - Make certificate renewal automatic, and ask your host to confirm it in writing. With 200-day certificates today and 47-day certificates by 2029, nobody should be doing this by hand.
- Ask your host which server and PHP version your site runs. Anything past its security support date gets upgraded. PHP 8.2's ends December 31. While you are asking, have the version header turned off; nobody needs it announced.
- Keep WordPress, the theme and every plugin updated, as the four sites in our sample do.
- Add the three headers above, and fix anything loaded over
http://from anhttps://page. - Set up Google Search Console, so that if Google ever flags your site as hacked, you hear about it from Google rather than from a client.
What we would build
A brokerage site with HTTPS, automatic certificate renewal and the security headers in place from the first day, on a stack nobody has to patch by hand, that also loads fast on a phone and shows its license number. A launch site starts at $900 and is live in 48 hours, and a full brokerage site starts at $4,500 and is live in about a week, with Flare Care keeping it current for the months after.
If you want this check run on your site, tell us about your brokerage, or build your package in about two minutes.
How we checked
The sites are every live website from our two earlier Sacramento-area audits: brokerage corporations licensed in Sacramento County since 2024 (residential) and Sacramento-region corporations with Commercial or CRE in their licensed name (commercial), the same 43 as our speed, email and site name checks.
On October 8, 2026 we did three things for each, and nothing else: opened one secure connection to read the certificate, requested the plain-HTTP homepage to see whether it redirects, and read the HTTPS homepage's own response headers and code. No other pages were requested, nothing was logged into, and no software was probed. Three homepages answered automated requests with a bot challenge, so their headers are left out of the header counts, which is why those use 38 rather than 41.
What it cannot see: everything behind the homepage, including plugins, admin logins and the server itself. A site can pass every check here and still be compromised, and miss several of them and be fine. These are the parts any visitor's browser, and any stranger, can read.
