SSL & Security

Website Security Basics

The simple, high-impact habits that keep a WebFulHost site safe: strong passwords, updates, backups and knowing what a host protects.

Most website break-ins aren't clever hacks — they're weak passwords and unpatched software. The good news is that the habits that stop them are straightforward. This is the security checklist every WebFulHost customer should have.

The non-negotiable checklist

  1. Use HTTPS. A valid SSL certificate is the baseline. Yours is included — see How to Enable SSL and Force HTTPS.
  2. Strong, unique passwords everywhere. That means cPanel, the client area, email mailboxes, WordPress admin, FTP and databases — each its own password. No reusing the dog's name.
  3. Update everything. WordPress core, plugins and themes form the most common entry point. Follow How to Update WordPress on a routine.
  4. Keep regular backups you can restore. WebFulHost takes automated daily backups, so a worst-case restore is one support request away.
  5. Remove what you don't use. Delete unused plugins, themes, mailboxes, FTP accounts, and old installations of anything.

What WebFulHost protects for you

Our team maintains the server: patching the operating system and control panel, monitoring for outages, blocking obvious attack traffic, and securing the hosting platform itself. That's significant — but it does not cover password choices on your own site, an outdated plugin with a known hole, or a mailbox password written on the office whiteboard.

Worth adding

  • Two-factor authentication (2FA) on your client area and any service that offers it — a stolen password alone then isn't enough.
  • Security plugins and login limits for WordPress that throttle brute-force login attempts.
  • Limited FTP accounts per person, and SFTP rather than plain FTP where possible (FTP vs SFTP).
  • A quick audit every few months — do a search like "wordpress malware signs" and glance at your user list for accounts you didn't create.

If you suspect a breach

Act fast, in order: change your passwords (client area first), note the date you noticed, and submit a ticket. Our support team can check server-side logs and point you at the right restore point. See What to Check Before Restoring a Backup once it's time to rebuild.

Was this article helpful?

Your feedback helps us improve our guides.

Still need a hand?

Contact WebFulHost Support — our team is available 24/7.