Sampling
A rotating sample of residential property websites operating across the South East of England, together with the major UK national portals for national context. Individual sites are never listed on this page.
When you browse a listing or send an enquiry about a home, the details you share travel through whatever technical security setup that particular website happens to have — and, as it turns out, no two sites in the UK property industry are set up quite the same way. We took a quiet look across the sector to see how consistently the basics are being looked after. Here's what we found — shared openly, without pointing at anyone in particular.
Publicly observable data · refreshed periodically · current view: July 2026
The numbers on this page are computed from a rotating sample of publicly-available residential property websites across the South East of England, together with the major national property portals for context. The sample is scanned periodically using free, independent industry-standard tools (Mozilla Observatory and Qualys SSL Labs) and our own origin-side configuration checks.
No individual website is named on this page. The chart below shows only the aggregate percentage of the sample where a given security concern is absent or incomplete — it does not, and cannot, identify any specific business.
Ordered by prevalence — the concerns most commonly missing across the sampled sites are at the top. Click any row to see a plain-English explanation and what it means for someone using the site.
The methodology is transparent by design — everything on this page can be reproduced by anyone with a browser.
A rotating sample of residential property websites operating across the South East of England, together with the major UK national portals for national context. Individual sites are never listed on this page.
Each site is checked against Mozilla Observatory and Qualys SSL Labs — the two most widely-used free public tests of website security.
Mozilla Observatory →In addition, we verify HTTPS enforcement, redirect handling, header hygiene, and cookie configuration — the same checks any browser can observe against any public URL.
The sample is scanned periodically and the chart above updates within minutes of each scan completing. No site is ever probed beyond what a normal visit would do.
You do not have to take our word for it. The two tools below are free, run in any browser, and can be pointed at any public URL — including our own.
Even in aggregate form, it's important to be clear about what these numbers do and don't mean.
The chart is an industry-wide picture. It is not a judgement on the quality, professionalism, reputation, service or reliability of any specific agency — those are separate concerns and are not measured here.
This is a snapshot of publicly-observable configuration, not a professional security audit. Real audits are commissioned privately, follow a formal scope, and produce findings only for the organisation involved.
These numbers move. Every scan reflects only what was publicly observable on that day. Sites, providers and configurations change — and the chart moves with them.
Many low-scoring configurations come from third-party website providers whose product the agency using them does not directly control. The industry-wide gaps shown above are shared across many operators for many reasons.
Notice. The data on this page is calculated from publicly-observable configuration of property websites, measured with free public tools available to anyone. FYSH does not access private systems, internal data, or non-public information about any organisation. The page is intended for general information about the state of the industry. It is not a security audit of any specific business, does not constitute professional advice, and should not be relied on in isolation for any commercial or reputational decision.
Read about how we look after listing details, messages and enquiries — and why security is a first-class concern for us.