“Daily backups” is useful plan-table language only when the provider also states how long copies remain available and how restoration works. “Firewall protection” needs a named layer plus a response policy for blocked traffic.
Secure web hosting begins with dependable platform controls. It also supplies a workable recovery route for the customer.
Manual malware cleanup can reasonably cost more because a specialist must inspect the compromised site. Remediation then fixes the exploited weakness. Advanced web-application filtering may also cost more for a higher-risk site. Before purchase, the base plan should describe its automatic response. It should tell the customer which recovery step remains their responsibility.
Included Protections to Verify Before Purchase

A credible managed shared-hosting plan names how each protection works and what happens when it fails.
| Protection | Included baseline | Implementation question |
| TLS | Automatic certificate issuance and renewal | Which hostnames are covered, and how is failed renewal reported? |
| Access | Multi-factor authentication with encrypted file transfer | Can every privileged user have a separate login? |
| Isolation | Boundaries between customers and unrelated sites | Can one compromised site write into another site's files? |
| Network defense | Always-on network filtering and basic DDoS mitigation | Which attack layers are covered, and when is traffic blocked? |
| Malware control | Basic monitoring with a defined alert route | What happens after the monitor raises an alert? |
| Backups | Automated copies stored apart from the live site | What is retained, and can the customer restore or download it? |
| Platform care | Supported runtimes and provider patching | Which software layers remain the customer's duty? |
| Incident access | A security contact available at all hours | What information is supplied during an incident? |
Providers can operate these controls consistently across managed infrastructure. Plan documentation should confirm the exact coverage for the purchased tier.
Hosting Security Responsibility

Hosting security follows a shared-responsibility model. On shared hosting, providers normally maintain the physical system and the managed server layer. They should also patch the control plane and maintain separation between customer accounts.
WordPress site owners remain responsible for administrator identities and application data. Plugins and themes also remain with the owner unless the plan explicitly manages them. Custom code always needs a named maintainer.
The amount of management changes the responsibility boundary for each software layer. An automatic WordPress core update is a specific service. Plugin and theme coverage requires an explicit plan term. Ask the provider to name responsibility for the operating system and PHP runtime. Then obtain the same answer for the content management system and its extensions.
Migration to a new host can carry a compromised site's infected files and stolen credentials. The cause must be corrected, and the replacement environment needs new secrets before restored content is trusted.
How Each Included Protection Works

The best pre-sales questions describe a plausible incident. A precise answer reveals more than another row of security terms.
Account access and site isolation
Suppose a staff administrator leaves on Friday. Revoke that person's individual control-panel identity and SFTP or SSH identity immediately. The replacement administrator should enroll a new multi-factor method under a separate identity. Unencrypted FTP should not carry an administrative session. A retained file-access log then preserves attribution for activity before departure, which shared credentials would erase.
Isolation deserves attention on shared hosting because several customers use common infrastructure. The provider should prevent one customer account from reading or writing another customer's files. A plan label such as “secure shared hosting” does not describe that boundary.
Isolation inside one customer account can be weaker. Placing many unrelated sites under one writable identity may let one compromised installation affect the others. Ask if isolated site containers or accounts are available, then use distinct credentials for sites with different owners.
Network firewall and DDoS defense
A network firewall filters connections at the infrastructure boundary. A web application firewall inspects HTTP requests for patterns associated with attacks on the application. The word “firewall” alone does not establish that a managed WAF or a particular ruleset is included.
Basic network DDoS mitigation should operate continuously on a credible platform. Ask which attack types are covered and if mitigation starts automatically. The provider should also explain any capacity limit or null-routing policy. Application-layer floods may require a CDN or WAF service beyond the entry plan.
Malware monitoring and response
Malware scanning can identify suspicious files or behavior. An alert needs a defined recipient and a response path. Ask how quickly the customer is notified and if the provider automatically quarantines files.
Cleanup is an additional service. It may require inspection of files and the database, followed by repair of the exploited weakness. Blacklist appeals or incident forensics add more labor. A base plan can reasonably charge for this work when detection and the cleanup boundary were disclosed before purchase.
Backups and restoration
Backups restore files and databases after compromise or accidental change. Daily frequency is a practical floor for a low-activity brochure site, while a busy store may need recovery points within the day.
With 7 daily restore points, a compromise discovered after 2 weeks has no clean daily copy. Longer retention or an earlier independent copy preserves a recovery point outside that bounded window.
Backup coverage matters as much as frequency during a WordPress recovery. The recovery needs the database and uploaded media. It also needs the relevant configuration files that define the installation. Confirm that a complete copy can be downloaded without waiting for support.
GreenGeeks lists daily backups on current WordPress plans. On-demand backup and restore are available only on select plans. Plan descriptions must identify who can initiate restoration and give the normal support-assisted recovery time.
Test a restore after setup and after a major platform change. Use staging or another disposable location. Open the restored site and verify a representative form. Record the procedure so the next administrator can repeat it during an incident.
Keep an independent copy outside the hosting account. A billing lockout or provider failure can make an internal backup inaccessible at the time it is needed.
Supported software and security contact
Current server software and a migration path away from an expiring runtime belong in the hosting baseline. For WordPress, that includes a current PHP branch and supported database software. Advertising malware monitoring while leaving applications on an end-of-life runtime is an avoidable conflict.
Ask which server layers receive automatic security patches. Record the customer's update duties in their own section of the service record. If the plan includes WordPress core updates, confirm how failed updates are reported and if rollback is available.
Hosting providers should publish a security contact and an incident-notification process. During a provider incident, the customer needs the affected service and relevant time window. It also needs practical containment instructions. Urgent security cases require a defined escalation route from any general support inbox.
Security work that can reasonably cost more

Paid security is justified when the service assigns human work to a defined incident. When a specialist removes malware by hand, the fee pays for incident labor. Vulnerability remediation can follow after cleanup identifies the entry point. Advanced WAF management may also be an add-on. High-capacity application-layer DDoS response belongs in a named service tier. Bot management can be priced separately when the site attracts automated abuse.
Long retention consumes storage. More frequent recovery points add operating work for the provider. Managed disaster recovery can include restoration exercises tied to a recovery objective. Compliance support requires specialist knowledge of the relevant regulatory control framework. Incident forensics adds investigation after a compromise.
Application maintenance is another reasonable paid boundary when the provider accepts update responsibility. A provider may test plugin updates before release. Compatibility repair requires explicit scope for each covered component in the contract. The contract should identify every covered application. It should also explain the handling of an urgent security update. A broad “security package” without these deliverables merely adds another unexplained label.
Incident Response as a Buying Test

Choose the least expensive plan that gives a complete written answer to a plausible incident. Before buying, ask what detects a vulnerable plugin exploit overnight and who contacts the customer. The provider should name any automatic containment and identify the latest clean recovery point.
A second answer must assign the cleanup work and state its price. If the sales team cannot name the responsible party before purchase, the business will have the same uncertainty during the incident.


