Glossary Entry
What is SQL Injection?
SQL Injection without the jargon — the definition, the analogy, and why any site owner should care.
The short answer
SQL injection slips database commands into an ordinary input field, turning a search box or a sign-in form into a route for reading or rewriting your data.
What follows: the longer explanation, a picture that holds, the practical stakes, and the places you will genuinely meet it.
By the Hosting & Domains team · Reviewed 18 August 2026
100+
Terms in the jargon buster
2 min
Average read time
Plain
English throughout
24/7
People, if you get stuck
It works on code that pastes user input straight into a database query. Parameterised queries are the fix, since input then reaches the database labelled as data rather than as something to execute. It is the default in modern frameworks, and WordPress ships prepared statements for precisely this.
For a site owner the exposure nearly always arrives through a component. A single plugin with a careless query becomes a doorway into your database, which is exactly why staying updated and running a WAF that knows injection attempts both pay for themselves.
The everyday parallel
Putting an instruction to the warehouse into a free-text comments field. A careless clerk treats it as an instruction and acts on it, while a disciplined one files the sheet verbatim and never asks what it says.
Any analogy flattens the detail, naturally — but this one is solid enough to think with, and thinking is what a jargon buster is for.
Why this term earns a page
It stays near the top of every attack list because a single vulnerable input can expose an entire database. What you can practically do is keep components current, give the database user only the permissions it needs, and let the WAF screen the attempts.
Nobody expects you to work at this layer daily. The aim is recognising it when it explains something — and that moment is exactly when this page pays for itself.
How it turns up day to day
Into the search field of an ageing plugin, an automated probe drops ' OR 1=1--. That shape is familiar to the WAF, which blocks it, and the patch released that week takes away the flaw the probe was after.
Entirely unremarkable once you have seen it — which is the point: most hosting ideas are plain machinery behind an intimidating label.
How Hosting & Domains deals with it
You will meet it in the control panel and now and then in a support thread, usually already set correctly. If this one landed, the natural follow-ups are WAF, Database, Cross-Site Scripting and Malware.
A free SSL certificate comes with every plan and reissues itself before the old one lapses — the padlock is never yours to diarise.

Unexplained jargon slows everybody down
An unexplained piece of jargon is, to us, a service defect. This is the support team's collected translations, published where a search engine can hand them over on our behalf.
A copy is taken daily on every plan, and putting a file or a database back is one click in the panel rather than a support ticket.
- 100+ entries, plain English all the way
- Ordinary analogies, working examples
- Neighbouring ideas linked together
- Written by our own support engineers
Why Hosting & Domains
Standard on every plan
Analogies that hold
Every concept comes with a mental model that returns exactly when you need it.
Tied to real hosting
Examples name platforms you would genuinely use, never an abstract diagram on a whiteboard.
This term, properly landed
SQL Injection defined, pictured by analogy and located in your own panel — recognise-level after a single read.
Clear about how deep to go
Most of these are recognise-level rather than operate-level, and every entry says which it is.
Cross-wired entries
Related terms point at each other, so one lookup compounds into working knowledge.
Jargon-free by design
Definitions written for people who run sites, not for other sysadmins — translation rather than restatement.
Quick Start
Order placed to site online
- 1
Find it in your own account
Open the control panel and find where this idea sits — a definition turns into understanding the moment it attaches to your own site.
- 2
Check the defaults as they stand
The platform ships sensible defaults for this — check rather than assume, and your setup becomes something you know instead of hope.
- 3
Chase the neighbouring terms
Hosting terms travel in groups — WAF, Database and Cross-Site Scripting finish this one's picture, each a two-minute read away.
Built In
Fitted to every plan
- Free SSL on every plan, reissued before the old one lapses
- LiteSpeed caching in the server itself rather than bolted on by plugin
- Your existing site brought across by our engineers, at no charge
- WebP image optimisation built in, at no extra charge
- People on the support desk every hour of every day
- WordPress and 400+ further applications installed in one click
- A daily copy, with restores you run yourself from the panel
- Webmail in the browser plus IMAP, POP and SMTP for any client
- Softaculous included for one-click application installs
- Upgrades applied in place, with no migration when you change plan
Frequently Asked
The questions that come up most
Can a non-developer do anything about SQL injection?
You have three real levers. Update every component, because patches are what remove the flaws. Run hosting with a WAF, since it blocks attempts meanwhile. And keep backups, since they cap what a successful attempt can cost. Repairing the code belongs to whoever wrote the component.
How would I know an injection attempt had succeeded?
Usually you find out sideways: your data appears where it should not, spam content shows up, an admin account you never created exists, or the database starts behaving oddly. You learn at one remove, which is exactly why prevention beats any plan to catch it happening.
Will you move my existing site free of charge?
Yes. Open a ticket with the login for your current host and we bring the lot across — files, databases, mailboxes, configuration. You check the copy before DNS moves, and the old site keeps taking traffic right up to the moment the new one serves it, so nobody meets a gap.
What is the uptime commitment, and what happens in a month that misses it?
99.9% — and if a month falls below that through a fault on our side, our terms entitle you to a pro-rated credit; ask and we apply it. Calling it a target rather than a contractual SLA is a deliberate choice. Hardware and network faults surface through platform monitoring, usually before the first customer notices.
Keep reading
Cross-Site Scripting (XSS)
With XSS, an attacker's script ends up inside pages other people load, taking sessions, defacing content or…
Malware
Website malware is the hostile code an intruder leaves behind once inside: spam injections, redirects, phis…
How to Test Your Website Speed
A walkthrough to follow with the panel open in the next tab.
VPS Hosting
KVM virtual servers — root access, DDoS filtering, one flat monthly figure.
Dedicated Cloud
Reserved resources with cloud flexibility — the step above a VPS.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Register it, then build on it.
From a first website to a rack of machines, moving up is a change to the account rather than a migration.
View VPS Hosting plans