Skip to main content

Glossary Entry

What is SQL Injection?

SQL Injection without the jargon — the definition, the analogy, and why any site owner should care.

The short answer

SQL injection slips database commands into an ordinary input field, turning a search box or a sign-in form into a route for reading or rewriting your data.

What follows: the longer explanation, a picture that holds, the practical stakes, and the places you will genuinely meet it.

By the Hosting & Domains team · Reviewed 18 August 2026

100+

Terms in the jargon buster

2 min

Average read time

Plain

English throughout

24/7

People, if you get stuck

It works on code that pastes user input straight into a database query. Parameterised queries are the fix, since input then reaches the database labelled as data rather than as something to execute. It is the default in modern frameworks, and WordPress ships prepared statements for precisely this.

For a site owner the exposure nearly always arrives through a component. A single plugin with a careless query becomes a doorway into your database, which is exactly why staying updated and running a WAF that knows injection attempts both pay for themselves.

The everyday parallel

Putting an instruction to the warehouse into a free-text comments field. A careless clerk treats it as an instruction and acts on it, while a disciplined one files the sheet verbatim and never asks what it says.

Any analogy flattens the detail, naturally — but this one is solid enough to think with, and thinking is what a jargon buster is for.

Why this term earns a page

It stays near the top of every attack list because a single vulnerable input can expose an entire database. What you can practically do is keep components current, give the database user only the permissions it needs, and let the WAF screen the attempts.

Nobody expects you to work at this layer daily. The aim is recognising it when it explains something — and that moment is exactly when this page pays for itself.

How it turns up day to day

Into the search field of an ageing plugin, an automated probe drops ' OR 1=1--. That shape is familiar to the WAF, which blocks it, and the patch released that week takes away the flaw the probe was after.

Entirely unremarkable once you have seen it — which is the point: most hosting ideas are plain machinery behind an intimidating label.

How Hosting & Domains deals with it

You will meet it in the control panel and now and then in a support thread, usually already set correctly. If this one landed, the natural follow-ups are WAF, Database, Cross-Site Scripting and Malware.

A free SSL certificate comes with every plan and reissues itself before the old one lapses — the padlock is never yours to diarise.

The filtering that absorbs an attack well before it reaches the site

Unexplained jargon slows everybody down

An unexplained piece of jargon is, to us, a service defect. This is the support team's collected translations, published where a search engine can hand them over on our behalf.

A copy is taken daily on every plan, and putting a file or a database back is one click in the panel rather than a support ticket.

  • 100+ entries, plain English all the way
  • Ordinary analogies, working examples
  • Neighbouring ideas linked together
  • Written by our own support engineers

Why Hosting & Domains

Standard on every plan

Analogies that hold

Every concept comes with a mental model that returns exactly when you need it.

Tied to real hosting

Examples name platforms you would genuinely use, never an abstract diagram on a whiteboard.

This term, properly landed

SQL Injection defined, pictured by analogy and located in your own panel — recognise-level after a single read.

Clear about how deep to go

Most of these are recognise-level rather than operate-level, and every entry says which it is.

Cross-wired entries

Related terms point at each other, so one lookup compounds into working knowledge.

Jargon-free by design

Definitions written for people who run sites, not for other sysadmins — translation rather than restatement.

Quick Start

Order placed to site online

  1. 1

    Find it in your own account

    Open the control panel and find where this idea sits — a definition turns into understanding the moment it attaches to your own site.

  2. 2

    Check the defaults as they stand

    The platform ships sensible defaults for this — check rather than assume, and your setup becomes something you know instead of hope.

  3. 3

    Chase the neighbouring terms

    Hosting terms travel in groups — WAF, Database and Cross-Site Scripting finish this one's picture, each a two-minute read away.

Built In

Fitted to every plan

  • Free SSL on every plan, reissued before the old one lapses
  • LiteSpeed caching in the server itself rather than bolted on by plugin
  • Your existing site brought across by our engineers, at no charge
  • WebP image optimisation built in, at no extra charge
  • People on the support desk every hour of every day
  • WordPress and 400+ further applications installed in one click
  • A daily copy, with restores you run yourself from the panel
  • Webmail in the browser plus IMAP, POP and SMTP for any client
  • Softaculous included for one-click application installs
  • Upgrades applied in place, with no migration when you change plan

Frequently Asked

The questions that come up most

Can a non-developer do anything about SQL injection?

You have three real levers. Update every component, because patches are what remove the flaws. Run hosting with a WAF, since it blocks attempts meanwhile. And keep backups, since they cap what a successful attempt can cost. Repairing the code belongs to whoever wrote the component.

How would I know an injection attempt had succeeded?

Usually you find out sideways: your data appears where it should not, spam content shows up, an admin account you never created exists, or the database starts behaving oddly. You learn at one remove, which is exactly why prevention beats any plan to catch it happening.

Will you move my existing site free of charge?

Yes. Open a ticket with the login for your current host and we bring the lot across — files, databases, mailboxes, configuration. You check the copy before DNS moves, and the old site keeps taking traffic right up to the moment the new one serves it, so nobody meets a gap.

What is the uptime commitment, and what happens in a month that misses it?

99.9% — and if a month falls below that through a fault on our side, our terms entitle you to a pro-rated credit; ask and we apply it. Calling it a target rather than a contractual SLA is a deliberate choice. Hardware and network faults surface through platform monitoring, usually before the first customer notices.

Keep reading

  • Cross-Site Scripting (XSS)

    With XSS, an attacker's script ends up inside pages other people load, taking sessions, defacing content or…

  • Malware

    Website malware is the hostile code an intruder leaves behind once inside: spam injections, redirects, phis…

  • How to Test Your Website Speed

    A walkthrough to follow with the panel open in the next tab.

  • VPS Hosting

    KVM virtual servers — root access, DDoS filtering, one flat monthly figure.

  • Dedicated Cloud

    Reserved resources with cloud flexibility — the step above a VPS.

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Register it, then build on it.

From a first website to a rack of machines, moving up is a change to the account rather than a migration.

View VPS Hosting plans