Industry Security6 min read1 October 2026

Website Security for UK Plumbers and Tradespeople

UK plumbers and tradespeople collect customer contact details, take online payments and use booking systems. Here is what you need to know about protecting your trade website from hackers.

By Yrzo AI — UK cybersecurity specialists

Do Plumbers and Tradespeople Need to Worry About Website Security?

If you are a plumber, electrician, gas engineer, roofer, or any other UK tradesperson with a website, the honest answer is yes — and probably more than you think.

Most trade websites are not hacked because an attacker wants your specific data. They are hacked because automated tools scan millions of websites every day looking for outdated WordPress installations, weak passwords, and unpatched plugins. When they find one, they exploit it — not for what your site does, but for what they can make it do: send spam, host phishing pages, mine cryptocurrency using your server, or redirect your visitors to malicious sites.

For a sole trader or small trade business, a hacked website can mean: your site going offline, Google blacklisting your domain (wiping your local SEO rankings), your hosting account suspended, and your customers' contact details exposed. The cost to recover can run into hundreds of pounds and days of lost work.

What Data Trade Businesses Actually Collect

Even a simple trade website collects more data than most tradespeople realise:

**Contact form submissions** — name, phone number, email address, and home address (for a quote or job). That is personal data under UK GDPR.

**Online booking systems** — if you use a booking plugin (Calendly, Booksy, a WordPress booking plugin), customer names, contact details, and sometimes payment details pass through your website.

**Payment data** — trade businesses taking deposits or full payment online are handling financial data. How securely depends entirely on how the payment is set up.

**Quote request details** — job descriptions often include home addresses, access arrangements, and details about the property. For residential work, that data belongs to identifiable individuals.

**Email marketing lists** — if you collect emails for seasonal promotions or service reminders, that list is personal data requiring consent and secure storage.

Under UK GDPR, even a sole trader collecting customer names and addresses through a contact form is a data controller with legal obligations — including reporting a breach to the ICO within 72 hours if it poses a risk to customers.

How Trade Websites Get Hacked

**Outdated WordPress** — most trade websites are built on WordPress. WordPress itself updates frequently, but plugins — contact form plugins, gallery plugins, SEO plugins, booking systems — often go months or years without updates on small business sites. Attackers scan for specific plugin versions with known vulnerabilities and exploit them automatically.

**Weak admin passwords** — "password123", the company name, or a birth year are guessed within seconds by automated tools. A WordPress admin account with a weak password is a complete site compromise.

**No HTTPS** — a site still running on HTTP (not HTTPS) transmits contact form data in plaintext. Anyone on the same network can read it. Google also penalises non-HTTPS sites in search rankings, which directly affects a tradesperson's local SEO visibility.

**Shared hosting vulnerabilities** — budget shared hosting puts hundreds of sites on the same server. If another site on your server is compromised, attackers sometimes pivot to other accounts on the same server.

**Abandoned websites** — a surprising number of trade businesses have two sites: the current one and an old one from three years ago that is still live, completely unpatched, and forgotten. Attackers find these and use them as entry points.

Practical Security Steps for UK Tradespeople

**Keep WordPress and all plugins updated** — log into your WordPress dashboard once a week and apply any pending updates. Remove plugins you are not actively using. Every unused plugin is a potential vulnerability.

**Use a strong, unique password for your WordPress admin account** — use a password manager (Bitwarden is free) to generate and store a long random password. Change the admin username from "admin" to something unique.

**Make sure your site uses HTTPS** — your hosting provider almost certainly includes a free SSL certificate (Let's Encrypt). If your site still shows "Not Secure" in the browser address bar, contact your hosting provider and ask them to enable HTTPS. It is usually a one-click fix.

**Install a basic security plugin** — Wordfence (free version) adds login protection, malware scanning, and firewall rules to a WordPress site with minimal configuration required.

**Set up weekly backups** — your hosting provider may offer automated backups. If not, a plugin like UpdraftPlus backs up your site weekly and stores the backup in Google Drive or Dropbox. If your site is compromised, a clean backup means a fast recovery.

**Use a reputable payment gateway** — if you take deposits online, use Stripe or PayPal. They handle card data on their secure servers. Never have card numbers typed into a contact form.

**Delete your old site** — if you have a previous version of your website sitting live somewhere, take it down or ask your web designer to delete it. An unpatched old site is a back door to your current hosting account.

What GDPR Means for a Sole Trader

Many sole traders believe GDPR only applies to big companies. It does not. If you collect customer names and contact details through a website form — and every trade website does — you are a data controller under the UK GDPR.

In practice, for a small trade business, compliance means: - Having a privacy policy on your website explaining what data you collect and why - Not keeping customer data longer than necessary - Having basic security measures in place (HTTPS, no data sent unencrypted) - Being able to delete a customer's data if they ask you to

The ICO does not routinely investigate sole traders, but if a customer complained about a data breach, you would need to demonstrate you had taken reasonable steps to protect their information.

Running a Security Scan on Your Trade Website

Yrzo AI performs 44 automated security checks on your website and delivers a plain-English report in under 20 minutes. It covers SSL configuration, security headers, cookie security, admin panel exposure, email authentication, and more.

For a trade business website, a scan costs £99. It tells you exactly what needs fixing and why — written for business owners, not IT professionals.

Run your scan at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →