Skip to main content

Security As Standard

Defences already up before you have signed in

Every plan arrives with a managed WAF, Imunify360 malware scanning, DDoS filtering, free SSL, a daily copy and round-the-clock monitoring already live. Nothing to bolt on, nothing further to buy.

Free

SSL on every name in the account

Daily

Automatic backup runs

24/7

The platform watched, without pause

Layer 7

DDoS and firewall cover

Layered Defence

Six layers standing between a threat and your site

Protection most hosts sell as paid extras. Here the whole stack is inside the plan price from the start.

Firewall and malware protections stacked around a single website

A managed web firewall (WAF)

Not one line of your code runs until the request has been matched against a signature catalogue we keep current. That is the point at which SQL injection, cross-site scripting and the rest of the usual repertoire get turned away.

Imunify360 malware detection

Everything on disk stays watched, and an infected file gets boxed off the second it appears. Where a plugin has fallen behind, a virtual patch covers it until the genuine update turns up.

DDoS absorbed at the edge

At the network perimeter, well upstream of your server, flood traffic and hostile packets get spotted and dropped. Genuine visitors come through without noticing a thing.

Self-renewing free SSL

Each name on the account picks up a certificate that keeps itself current, which holds traffic encrypted and leaves the padlock lit for good.

A copy taken daily

Once a day the files and the databases come off the machine altogether, which leaves a clean point you can wind back to within minutes.

Watched every hour of the year

Server health, uptime and intrusion attempts are tracked without pause by automation and by real engineers, nights, weekends and holidays included.

The filtering that absorbs an attack well before it reaches the site

The WAF

Hostile requests halted right at the door

No request reaches your application until it has been read. Out at the perimeter, malicious payloads and probing bots are turned away while genuine visitors pass at full speed. There is no plugin to add and no rule set for you to maintain.

  • SQL injection and XSS blocked outright
  • Recognised bots and exploits filtered
  • Abusive traffic slowed automatically
  • Rules tuned and updated for you
Last night's copy of the site, filed away without anyone asking for it

Malware Scanning

Imunify360 stops an infection spreading

Imunify360 never stops reading your files. The instant malicious code appears it is isolated and reported, which boxes the trouble in before it can creep outward, and virtual patching shields outdated software until you get round to updating on a schedule of your own.

  • Continuous scanning, and again on upload
  • Quarantine happens without your input
  • Outdated plugins get virtual patches
  • Clear alerts posted to your dashboard

The Handoff

How each of the six layers backs up the one before

No single control stops everything. Each layer covers the gaps in the last, so getting through means beating all six in a row.

Engineers going through live threat detections shown on a server dashboard
  1. 1

    Traffic meets the DDoS filter first

    Out at the perimeter, volumetric floods and obvious rubbish get soaked up and thrown away, so the machine is never dragged into it and the uptime figure holds.

  2. 2

    The WAF screens what remains

    Whatever slips past the perimeter next meets the managed firewall, and that is what turns back injection payloads, cross-site scripting and the remainder of the application-level catalogue.

  3. 3

    Isolation contains whatever lands

    A sealed environment of its own is where your site runs, which leaves an incident on a neighbouring account on that same machine no route across.

  4. 4

    Imunify360 checks each file on arrival

    Whatever gets written to disk is read straight away. An infection goes into quarantine on sight, while software trailing behind on updates picks up a virtual patch.

  5. 5

    SSL encrypts the whole exchange

    Each exchange between a visitor and the site travels encrypted from end to end, which leaves nothing in transit that can be read or altered on the way.

  6. 6

    The copy stands as the final net

    If something does break through regardless, the daily off-server copies restore the entire site to a clean point inside minutes.

Plans

The same security stack on every plan

All three sizes carry identical protection. Start where the site is today and step up as it grows.

Sprint

One site, live within minutes, sitting on the lowest tier we run

$2.42/mo

$29.04 today · billed annually

the price never jumps at renewal

SSD storage
10 GB
Websites
1
Bandwidth
500 GB
CPU / RAM
1 core / 2 GB
Databases
25 MySQL
  • Year one of your domain name is charged at nothing
  • SSL at no charge, reissued before it ever expires
  • We take the site off your previous host and land it here, no charge
  • Describe the site to the AI builder in the panel, then publish
  • WordPress Toolkit comes with it, plus a fresh backup every day
  • Real SSH access, and Git and Composer are preinstalled
  • Softaculous installs 240+ apps in one click
  • ImunifyAV+ sweeps every site for malware
  • NVMe SSD storage behind a LiteSpeed cache
  • Mailboxes on your own domain, included
  • MailChannels gets your outbound mail delivered
  • cPanel at its current release, staffed support 24/7
  • Your account goes live minutes after checkout
Secure My Site

The order gets finalised over at Hosting Cheap, the shared billing system that sits behind all of our brands.

Most popular

Turbo

Twenty-five sites on a single account, none of them throttled

$4.66/mo

$55.92 today · billed annually

the price never jumps at renewal

SSD storage
20 GB
Websites
25
Bandwidth
1 TB
CPU / RAM
1 core / 2 GB
Databases
50 MySQL
  • Nothing to pay for the domain name in its first year
  • A free certificate that reissues itself well before expiry
  • Your site comes off the old host and settles onto ours, at no cost
  • Tell the AI builder in the panel what you want, then hit publish
  • WordPress Toolkit is bundled, with a daily backup alongside it
  • Genuine SSH, plus Git and Composer set up in advance
  • Softaculous installs 240+ apps in one click
  • ImunifyAV+ sweeps every site for malware
  • NVMe SSD storage behind a LiteSpeed cache
  • Mailboxes on your own domain, included
  • MailChannels gets your outbound mail delivered
  • cPanel on its newest build, with people answering 24/7
  • Your account goes live minutes after checkout
Secure My Site

The order gets finalised over at Hosting Cheap, the shared billing system that sits behind all of our brands.

Nitro

200 GB of NVMe, and enough processing power to use every bit

$7.08/mo

$84.96 today · billed annually

the price never jumps at renewal

SSD storage
200 GB
Websites
100
Bandwidth
2 TB
CPU / RAM
2 cores / 4 GB
Databases
100 MySQL
  • The domain name's first year carries no charge at all
  • WordPress Toolkit Deluxe comes in without an extra fee
  • Backups run every 6 hours, and Imunify360 stands out in front
  • CloudLinux Pro brings PHP X-Ray, which points at the slow code
  • Push code in Node.js, Python or Ruby, each one already wired up
  • Priority tickets answered whatever the clock says
  • A certificate at no cost, renewing itself ahead of expiry
  • Our engineers move the site over from your old host, and charge nothing
  • An AI builder is thrown in: state what you want, then publish
  • NVMe SSD storage behind a LiteSpeed cache
  • A full command line, with SSH, Git and Composer on board
  • Softaculous installs 240+ apps in one click
  • Your account goes live minutes after checkout
Secure My Site

The order gets finalised over at Hosting Cheap, the shared billing system that sits behind all of our brands.

More Safeguards

Three quieter protections on duty

A server braced against repeated login attacks

Login hammering shut down

Let the failed logins pile up and throttling arrives, followed by an IP ban, which finishes off whatever bot has been grinding at your admin or mail credentials.

Virtual patches land first

The moment a vulnerability goes public, a patch at firewall level shuts it, and often that happens before the vendor ships any official fix.

Hard walls between accounts

Sealed off from every other account on the machine is how yours runs, which leaves a compromise next door no path across to your site.

The dashboards watching the uptime figure the guarantee is written against

Recovery & Uptime

A fresh copy every day, with somebody always keeping watch

Even strong defences deserve a fallback behind them. Automated daily copies bring the whole site back within minutes, uptime and intrusion monitoring runs without pause, and real people stand ready to step in when needed.

  • Off-server copies taken every day
  • A full-site restore in one click
  • Monitoring with no off-hours
  • Free SSL, reissuing on its own

How It Works

Guarded in three quick moves

A business owner switching on a hardened hosting plan with SSL included
  1. 1

    Pick your plan

    The WAF, malware scanning, DDoS filtering and the daily copy are all live the moment a tier arrives. Nothing extra to bolt on.

  2. 2

    Move your site in

    Aim the name our way, or have our team shift you across at no charge. The certificate issues itself as soon as the site answers.

  3. 3

    Then let it run itself

    Look in on the clean scan results and the uptime figure in your dashboard whenever you fancy. Underneath, the monitoring and the copies carry on regardless.

All Standard

Everything listed here arrives with every plan

  • A managed WAF shielding every site
  • Malware scanning through Imunify360
  • Infected files quarantined automatically
  • Network-level DDoS filtering
  • Free SSL that reissues unaided
  • A daily copy held off the server
  • One-click restores
  • Defences against brute-force logins
  • Full isolation between hosting accounts
  • 24/7 monitoring and support

FAQ

Hardened hosting, asked and answered

Which attacks does the firewall actually block?

Every request gets measured against a library of known attack signatures that our team keeps current, and that happens before your site is ever asked to run it. The net catches SQL injection aimed at the database, cross-site scripting written to lift a visitor's session, remote file inclusion, directory traversal and command injection. On that same pass out go abusive bots, credential-stuffing tools, and the probes hunting well-known plugin and theme holes. None of it requires a rule from you. Tuning the firewall and keeping it current as threats shift is work that belongs to us. Legitimate visitors come through with no added friction, while hostile requests are discarded at the edge before your server burns a single cycle on them. What that means in practice is that the great mass of everyday attacks never gets near your application, your database or your files.

How does Imunify360 find and handle malware?

Imunify360 ships with every hardened plan. Scanning runs without pause in the background, and it runs again the second a file is uploaded or altered. When something malicious surfaces, a hidden backdoor, a defaced page, a phishing kit, a script pumping out spam, the file goes straight into quarantine, so the infection stays contained rather than creeping through the account. Your dashboard shows precisely what was caught and where it had been sitting, and inspecting or restoring any of it is yours to do. Detection tells only half the story. Virtual patching shields out-of-date plugins and themes from known exploits until you find the time to update, which closes the very gap attackers aim for most. Because the scanning never stops, rather than running once a night, most incidents are found and shut inside minutes, and that keeps the site clean and its visitors out of trouble.

Does the free SSL certificate come with a catch?

None whatsoever: no trial window, no first-year-only rate, no upsell waiting quietly at renewal. Each name and subdomain on a hardened plan gets its certificate as it goes live, and that certificate reissues itself ahead of expiry for as long as you host here. The padlock people look for never disappears, and no invoice for it ever lands. What the certificate does is scramble the path between browser and server, so logins, form entries, checkout details and anything else typed in stay private on the journey. It counts toward ranking as well, and it stops browsers from stamping a 'Not secure' label across your pages. Your own share of the work comes to nothing at all, since issuing and reissuing both happen on their own, which leaves the site encrypted from its very first day online.

How often are copies taken, and can I restore one myself?

A copy runs on its own every day and is kept off-server, deliberately away from the machine it exists to protect. Files and databases get taken in a single pass, so what comes back is a whole working site rather than parts waiting to be reassembled. Restoring rests entirely with you: open the dashboard, choose a recovery point, and roll back the whole account, one site, or a single database. A few clicks, usually finished inside minutes. That daily copy answers nearly everything that can go wrong, whether an update broke the theme, an edit shipped that should not have, something got deleted by accident, or something nastier happened. You never have to remember to start one, and because the copies live away from the machine, they survive even when the live environment itself runs into trouble.

Will the DDoS filtering slow my site down?

It will not. All of it takes place out at the perimeter, a long way upstream of your machine, and the decision rests on the shape and sheer volume of what is arriving rather than on unpicking every page request. So an ordinary visitor notices nothing added on the way in, while a barrage of packets assembled to swamp the site gets soaked up and stripped out before your hosting ever sees it. Capacity for that work sits with the network as a whole, not with any single machine, which is why it shrugs off attacks many times larger than one server could ever survive. You end up with a site still serving through an assault that would flatten a host without it. Nothing needs switching on, nothing needs configuring. Every plan runs it by default, guarding your uptime whether or not somebody happens to be aiming at you today.

What does the round-the-clock monitoring watch?

Automated tooling runs alongside engineers who watch the platform through every hour of every day. The tooling tracks machine health, uptime, resource use, disk and network behaviour, and the known marks of intrusion, then raises an alert the second any of it drifts from its usual pattern. Engineers read those alerts and chase anything odd at once, instead of waiting for you to notice and open a ticket. What gets covered stretches from hardware faults to unusual traffic surges, from strings of failed logins to other early warnings, which is how a good many issues are settled before a visitor ever runs into them. Set beside the firewall, the malware scanning and the daily copy, this is the layer keeping watch while you sleep or work on something else. And if you happen to spot something ahead of us, that same team is one message away at any hour, ready to work it through with you.

More hosting to explore

  • Web Hosting

    Our main cPanel platform, running the same quick NVMe stack.

  • SSL Certificates

    Free certificates that reissue themselves and encrypt every visit to your site.

  • WordPress Hosting

    WordPress managed on your behalf, with that same firewall and scanning stack inside.

  • Business Hosting

    More capacity for growing sites that refuse to compromise on their security.

Set a permanent guard over your site.

A managed WAF, malware scanning, DDoS filtering, free SSL, a daily copy and monitoring without pause — every bit of it inside the price.

Browse Secure Plans

Sites are attacked by scripts far more often than by people, and scripts lose to patching, filtering and backups, all of which ought to be running before the question even occurs to you. It runs on NVMe arrays with LiteSpeed in front, in data centres with conditioned power and more than one way out to the internet.

A good match for owners who take security as seriously as they take speed. Certificates cost nothing, the migration costs nothing, backups run by themselves, and support answers quickly whatever the hour.

Security running before you ask

DDoS filtering happens at the network edge, so junk traffic never reaches your account. Accounts are walled off from one another, PHP runs per user, and kernel, panel and PHP patches roll across the fleet as releases appear. A free certificate wraps everything moving between visitor and server.

None of that depends on which tier you take. NVMe storage, LiteSpeed over HTTP/2 and the 99.9% uptime SLA are constant from the smallest plan to the largest.

Everything the hardening includes

Comparing Hosting & Domains is easy because nothing is hidden. The listed price already includes the certificate, the migration, the backups and the support, which are the parts other hosts add afterwards. Every hosting plan carries a 30-day money-back guarantee, so trying it risks nothing more than an afternoon.

Security here is not a ladder anybody pays to climb. Filtering, isolation, patching, certificates and nightly backups are on every plan, including the one at $2.42 a month.

The filtering that absorbs an attack well before it reaches the site

The defences between the internet and your site

Sites run in our London datacentre behind edge filtering, on NVMe storage with a backup taken each night. Restores are self-service from the panel, so a bad plugin or a bad day costs minutes rather than a rebuild.

Backups run each night and restores are self-service from the panel: no ticket, no queue, and no waiting for office hours we do not keep anyway.

  • Every account shielded by edge DDoS filtering
  • Per-user PHP inside isolated accounts
  • a 99.9% uptime SLA backed by service credits
  • Daily backups you restore yourself, in one click

Good to Know

More that's built in

Restores without a ticket

A backup only matters when you can use it. Roll one back from the panel, with no support queue in the way.

A panel that stays out of the way

One screen for files, databases, mail, DNS and installers, always on a current release.

Scale up without relocating

Move up whenever the site asks for it; files, settings and address stay exactly where they are.

Free to leave any time

Your data leaves in the same standard formats it came in, and we will help with the move if it comes to that.

Speed set up for you

Every site lands on NVMe with server-side caching already running, leaving no tuning for you.

Certificates in the price

Each domain comes with a self-renewing certificate, so encryption never appears in the upsell column.

Getting Going

Getting going takes three steps

  1. 1

    Select a tier

    Choose any plan — every tier carries identical protection.

  2. 2

    Hook up the domain

    Point the domain here; the certificate installs and renews itself.

  3. 3

    Open for traffic

    Migrate free, then leave the patching, the filtering and the backups to run.

In Every Plan

Thrown in without an extra charge

  • 30 days in which to change your mind on any hosting plan
  • Fleet-wide patching by our engineers
  • Daily backups you restore yourself
  • Upgrade tiers without your files going anywhere
  • Canadian-registered company, pricing in US dollars
  • Shaped around owners who take security as seriously as they take speed
  • Every hosted domain gets SSL free
  • Your migration is carried out by our engineers at no cost

Still Curious

Questions that keep coming up

Suppose my site gets hacked regardless — then what?

Contact the desk and we start work. A nightly backup is ready to restore, the logs show when the change happened, and engineers help trace the plugin or the password that opened the door. Nobody suspends you and vanishes, and the restore adds nothing to the bill.

Do I wait around after ordering?

Within minutes of checkout. Coming from another host adds a day at most and costs nothing: files, databases, mail and DNS are all handled by our engineers.

Do certificates cost anything?

Free, installed, and renewing by itself. You would only buy a certificate for a wildcard or for a validated seal that procurement insists on.

What if secure web hosting turns out not to suit me?

The plan carries a 30-day money-back guarantee. Say so inside the month and the refund is processed, with no exit interview and no hand-off to a retention team paid to argue.

Keep reading

Handpicked from the Resource Library