Hospitality Locked the Door and Left the Side Gate Open

96.2% of hospitality sites serve a secure page. Only 73.5% send insecure visitors to it, last of all 47 industries I ranked.

Hospitality Locked the Door and Left the Side Gate Open

A message landed on Sunday night from a man who runs a twelve room inn up the coast. I’ll quote it, because he put it better than I would have.

“Got three quotes back. The cheapest is under half what the other two want and he says he can have it live next week. Any reason I shouldn’t just go with him?”

I wrote back longer than he wanted. Most of that reply is below, and it’s meant for you too if there’s a quote sitting unanswered in your inbox this morning.

Before I answer the question, I want to show you one number. I went through all 47 industries on it last month, best result at the top, and restaurants and hotels came out at the very bottom.

The same trade comes first on how carefully it describes the photographs on its pages, which is what makes the bottom of this one sting.

One check, and a decent host clears it in about an hour. Is it written anywhere on the quote in front of you?

What your guest sees at the door

Two separate things happen when a customer arrives, and I watch people muddle them together all the time.

The first is the padlock. She types your name, your page opens, and a small lock appears beside your address, which means whatever she types next travels scrambled instead of readable.

Her card number. Her phone number. The note about the anniversary cake and the food her husband can’t eat.

Your host switches that on with a certificate, and most of them hand it out free now without anybody asking.

The second thing is the forwarding, and your guest never sees it working properly. Your site still answers on the old unlocked address, and a person has to tell the server to bounce every one of those arrivals over to the locked version instead.

Nobody gets round to the second one, because nothing looks broken when you skip it. When did anyone last check yours?

Where this trade lands

The padlock is fine here. Better than fine, honestly.

Plenty of trades can’t say that. Wedding photographers hold the best ratings I count and one of the weakest padlocks, which is a strange pair of facts to own.

96.2% of hospitality sites serve their pages securely, against 94% across everything I audited.

Then I checked the forwarding. 73.5% send insecure visitors over to the secure version, where the national number is 88%.

You bought the lock, hung it on the front door, and left the side gate swinging in the wind.

Who is still using the old address?

Fair question, because almost nobody types a web address by hand anymore, and that isn’t where this bites you.

Your old unlocked address is printed on things, and I doubt you could list them all from memory.

It’s on the QR code stuck to table nine, the one your last web guy generated back in 2019. On the takeout menus in the drawer, the business cards, the sandwich board, the sponsor page of the minor hockey league, a directory listing nobody can log into anymore, and the About box on a Facebook page a former manager set up.

Every one of those links is frozen in place. They will still be pointing at the unlocked address long after you’ve forgotten who made them.

When a guest lands there and no forwarding is waiting for her, Chrome has been putting “Not secure” beside your name since 2018, and on some visits she gets a full warning screen before she ever reaches your menu.

A pool company I audited had the identical gap, and the only people meeting that warning screen were its regulars, because they were the ones with the old address saved.

Picture that moment properly. She is holding a menu, she scanned the code on the table, and she was about to send you a booking with her phone number attached to it.

Would you keep typing?

The cost you will never see

Search engines walk into the same open gate.

Two working copies of your site can end up on the record, one locked and one not. Links from the tourism board, the write-up in the local paper and the food blogger who loved your patio all land on whichever copy that particular person happened to paste.

Google’s own documentation on duplicate addresses describes how it consolidates the signals from those copies into a single preferred one. It tries, anyway. A search engine is guessing at which of your copies you meant, and it guesses from whatever the outside world happened to paste.

Your guest sees none of this. She searches your name, and whichever copy won the argument is what gets handed to her.

87.4% of hospitality sites do carry a canonical tag, which sits above the 84.9% I see nationally.

It helps, and I’d rather you had one than not. But a canonical tag is a note politely asking a search engine to use this version, while forwarding is a locked gate, and a note is not a gate.

Which of those would you want on the real back door of your kitchen?

Why the cheap quote leaves it out

Back to your three quotes, then.

Nothing in the cheap one is a lie. He can build you a good-looking site in a week, and the certificate will be on, because his host does that by default and he would have to work to prevent it.

The forwarding is a different sort of job. It is one line in a config file, or a checkbox on a hosting panel, and it lives with the security housekeeping nobody itemizes on a quote.

Your own phone will never show you it’s missing, either. It already remembers the secure version of your site, because you’ve been there a thousand times, so the whole thing looks perfect to you and it always will. Who in your building would ever catch it, then?

Most of your guests never touch that gate. Google sends people to the secure version, and so does any link you’ve posted this year, which makes it a slow leak rather than a fire in a trade that lives on first impressions.

Some hosts also force the secure version out at their own edge, in a way my robot reads differently from a redirect set on the server, so a few of the sites I marked down may be handling this further upstream than I can see from outside.

And the forwarding isn’t one of the ten checks that build my score, so the leak costs this trade nothing whatsoever in the grade I gave it.

It only costs you the guest who used the old address and got a warning instead of a menu. Does that feel like a fair trade to you?

It doesn’t to me. Restaurants and hotels are the bulk of what I build, and I’ve never once quoted one without this on the list, because it takes an hour and it embarrasses everybody when it’s missing.

Twenty seconds, before you sign anything

Open a private window on your phone, so it can’t cheat by leaning on your own saved history.

Type your address without the https on the front, hit go, and watch what the bar at the top says. Then try it again with a www in front, because plenty of sites forward one version of the name and not the other.

Padlock both times, and you’re already in good shape. Go and make yourself a coffee.

A warning either time, and you have a question to put to all three of the people who quoted you. Does the price include forcing every visitor onto the secure address, and will you show me it working from a phone that has never visited my site before?

If your cheap builder says yes without hesitating, hire him. I’ve just saved you money and I’m pleased about it.

If he goes quiet on you, send me the address and I’ll open it myself. That is what I keep the free audit for, and ten minutes is usually enough to tell you which of those two people you are dealing with.