In this guide: Is your web hosting secure? 12 security features to check — server-level protections, account isolation, backups and recovery, and questions to ask your host.
Website security doesn’t start with a WordPress plugin. It starts with your hosting. If the server is outdated, poorly isolated, or unmonitored, even a perfectly maintained website is at risk.
This week on Hostreta, we’re focusing on security and reliability. Let’s begin with the 12 hosting security features you should check.
Your host controls the layers beneath your website:
A secure host blocks many attacks before they reach your site and helps you recover quickly when something goes wrong.
1. Web Application Firewall (WAF)
Filters malicious requests (SQL injection, cross-site scripting, known exploit attempts) at the server level. See Web Application Firewalls Explained.
2. DDoS protection
Network-level mitigation to absorb traffic floods. Many hosts partner with CDNs for this. See DDoS Attacks Explained.
3. Malware scanning
Automatic scanning of your files for known malware, ideally with alerts and cleanup options.
4. Up-to-date software stack
Current, supported versions of PHP, MySQL/MariaDB, and the operating system, with security patches applied promptly. The host should let you choose supported PHP versions and warn about outdated ones.
5. Brute-force protection
Rate limiting or blocking repeated failed logins to control panels, SSH, FTP, and common CMS login pages.
6. Free SSL and secure protocols
Free SSL certificates with auto-renewal, TLS 1.2/1.3, and support for SFTP/SSH instead of plain FTP.
7. Isolated accounts on shared servers
Technologies like CloudLinux (with CageFS), containers, or separate system users keep your account’s files and processes separated from other customers. Without isolation, one compromised site could affect neighbors. See What Is Server Isolation?.
8. Resource limits
Per-account CPU and memory limits prevent one site from bringing down the whole server.
9. Secure control panel access
Two-factor authentication for your hosting account and control panel, activity logs, and the ability to create limited-access users for developers.
10. Automatic backups
Daily backups (at minimum), stored off the server, with a retention period of at least a week or two — ideally longer.
11. Easy restore
One-click restore of files, databases, or the whole account, preferably free of charge. Ask how long restores take.
12. Monitoring and incident response
24/7 infrastructure monitoring, a public status page, and a clear process for handling hacked accounts — including whether malware cleanup is included or paid.
Remember the 3-2-1 backup rule: keep your own off-site backup too.
Use these before buying — or ask your current host today:
Clear, confident answers are a good sign. Vague answers are a red flag.
Even the best host can’t protect you from:
We’ll cover all of these this week, starting with the WordPress Security Checklist.
Further reading: WordPress Advanced Administration Handbook
We may earn a commission on purchases made through these links, at no extra cost to you.
Don’t miss the chance to participate in the biggest giveaway of this year.