Skip to main content

Defense Built In

Hosting with a bodyguard built in, day and night

Every plan ships with a managed WAF, Imunify360 malware scanning, DDoS mitigation, free SSL, daily backups and 24/7 monitoring already switched on — no add-ons, no upgrades needed.

Free

SSL certificates, every domain

Daily

Backups running automatically

24/7

Security monitoring, always on

Layer 7

Firewall and DDoS filtering

Defense In Layers

Six layers standing between attackers and your site

The kind of protection you'd normally shop around for and pay extra on — here it's baked into your plan from day one.

Multiple layers of firewall and malware defense wrapped around a website

Application firewall (WAF)

Every request is checked against a constantly updated attack-pattern library before it can reach your code, catching SQL injection, cross-site scripting and other known exploits on the way in.

Malware scanning with Imunify360

Files are checked around the clock, and anything infected is quarantined the moment it's found. Outdated plugins get virtual patches that shield them from exploits until you're ready to update.

DDoS mitigation

Traffic is inspected at the network edge, where large-scale floods and malicious packets get filtered out long before they reach your server — real visitors never notice a thing.

Free, auto-renewing SSL

Every domain on your account gets an SSL certificate issued and kept current automatically, so connections stay encrypted and the padlock never disappears.

Daily backups

A fresh copy of your files and databases is stored off-server every day, giving you a known-good point to restore to in minutes if something goes wrong.

24/7 monitoring

People and automated systems keep watch over server health, uptime and intrusion attempts every hour of every day, all year long.

Shield icon representing DDoS protection and site security

Firewall

A firewall that turns attacks away at the door

Every request gets read by the firewall before it ever touches your code. Bad payloads and probing bots are stopped at the edge, while real visitors move through without a hitch — no plugins to install and no rules for you to write.

  • Stops injection and XSS attempts cold
  • Screens out known bad bots and exploits
  • Throttles abusive traffic automatically
  • Tuned and managed on your behalf
Cloud icon representing daily automated website backups

Malware Scanning

Imunify360 catches trouble before it spreads

Imunify360 keeps an eye on your files around the clock. As soon as it finds malicious code, it isolates the file and flags it for you, containing the problem before it can quietly spread — while virtual patching covers outdated software until you're ready to update it.

  • Scans running nonstop and on every upload
  • Bad files quarantined without you lifting a finger
  • Virtual patches covering outdated plugins
  • Straightforward alerts right in your dashboard

Layers In Action

How each layer backs up the next

No single safeguard catches everything on its own. Here's the handoff between layers, so an attacker has to get past every one of them, not just one.

Security team reviewing a threat-detection dashboard for server activity
1

DDoS filtering meets traffic first

Large-scale floods and obvious junk traffic get absorbed and dropped at the network edge, before they ever reach your server, so your uptime stays intact.

2

The firewall checks what remains

Whatever traffic gets through passes into the managed WAF, which blocks injection attempts, cross-site scripting and other exploits aimed at your application.

3

Isolation keeps the damage contained

Your site sits in its own walled-off environment, so trouble on another account on the server has no path to reach yours.

4

Imunify360 checks every file that lands

Anything saved to disk gets scanned continuously — infected files are quarantined automatically, and outdated software gets a virtual patch.

5

SSL locks down every connection

Every exchange between your visitors and your site is encrypted end to end, so data in transit can't be read or altered along the way.

6

Daily backups catch anything that slips by

If something still gets through, off-server daily backups let you roll your entire site back to a known-good point within minutes.

Plans

Plans, all secured the same way

The full security stack ships with every tier — choose the size your site needs today and scale up later.

Launch

The simple starting point for putting a single site online

$2.09/mo

renews at the same price · billed annually

SSD storage
10 GB
Websites
1
Bandwidth
500 GB
CPU / RAM
1 core / 2 GB
Databases
25 MySQL
  • Your first year of domain registration on us
  • SSL that renews itself automatically, at no cost
  • We'll move your existing site over for free
  • Build with our free AI-powered site builder
  • WordPress Toolkit with automatic daily backups
  • Command-line access via SSH, Git and Composer
Protect My Site
Most Popular

Pro

Room for every site you want to run

$2.79/mo

renews at the same price · billed annually

SSD storage
20 GB
Websites
25
Bandwidth
1 TB
CPU / RAM
1 core / 2 GB
Databases
50 MySQL
  • Your first year of domain registration on us
  • SSL that renews itself automatically, at no cost
  • We'll move your existing site over for free
  • Build with our free AI-powered site builder
  • WordPress Toolkit with automatic daily backups
  • Command-line access via SSH, Git and Composer
Protect My Site

Elite

Serious performance backed by 200 GB of NVMe storage

$5.59/mo

renews at the same price · billed annually

SSD storage
200 GB
Websites
100
Bandwidth
2 TB
CPU / RAM
2 cores / 4 GB
Databases
100 MySQL
  • Your first year of domain registration on us
  • WordPress Toolkit Deluxe included
  • Backups every 6 hours, plus Imunify360 protection
  • PHP X-Ray and CloudLinux Pro for faster debugging
  • Runtime support for Python, Node.js and Ruby
  • 24/7 priority support when you need it
Protect My Site

Extra Safeguards

A few more ways we've got your back

Security engineer locking down a server against brute-force login attempts

Brute-force lockouts

Repeated failed logins trigger throttling and IP blocking, so bots trying to guess your way into admin or mail accounts get shut out fast.

Patched before exploited

The moment a new vulnerability is disclosed, a virtual patch closes it off at the firewall — often before the software vendor even ships an official fix.

Account isolation

Your hosting account is walled off from every other account on the server, so trouble next door has no way of reaching your site.

Dashboard screen tracking 99.9% website uptime

Recovery & Uptime

Daily backups, plus eyes on your site around the clock

Even strong defenses need a fallback plan. Daily automated backups mean you can roll your whole site back in minutes, and continuous monitoring keeps an eye on uptime and intrusion attempts around the clock — with real people standing by to jump in.

  • Daily backups stored off-server
  • Full-site restore in one click
  • Monitoring that never clocks out
  • Free SSL that renews on its own

How It Works

Get secured in three easy steps

Small business owner setting up a secure hosting plan with SSL included
1

Choose a plan

Whichever tier you choose, the WAF, malware scanning, DDoS mitigation and daily backups are already switched on — nothing extra to add.

2

Bring your site across

Point your domain our way, or hand migration to our team at no charge — SSL is set up automatically the moment you go live.

3

Let it run itself

Check clean scan results and uptime from your dashboard whenever you like, while monitoring and backups keep working quietly in the background.

Included

Everything below comes with every plan

  • Managed WAF protection
  • Malware scanning via Imunify360
  • Auto-quarantine of infected files
  • Network-level DDoS mitigation
  • Free SSL, renewed automatically
  • Off-server backups, every day
  • One-click restores
  • Brute-force login defense
  • Isolated hosting accounts
  • Round-the-clock monitoring and support

FAQ

Questions about our secure hosting

What kinds of attacks does the firewall stop?

Before a single request reaches your site's code, the managed firewall checks it against a library of known attack signatures that we keep current. That catches SQL injection attempts aimed at your database, cross-site scripting payloads built to hijack visitor sessions, remote file inclusion, directory traversal and command injection. It also weeds out abusive bots, credential-stuffing scripts and traffic scanning for well-known plugin or theme weaknesses. You don't write a single rule yourself — our team tunes and updates the firewall as new threats surface. Genuine visitors sail through without any delay or friction, while harmful requests get dropped right at the edge, so your server never has to process them. In short, a large share of common attacks never gets anywhere near your application, your database or your files.

How does the malware scanning actually catch infections?

Imunify360 comes standard on every secure plan, running in the background around the clock and again the instant a file is uploaded or edited. When it spots something malicious — a planted backdoor, a defaced page, a phishing kit or a script sending spam — it quarantines that file straight away, so the problem stays contained instead of spreading through your account. Your dashboard shows exactly what was found and where, and you can inspect or restore items yourself if needed. On top of detection, virtual patching covers outdated plugins and themes against known exploits until you get around to updating them, closing the gap attackers usually go after. Because the scanning never stops — rather than running once a day — most issues are caught and shut down within minutes, keeping your site clean and your visitors out of harm's way.

Is the free SSL certificate actually free, no catch?

Yes — no trial period, no first-year-only deal, no upsell attached. Every domain and subdomain on a secure plan gets an SSL certificate the moment it goes live, and that certificate renews itself automatically before it can expire, for as long as you stay hosted with us. Your visitors' padlock icon never disappears, and you'll never get a bill or reminder for renewing it. What SSL actually does is encrypt the link between your visitors and your server, so login credentials, contact-form submissions, checkout details and anything else typed into your site stay private in transit. It also counts toward search rankings and keeps browsers from slapping a 'Not secure' warning on your pages. There's no setup on your end — the certificate is issued and kept current for you, so your site is encrypted from the very first day it's live.

How often do backups run, and can I restore one myself?

Backups run automatically every single day and are kept off-server, well away from the machine they're protecting. Each one wraps up both your files and your databases together, so what you restore is a whole, working copy of your site rather than scattered pieces you have to reassemble. Restoring is entirely in your hands: open your dashboard, pick a recovery point, and roll back your whole account, one site, or just a single database — a handful of clicks and it's usually done within minutes. That makes your daily backup the fix for nearly anything that goes sideways: a broken update, a bad edit, something deleted by accident, or worse. You never have to remember to trigger one yourself, and since copies live off-server, they're still there for you even if the live environment runs into trouble.

Does DDoS protection add any lag to my site?

No. Mitigation happens out at the network edge, well before traffic ever reaches your server, and it works by reading the volume and pattern of incoming traffic rather than examining each page request. Real visitors get waved straight through with zero added delay, while a barrage of malicious packets aimed at overwhelming your site gets absorbed and stripped out before it ever touches your hosting. Because that filtering capacity spans our entire network rather than a single machine, it can soak up attacks far bigger than any one server could handle on its own. The upshot is that your site keeps running smoothly during an attack that would take an unprotected site completely offline. You don't need to enable or configure anything — it's active by default on every plan, quietly protecting your uptime whether or not anyone's currently targeting you.

What exactly does round-the-clock monitoring watch for?

Monitoring blends automated systems with real people keeping an eye on the platform every hour of every day. On the automated side, we're tracking server health, uptime, resource usage, disk and network activity, and known signs of intrusion, with an alert firing the second anything looks off. Our team then reviews those alerts and digs into anything suspicious right away, instead of waiting for you to notice a problem and file a ticket. That covers hardware failures, odd traffic spikes, repeated failed logins and other signs something's wrong, so issues are frequently handled before your visitors ever notice. Combined with the firewall, malware scanning and daily backups, this is the layer standing watch while you're asleep or busy with other things. And if you do spot something first, the same round-the-clock support team is just a message away to help you dig in.

Put a security team behind your site.

Managed WAF, malware scanning, DDoS protection, free SSL, daily backups and 24/7 monitoring — already included.

View Secure Plans