Security & protection — included free
Every site is protected, cleaned and repaired for you, automatically
Malware removal, flood protection, a website firewall, login protection, bot checks for your forms, safe updates and automatic repairs are built into our hosting platform. They run on their own, around the clock, on every site you host with us — nothing to buy, install or switch on, and no extra charge.
- Included free on every plan
- Automatic malware removal
- Flood guard
- Website firewall
- Login & form protection
- Self-repairing sites
Already a customer? You are already covered — every protection on this page is on for your sites right now.
Protection that works while you sleep
Most hosting leaves security to you: a plugin to install, a scanner to pay for, a clean-up service to call when it goes wrong. Here it is part of the platform itself, and it acts on its own.
Automatic malware removal
Every file that changes on your sites is checked within the hour, and every file is checked again each day. Files that match known malware are taken off the site straight away and kept safely aside, a known malicious program started from a site’s files (such as a hidden crypto-miner) is stopped within minutes, and you get one plain e-mail saying what we found, what we removed and what to do next. When malware turns up on one site, every other site on your account is checked straight away too.
Malware scan for every site
On top of that, each site’s Malware scan tab shows the results of a full scan in plain words, with buttons to scan again, quarantine or restore a file, put back official core files or ask us to check a file. Official, unchanged copies of WordPress, plugins, themes, Joomla and Drupal are never reported.
Flood guard
If a site is hit by a flood of fake traffic, flood guard spots it within minutes and puts limits on that site alone, so it stays online and your other sites are never dragged down. You get an e-mail when it acts, and the limits come off by themselves once the flood stops.
Website firewall
Requests to your site are checked before your site sees them. Break-in attempts — reading private configuration files, injecting database commands, climbing out of the site folder — are refused. Signing in, editing, uploads and plugin installs are left alone, and each site has a Website firewall tab.
Login protection
Password-guessing attacks on WordPress logins and XML-RPC are slowed at the server, before they ever reach your site, so bots cannot hammer your admin page. Real sign-ins and our one-click admin login are not affected.
Bot check for your forms
A “verify you are human” check for WordPress login, sign-up, comment and contact forms. Switch it on in one click — and if a site’s forms start being abused by spam bots, we switch it on for you and let you know. New WordPress sites with a contact form get it from day one.
Backdoor & bad-plugin guard
Known back doors, fake or malicious plugins and phishing kits are refused the moment they land — whether they arrive through WordPress, the File Manager, an upload or a restore.
Updates that cannot take you offline
WordPress sites are kept up to date automatically, and we load each site before and after every update. If an update would break it, it is put straight back and the rest are kept — so staying secure never costs you an outage.
Site integrity guard
Every hour, WordPress, Joomla and Drupal sites are checked for tampering and breakage — a changed site address, damaged settings, altered core files. What can be fixed is repaired automatically, with a backup taken first, and you get one e-mail saying what we put right.
Broken sites repaired for you
Common faults that take a site offline, such as an endless redirect loop, a missing theme or a broken line in a site’s .htaccess file, are found and fixed automatically, with a backup of anything we change. If a site goes down for a reason only you can fix, we e-mail you what is wrong and how to fix it.
Walled off from everyone else
Each account’s sites run in their own separate containers, with their own PHP and their own databases. Other customers’ sites cannot reach your databases, and a problem on someone else’s site stays on their site.
Your domain’s e-mail reputation, protected
E-mail your sites send is signed as your own domain with DKIM and covered by DMARC where we run your DNS, so it lands in inboxes. Outgoing mail is checked on the way out, and obvious spam — for example a bot abusing a contact form — is held back instead of being sent in your name.
What happens if one of your sites is hacked
Any website can be broken into — usually through an old plugin or a reused password. What matters is how fast it is found and how much of the clean-up you have to do yourself. Here is what happens on our platform, without you asking.
- It is found quickly. Changed files are checked every hour, running programs every few minutes, and every file every day.
- The known malware is taken off. Matching files are removed from the site and kept safely aside, and anything they started is stopped. Your content, uploads and settings are not touched.
- Your other sites are checked too. Attackers rarely stop at one site, so every other site on your account gets an automatic deep check straight away, and known malware found there is taken off in the same way.
- You are told, once, in plain words. An e-mail says which site, what we found, what we took off and the few things worth doing now, such as changing admin passwords and updating old plugins.
- The rest is on your dashboard. The site’s Malware scan tab lists anything else worth a look, with one-click quarantine, restore and core-file repair. The site health check repairs damaged core files and settings.
- We are here if you want a hand. Press Ask support to check on the tab, or open a ticket, and our team looks at the files for you.
No clean-up bill. Automatic malware removal, the scans, the repairs and the e-mails are all part of your hosting. There is no “security add-on” to buy and no per-clean-up fee.
What you see on your dashboard
It all runs by itself, but nothing is hidden: every site has tabs that show what is protecting it and let you take control when you want to.




Included free, on every plan and every site type
Nothing on this page is an add-on. Whether you host one site or a thousand, WordPress or static HTML, a money site or a private blog network, these protections are built in and on by default.
On every site
Automatic malware removal, the malware scan, flood guard, the website firewall, isolation between customers, and the backdoor and upload guard — whatever the site is built with.
On WordPress sites, too
Login protection, the bot check for forms, updates that are checked and undone if they break the site, and the bad-plugin guard. Joomla and Drupal sites get the hourly integrity check and repair as well.
Behind it all
Free daily backups with one-click restore on every site, and optional hourly backups when you want to roll back to any hour. We regularly restore real backups to prove they work, rather than hoping they do.
Questions
Do I pay extra for any of this?
No. Every protection on this page is included with your hosting at no extra cost. The only related paid option is hourly backups, for when daily backups are not enough.
Do I need to install a security plugin?
No. The protection runs on our platform, outside your site, so there is nothing to install, configure or keep updated — and it covers static, PHP, Joomla, Drupal and shop sites as well as WordPress. You can still use a security plugin if you like one.
Will you delete my files if you find malware?
Only files that exactly match known malware are taken off automatically, and they are kept safely aside rather than destroyed, so nothing is lost. Anything less certain is shown on the site’s Malware scan tab for you to decide, with one-click quarantine and restore. Your content, uploads and settings are never touched.
How will I know if something happened?
We e-mail you: when malware is removed from a site, when flood guard protects a site, when we switch the form bot check on because a site is being spammed, and when we repair a site. Each e-mail says what happened and whether you need to do anything. You can also see everything on each site’s tabs.
Can the firewall block my real visitors?
It is tuned to leave normal use alone: signing in, editing pages, uploading media, installing plugins and themes, payment callbacks and scheduled tasks all pass. If something legitimate is ever blocked, the visitor sees a reference number — send it to support and we look at it straight away.
What does flood guard do to my site during an attack?
It puts limits on the flooded site only — on sites using Cloudflare it also turns on “I’m Under Attack” mode for a few hours. The site stays online, perhaps a little slower, and the limits come off by themselves once the flood stops. Your other sites carry on as normal.
Can one customer’s hacked site affect mine?
No. Every account’s sites run in their own containers with their own databases, walled off from other customers, and a flood aimed at someone else’s site is limited to that site.
Which site types are covered?
All nine: WordPress, static HTML, PHP, Joomla, Drupal, PrestaShop, OpenCart, Grav and MediaWiki get malware removal, scanning, flood guard, the firewall and isolation. Protections that are specific to WordPress, Joomla or Drupal apply to those sites.
Read more
Hosting that looks after itself
Every protection on this page is on from the moment your first site goes live.
