Web application firewall
Every request is inspected at the network edge for SQL injection, cross-site scripting, path traversal and other OWASP Top 10 attacks — before it reaches WordPress or your code.
Hostwoody hosting protects your website before, during and after an attack — with an edge firewall, DDoS mitigation, daily malware scans, login protection and isolated infrastructure. All included, with nothing to install.
Every request is inspected at the network edge for SQL injection, cross-site scripting, path traversal and other OWASP Top 10 attacks — before it reaches WordPress or your code.
Volumetric and application-layer attacks are filtered in real time, so genuine visitors keep reaching your site.
Websites are scanned every day for web shells, spam scripts and other malware, with a report and optional email alert. Rescan on demand after fixing issues.
Automated login attempts on common website logins are detected, challenged and blocked.
Traffic from networks with a poor reputation is blocked or routed away from standard web servers.
Protect your control panel and SSH access with time-based one-time codes.
Web servers only serve websites, database servers only run databases and email servers only handle email. Logs go to central log servers. This separation means that even if a website is compromised, an attacker can’t read your email or cover their tracks.
The platform has no single point of failure, backups are kept off-site in a different data centre, and our data centres have 24/7 on-site security, CCTV and controlled access.
FTP, SFTP, SSH and remote MySQL stay locked until you enable them, and FTP can unlock for a set time only.
Block individual IP addresses, whole ranges or entire countries.
Add a password to any part of your site without writing code.
Find and fix permission errors that could expose files.
Check that WordPress core files match the official release.
Manage HTTP security headers from the CDN dashboard.
No. The firewall, malware scanning and login protection run at server and network level, so there’s nothing to install and no plugin slowing your site.
You’ll see a report in MyPanel and can receive an email alert. Outgoing PHP mail may be disabled to stop the site spreading spam. Update or remove the affected software, delete compromised files, then rescan — or restore a clean backup.
No. Every feature on this page is included with all hosting plans.
No host can promise a site will never be attacked. Our layers greatly reduce the risk, but keeping your software, plugins and passwords up to date remains essential.
Firewall, DDoS protection and malware scanning come with every plan.