Skip to main content

Security As Standard

Defences running before you even sign in

Every plan arrives with a managed WAF, Imunify360 malware scanning, DDoS filtering, free SSL, a daily copy and round-the-clock monitoring already live. Nothing to bolt on, nothing further to buy.

Free

SSL for every name you hold

Daily

Automatic backup runs

24/7

The platform watched, without pause

Layer 7

DDoS and firewall cover

Layered Defence

Six defences between a threat and your site

Protection most hosts sell as paid extras. Here the whole stack is inside the plan price from the start.

Stacked firewall and malware protections around a website

A managed web firewall (WAF)

Before a line of your code runs, the request is matched against a signature catalogue we keep current — which is where SQL injection, cross-site scripting and the rest of the usual repertoire are turned away.

Imunify360 malware detection

Nothing on disk goes unwatched, and an infected file is boxed off the instant it shows up. A plugin left behind gets a virtual patch to cover it until the real update arrives.

DDoS absorbed at the edge

Flood traffic and hostile packets are identified and dropped at the network perimeter, well upstream of your server. Genuine visitors pass through none the wiser.

Self-renewing free SSL

Every name on the account receives a certificate that stays current by itself, keeping traffic encrypted and the padlock permanently lit.

A copy taken daily

Each day the files and the databases are lifted off the machine, which leaves a clean point you can wind back to inside minutes.

Watched every hour of the year

Automation and real engineers track server health, uptime and intrusion attempts continuously — nights, weekends and holidays included.

The filtering that absorbs an attack well before it reaches the site

The WAF

Hostile requests stopped at the door

Nothing reaches your application before the request has been read. Malicious payloads and probing bots are turned away at the perimeter while real visitors pass at full speed — no plugin to add, no rules for you to maintain.

  • SQL injection and XSS blocked outright
  • Recognised bots and exploits filtered
  • Abusive traffic slowed automatically
  • Rules tuned and updated for you
Last night's copy of the site, filed away without anyone asking for it

Malware Scanning

Imunify360 stops an infection spreading

Imunify360 never stops reading your files. Malicious code is isolated and reported the instant it appears, boxing the problem in before it can creep outward — while virtual patching shields outdated software until you update on your own schedule.

  • Continuous scanning, and again on upload
  • Quarantine happens without your input
  • Outdated plugins get virtual patches
  • Clear alerts posted to your dashboard

The Handoff

How each of the six layers covers the last

No single control stops everything. Each layer covers the gaps in the last, so getting through means beating all six in a row.

Engineers working through live threat detections on a server dashboard
  1. 1

    Traffic meets the DDoS filter first

    Volumetric floods and obvious rubbish are soaked up and thrown away at the perimeter, so the machine is never drawn in and the uptime figure holds.

  2. 2

    The WAF screens what remains

    Anything that gets past the perimeter runs into the managed firewall, which turns back injection payloads, cross-site scripting and the remainder of the application-level catalogue.

  3. 3

    Isolation contains whatever lands

    Your site runs inside its own sealed environment, so an incident on a neighbouring account on the same machine has no route across.

  4. 4

    Imunify360 checks each file on arrival

    Anything written to disk is read at once: an infection goes into quarantine on sight, and software behind on updates picks up a virtual patch.

  5. 5

    SSL encrypts the whole exchange

    Every conversation between visitor and site travels encrypted the whole way, so nothing in transit can be read or altered en route.

  6. 6

    The copy stands as the final net

    Should something break through anyway, daily off-server copies put the whole site back to a clean point within minutes.

Plans

One security stack across every plan

All three sizes carry identical protection. Start where the site is today and step up as it grows.

Sprint

A single site, online in minutes, on the cheapest tier we run

$2.42/mo

$29.04 today · billed annually

the price never jumps at renewal

SSD storage
10 GB
Websites
1
Bandwidth
500 GB
CPU / RAM
1 core / 2 GB
Databases
25 MySQL
  • The first year of your domain name costs nothing
  • Free SSL that renews itself before it can lapse
  • We lift the site off your old host and set it down here, free
  • An AI builder in the panel: describe the site, then publish it
  • WordPress Toolkit included, and a new backup taken each day
  • Proper SSH, with Git and Composer already installed
  • Softaculous installs 240+ apps in one click
  • ImunifyAV+ sweeps every site for malware
  • NVMe SSD storage behind a LiteSpeed cache
  • Mailboxes on your own domain, included
  • MailChannels gets your outbound mail delivered
  • The latest cPanel, with humans on support 24/7
  • Your account goes live minutes after checkout
Secure My Site

Orders are completed on Hosting Cheap, the billing system every one of our brands runs through.

Most popular

Turbo

Twenty-five sites at full tilt under one account

$4.66/mo

$55.92 today · billed annually

the price never jumps at renewal

SSD storage
20 GB
Websites
25
Bandwidth
1 TB
CPU / RAM
1 core / 2 GB
Databases
50 MySQL
  • The first year of your domain name costs nothing
  • Free SSL that renews itself before it can lapse
  • We lift the site off your old host and set it down here, free
  • An AI builder in the panel: describe the site, then publish it
  • WordPress Toolkit included, and a new backup taken each day
  • Proper SSH, with Git and Composer already installed
  • Softaculous installs 240+ apps in one click
  • ImunifyAV+ sweeps every site for malware
  • NVMe SSD storage behind a LiteSpeed cache
  • Mailboxes on your own domain, included
  • MailChannels gets your outbound mail delivered
  • The latest cPanel, with humans on support 24/7
  • Your account goes live minutes after checkout
Secure My Site

Orders are completed on Hosting Cheap, the billing system every one of our brands runs through.

Nitro

200 GB of NVMe, with the horsepower to work all of it

$7.08/mo

$84.96 today · billed annually

the price never jumps at renewal

SSD storage
200 GB
Websites
100
Bandwidth
2 TB
CPU / RAM
2 cores / 4 GB
Databases
100 MySQL
  • The first year of your domain name costs nothing
  • WordPress Toolkit Deluxe included at no added cost
  • A backup every 6 hours, and Imunify360 standing in front
  • PHP X-Ray on CloudLinux Pro names the slow code for you
  • Ship code in Node.js, Python or Ruby — all pre-wired
  • Priority tickets answered whatever the clock says
  • Free SSL that renews itself before it can lapse
  • We lift the site off your old host and set it down here, free
  • The AI builder is included: say what you want and publish
  • NVMe SSD storage behind a LiteSpeed cache
  • A command line with SSH, Git and Composer on it
  • Softaculous installs 240+ apps in one click
  • Your account goes live minutes after checkout
Secure My Site

Orders are completed on Hosting Cheap, the billing system every one of our brands runs through.

More Safeguards

Three quieter protections on duty

A server being hardened against repeated login attacks

Login hammering shut down

A run of failed logins brings throttling and an IP ban down on it, which ends whatever bot is grinding away at your admin or mail credentials.

Virtual patches land first

When a vulnerability goes public, a firewall-level patch closes it quickly — often before the vendor ships an official fix.

Hard walls between accounts

Your account runs sealed off from every other one on the machine, so a compromise next door has no path to your site.

The dashboards watching the uptime figure the guarantee is written against

Recovery & Uptime

A fresh copy each day, and somebody always watching

Strong defences still deserve a fallback. Automated daily copies can return the whole site within minutes, while uptime and intrusion monitoring runs without pause — and real people stand ready to step in.

  • Off-server copies taken every day
  • A full-site restore in one click
  • Monitoring with no off-hours
  • Free SSL, reissuing on its own

How It Works

Guarded in three quick moves

A business owner activating a hardened hosting plan with SSL included
  1. 1

    Pick your plan

    Every tier arrives with the WAF, malware scanning, DDoS filtering and the daily copy already live. Nothing extra to attach.

  2. 2

    Move your site in

    Point the name at us, or let our team move you at no charge. The certificate issues itself the moment the site is reachable.

  3. 3

    Then let it run itself

    Glance at clean scan results and uptime in your dashboard whenever you like — the monitoring and the copies keep working underneath either way.

All Standard

Every item here comes with every plan

  • A managed WAF shielding every site
  • Malware scanning through Imunify360
  • Infected files quarantined automatically
  • Network-level DDoS filtering
  • Free SSL that reissues unaided
  • A daily copy held off the server
  • One-click restores
  • Defences against brute-force logins
  • Full isolation between hosting accounts
  • 24/7 monitoring and support

FAQ

Hardened hosting, asked and answered

Which attacks does the firewall actually block?

Each request is measured against a library of known attack signatures, kept current by our team, before your site is asked to run it at all. Caught in that net: SQL injection aimed at the database, cross-site scripting written to steal a visitor's session, remote file inclusion, directory traversal and command injection. The same pass removes abusive bots, credential-stuffing tools and the probes hunting well-known plugin and theme holes. You write no rules for any of it. Keeping the firewall tuned and current as threats change is our work. Legitimate visitors pass through without added friction, while hostile requests are discarded at the edge before your server spends a cycle on them. In practice, the great mass of everyday attacks never comes near your application, your database or your files.

How does Imunify360 find and handle malware?

Imunify360 comes with every hardened plan. Scanning runs continuously in the background, and again the second a file is uploaded or altered. When something malicious turns up — a hidden backdoor, a defaced page, a phishing kit, a script pumping out spam — the file goes straight into quarantine, keeping the infection contained rather than letting it creep through the account. The dashboard shows precisely what was caught and where it sat, and inspecting or restoring any of it is yours to do. Detection is only half the story: virtual patching shields out-of-date plugins and themes from known exploits until you find time to update, closing the gap attackers most often aim for. Since the scanning never stops rather than running once nightly, most incidents are found and closed within minutes, which keeps the site clean and its visitors out of trouble.

Is there a catch to the free SSL certificate?

Nothing at all: no trial window, no first-year-only rate, no upsell lying in wait at renewal. Every name and subdomain on a hardened plan receives its certificate as it goes live, and that certificate reissues itself before expiry for as long as you host here. The padlock people check for never disappears, and no invoice for it ever lands. What a certificate does is scramble the path between browser and server, so logins, form entries, checkout details and everything else typed in stays private on the way. It also counts toward ranking, and it keeps browsers from printing a 'Not secure' label over your pages. Your side of the work is nothing: issuing and reissuing both happen automatically, so the site is encrypted from its first day online.

When are copies taken, and can I restore them myself?

A copy runs automatically every day and is held off-server, deliberately distant from the machine it exists to protect. The files and the databases are taken in one go, so what comes back is a whole working site rather than parts to be reassembled. Restoring sits entirely in your hands: open the dashboard, pick a recovery point, and roll back the whole account, one site, or a single database — a few clicks, usually finished inside minutes. That daily copy answers nearly everything that can go wrong: an update that broke the theme, an edit that should not have shipped, an accidental deletion, or something nastier. You never have to remember to start one, and since the copies live away from the machine, they survive even when the live environment itself hits trouble.

Will the DDoS filtering slow my site down?

It will not. The filtering happens at the perimeter, a long way upstream of your machine, and works from the shape and volume of arriving traffic rather than by taking each page request apart. Ordinary visitors pass straight through with nothing added, while a barrage of packets built to overwhelm the site is absorbed and stripped away before it ever reaches your hosting. The filtering capacity belongs to the network as a whole rather than one machine, so it can shrug off attacks many times larger than a single server could survive. The result is a site that keeps serving through an assault that would flatten an unprotected host. Nothing to switch on and nothing to configure: it runs by default on every plan, protecting your uptime whether or not anybody is currently aiming at you.

What does the round-the-clock monitoring watch?

Automated tooling works alongside engineers who watch the platform through every hour of every day. The tooling follows machine health, uptime, resource use, disk and network behaviour and the known marks of intrusion, and raises an alert the moment any of it leaves its usual pattern. Engineers read those alerts and chase anything odd immediately, rather than waiting for you to notice and open a ticket. Coverage spans hardware faults, unusual traffic surges, strings of failed logins and other early warnings, which means many issues are settled before a visitor ever meets them. Together with the firewall, malware scanning and the daily copy, this is the layer standing watch while you are asleep or busy elsewhere. And should you spot something before we do, the same team is one message away at any hour, ready to work it through with you.

More hosting to explore

  • Web Hosting

    The main cPanel platform, on the same quick NVMe stack.

  • SSL Certificates

    Self-reissuing free certificates encrypting every visit to your site.

  • WordPress Hosting

    WordPress managed for you, with this same firewall and scanning stack inside it.

  • Business Hosting

    Extra capacity for growing sites that will not compromise on security.

Put a standing guard on your site.

A managed WAF, malware scanning, DDoS filtering, free SSL, a daily copy and monitoring without pause — every bit of it inside the price.

Browse Secure Plans

Sites are attacked by scripts far more often than by people, and scripts lose to patching, filtering and backups, all of which ought to be running before the question even occurs to you. It runs on NVMe arrays with LiteSpeed in front, in data centres with conditioned power and more than one way out to the internet.

A good match for owners who take security as seriously as they take speed. Certificates cost nothing, the migration costs nothing, backups run by themselves, and support answers quickly whatever the hour.

Security running before you ask

DDoS filtering happens at the network edge, so junk traffic never reaches your account. Accounts are walled off from one another, PHP runs per user, and kernel, panel and PHP patches roll across the fleet as releases appear. A free certificate wraps everything moving between visitor and server.

None of that depends on which tier you take. NVMe storage, LiteSpeed over HTTP/2 and the 99.9% uptime SLA are constant from the smallest plan to the largest.

Everything the hardening includes

Comparing Hosting & Domains is easy because nothing is hidden. The listed price already includes the certificate, the migration, the backups and the support, which are the parts other hosts add afterwards. Every hosting plan carries a 30-day money-back guarantee, so trying it risks nothing more than an afternoon.

Security here is not a ladder anybody pays to climb. Filtering, isolation, patching, certificates and nightly backups are on every plan, including the one at $2.42 a month.

The filtering that absorbs an attack well before it reaches the site

The defences between the internet and your site

Sites run in our London datacentre behind edge filtering, on NVMe storage with a backup taken each night. Restores are self-service from the panel, so a bad plugin or a bad day costs minutes rather than a rebuild.

Backups run each night and restores are self-service from the panel: no ticket, no queue, and no waiting for office hours we do not keep anyway.

  • Every account shielded by edge DDoS filtering
  • Per-user PHP inside isolated accounts
  • a 99.9% uptime SLA backed by service credits
  • Daily backups you restore yourself, in one click

Good to Know

More that's built in

Restores without a ticket

A backup only matters when you can use it. Roll one back from the panel, with no support queue in the way.

A panel that stays out of the way

One screen for files, databases, mail, DNS and installers, always on a current release.

Scale up without relocating

Move up whenever the site asks for it; files, settings and address stay exactly where they are.

Free to leave any time

Your data leaves in the same standard formats it came in, and we will help with the move if it comes to that.

Speed set up for you

Every site lands on NVMe with server-side caching already running, leaving no tuning for you.

Certificates in the price

Each domain comes with a self-renewing certificate, so encryption never appears in the upsell column.

Getting Going

Set up in three quick steps

  1. 1

    Select a tier

    Choose any plan — every tier carries identical protection.

  2. 2

    Hook up the domain

    Point the domain here; the certificate installs and renews itself.

  3. 3

    Open for traffic

    Migrate free, then leave the patching, the filtering and the backups to run.

In Every Plan

Bundled in at no extra cost

  • 30 days in which to change your mind on any hosting plan
  • Fleet-wide patching by our engineers
  • Daily backups you restore yourself
  • Upgrade tiers without your files going anywhere
  • UK-registered company, pricing in US dollars
  • Shaped around owners who take security as seriously as they take speed
  • Every hosted domain gets SSL free
  • Your migration is carried out by our engineers at no cost

Still Curious

Questions that keep coming up

Suppose my site gets hacked regardless — then what?

Contact the desk and we start work. A nightly backup is ready to restore, the logs show when the change happened, and engineers help trace the plugin or the password that opened the door. Nobody suspends you and vanishes, and the restore adds nothing to the bill.

Do I wait around after ordering?

Within minutes of checkout. Coming from another host adds a day at most and costs nothing: files, databases, mail and DNS are all handled by our engineers.

Do certificates cost anything?

Free, installed, and renewing by itself. You would only buy a certificate for a wildcard or for a validated seal that procurement insists on.

What if secure web hosting turns out not to suit me?

The plan carries a 30-day money-back guarantee. Say so inside the month and the refund is processed, with no exit interview and no hand-off to a retention team paid to argue.

Keep reading

Handpicked from the Resource Library