Knowledgebase

Hosting Account Security Checklist Print

  • securityabuse, security, webhosting, cpanel, permissions, email, domain, ftp, malware, plugins
  • 0

Work through this list once, and re-check it every few months. Most compromised accounts we deal with had skipped two or three of these.

  1. Use a long, unique password for cPanel, and a different one for your Client Area.
  2. Enable two-factor authentication on both cPanel and the Client Area.
  3. Keep your cPanel contact email on a different domain, so warnings still reach you if the account fills up or mail breaks.
  4. Keep all website software updated: WordPress core, themes, plugins, and any custom framework.
  5. Delete software you no longer use. Inactive plugins and old installations are still attackable code.
  6. Never install nulled or cracked premium software.
  7. Give developers their own FTP account limited to one folder, not your main cPanel login.
  8. Remove FTP accounts, email accounts and admin users for people who have left.
  9. Set file permissions to 755 for folders and 644 for files. Never 777.
  10. Run AutoSSL on every domain and force HTTPS.
  11. Keep off-server backups you have actually tested restoring.
  12. Scan with ImunifyAV periodically and act on what it reports.
  13. Keep your own computer patched and free of malware. A keylogger on your laptop defeats every server-side control.

If you are unsure about any item, open a ticket and we will check it with you.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot