Hosting Cost
Intermediate Resources

Web Hosting Security Checklist

Marcus Feld, Infrastructure Editor
Marcus Feld

Infrastructure Editor

Disclosure: Some links on this page are affiliate links — if you sign up through one, we may earn a commission at no extra cost to you. It never changes our ratings, rankings or verdicts: we don't sell hosting and take no pay-for-placement.

Who it's for

  • Site owners
  • Developers
  • Agencies managing client security
  • Anyone hardening a hosting account

Hosting security splits into two zones of responsibility. The provider secures the physical infrastructure and network. The account owner secures everything running on top of it — the application, the credentials, and the configuration. This hosting security checklist covers web hosting security end to end, from account setup through ongoing hardening.

Hosting Security Checklist: Account-Level Security

  • Use a unique, strong password for the hosting account itself, not reused from any other service
  • Enable two-factor authentication on the hosting account and control panel, if offered
  • Review who has access to the hosting account and control panel, and remove anyone who shouldn’t
  • Confirm the account’s registered email and recovery details are current
  • Understand what’s covered under hosting terms of service regarding account compromise

See how to secure your hosting account for the full account-hardening walkthrough.

Hosting Security Checklist: Application-Level Security

  • Keep the CMS, plugins, and themes updated to their latest stable versions
  • Remove unused plugins, themes, and old site copies entirely, don’t just deactivate them
  • Install an SSL certificate and confirm HTTPS is enforced site-wide (see install an SSL certificate)
  • Use strong, unique passwords for every admin/user account on the site itself
  • Limit login attempts and consider two-factor authentication at the application level

File and Server Configuration

  • Set correct file permissions — avoid overly permissive settings on directories and files
  • Disable directory listing on the web server
  • Remove or restrict access to any exposed configuration, backup, or setup files
  • Confirm SSH access uses key-based authentication rather than a password alone, if using root access

Threat Mitigation

Hosting Security Checklist: Backups and Recovery

  • Confirm automatic backups are enabled and running on the expected schedule
  • Verify backups are stored off-server, not only on the same account they’re protecting
  • Test a restore at least once so recovery isn’t untested when it’s actually needed
  • Keep a documented recovery plan for what to do if the site is compromised — see how to secure a website

Ongoing Maintenance

  • Re-run this checklist after any major change: new plugin, new admin user, new third-party integration
  • Review account access and remove stale users on a regular schedule
  • Monitor uptime and error logs for anomalies that could indicate a compromise
  • Stay current on the shared-responsibility line — see web hosting security for what the host covers versus what the account owner must handle

Security on shared and managed plans leans more on the provider. On VPS, dedicated, and colocation, the account owner carries far more of this list personally, since there’s no managed layer absorbing it — see root access & SSH for what that responsibility actually involves.

For the full security guide this checklist condenses, see web hosting security. For the resources hub, see web hosting resources.