Website security

Security built into every layer of your hosting

Hostwoody hosting protects your website before, during and after an attack — with an edge firewall, DDoS mitigation, daily malware scans, login protection and isolated infrastructure. All included, with nothing to install.

  • PCI-compliant hosting
  • ISO 27001-certified data centres
  • No security plugins required
A close view of server drive bays and ventilation grilles
Protection layers

How your website is protected

Web application firewall

Every request is inspected at the network edge for SQL injection, cross-site scripting, path traversal and other OWASP Top 10 attacks — before it reaches WordPress or your code.

1 Tbps+ DDoS protection

Volumetric and application-layer attacks are filtered in real time, so genuine visitors keep reaching your site.

Daily malware scanning

Websites are scanned every day for web shells, spam scripts and other malware, with a report and optional email alert. Rescan on demand after fixing issues.

Brute-force login protection

Automated login attempts on common website logins are detected, challenged and blocked.

Bot and IP reputation filtering

Traffic from networks with a poor reputation is blocked or routed away from standard web servers.

Two-factor authentication

Protect your control panel and SSH access with time-based one-time codes.

Infrastructure

Isolated, redundant infrastructure

Web servers only serve websites, database servers only run databases and email servers only handle email. Logs go to central log servers. This separation means that even if a website is compromised, an attacker can’t read your email or cover their tracks.

The platform has no single point of failure, backups are kept off-site in a different data centre, and our data centres have 24/7 on-site security, CCTV and controlled access.

  • Separate web, database, FTP and email servers
  • Off-site backups in a second data centre
  • PCI-compliant hosting platform
  • ISO 27001-certified data centres
Included on every plan
  • Web application firewall
  • DDoS mitigation
  • Daily + on-demand malware scans
  • Free wildcard SSL
  • Brute-force protection
  • 2FA for your control panel
  • FTP security lock
Your controls

Lock down your own website

FTP security lock

FTP, SFTP, SSH and remote MySQL stay locked until you enable them, and FTP can unlock for a set time only.

Block IPs and countries

Block individual IP addresses, whole ranges or entire countries.

Password-protect directories

Add a password to any part of your site without writing code.

File permissions checker

Find and fix permission errors that could expose files.

WordPress checksum report

Check that WordPress core files match the official release.

Security headers

Manage HTTP security headers from the CDN dashboard.

FAQ

Security questions

Ask us something else →

Host with security built in

Firewall, DDoS protection and malware scanning come with every plan.