Skip to main content
HostingSeller
Shop plans

Operator's Guide

Hosting with SSH access — A terminal for you is one decision; a terminal for the client is another

Written for people administering more than one account at a time, where shell access is both the tool that makes the work tractable and the setting most likely to be handed out carelessly.

Straight answer first

Buy shared plans that arrive with SSH, Git and Composer already fitted — a Pro plan gives you the terminal as standard equipment rather than as a privilege to be applied for — and then decide separately, per client account, whether that terminal is exposed to them at all.

Those two decisions get conflated constantly, and the second is the one with consequences. Shell access is what makes administering a fleet possible; it is also the fastest route by which a client's compromised credential becomes your outbound-spam problem.

Written by the Hosting Seller staff · Checked 24 August 2026

99.9%

Uptime target we hold

24/7

Second line, any hour

Free

SSL on every account

NVMe

Disk under every account

For anybody running one site, SSH is a convenience. For anybody running twenty, it is the difference between a job that takes an evening and a job that takes a week — bulk changes, deployments, dumps and log reading all collapse into commands you can repeat and script.

The operator's version of this question therefore has two halves. What can you do from a shell across the accounts you administer, and what happens when a shell exists inside an account you do not fully control. Most hosting pages answer only the first.

The bulk work that pays for the terminal

The jobs that justify shell access are the repetitive ones. A search-and-replace across a database before a domain change. A tarball and a mysqldump taken before anybody touches a plugin. Tailing a log while a client describes a fault badly over the phone. Pulling a release rather than dragging a folder into an FTP window.

On WordPress work specifically, WP-CLI is the reason the terminal earns its keep. Bulk plugin updates, user resets, transient clearing and search-replace are single commands that behave identically on every account, which is exactly what you want when the same task has to happen twenty times.

Composer matters for the same reason on framework work. A dependency install that runs on the server is reproducible; one that depends on somebody's laptop is not, and reproducibility is the property that makes a fleet administrable at all.

Shell for the client: the setting, and the judgement

In WHM, shell access is a per-account decision with three positions: disabled, jailed, or normal. Jailed is the position that should be your default for anybody who is not you — the account gets a shell that sees its own filesystem and nothing above it.

Grant it sparingly. A developer client who genuinely deploys with Git needs it; a shop owner who has asked because a forum post said to does not. Every shell you hand out is a credential that can be phished, reused from a compromised laptop, or left in a leaving developer's terminal history.

The failure mode worth naming is outbound abuse. A stolen shell credential is used to run a mailer or a proxy, not to deface a site, and the first symptom is not a defaced homepage — it is your other clients' mail being treated as suspect. Contain that by keeping accounts separate, keeping shells jailed and leaving them off by default.

Keys, not passwords, and one place to keep them

Use key-based authentication and treat the keys as inventory. Which key opens which account, whose laptop it lives on, and what happens to it when a contractor's engagement ends are questions that need answers before the engagement ends rather than after.

A practical arrangement for small teams: one key per person rather than one shared key per account, so revoking access is removing a line rather than rotating a secret everybody has. It costs a few minutes at setup and saves an unpleasant afternoon later.

Do the same with SFTP, which rides on the same credentials. It is the route most likely to be handed to a designer once and never withdrawn, and it is worth auditing on the same schedule as the shells.

Testing a supplier's shell story before you resell it

Plenty of hosts advertise SSH and mean 'apply, wait, be assessed'. That is unworkable when you are provisioning accounts for clients on a timetable. Ask the pre-sales desk directly whether shell is on at creation, whether jailed shell is available per account, and what the process limits are — and keep the answer.

Here it is standard rather than granted: SSH, Git and Composer are on the account from the start, PHP is selected per site from the panel, and the Pro plan carries the multi-site room that makes the terminal worth having. The renewal figure matches the joining figure, which matters when the account is a cost inside a retainer you have already quoted.

Then verify rather than believe. Order inside the money-back window — 30 days on shared, business, WordPress and WooCommerce hosting, 7 days on reseller — move a real site across on the free migration, and run your actual bulk jobs. Look the company up while you are at it: IGI Security Services Ltd, registered in England and Wales.

A developer writing code against a hosted server environment

Why the recommendation on this page is ours

We are the supplier, and we would rather write that at the top than build a scoring table that mysteriously ranks us first. The useful part of a page like this is the reasoning and the specifics, both of which you can check independently of who wrote them.

Shell access is standard on the plans described here rather than a tier upgrade, which is a commercial decision as much as a technical one — accounts you cannot administer efficiently generate support tickets for both of us.

  • SSH, Git and Composer fitted at account creation
  • Jailed shell available per account from WHM
  • Key-based authentication supported
  • PHP chosen per site from the panel

Why Hosting Seller

On every plan, as standard

Standard, not granted

Shell arrives with the account rather than through an application process, which is the only version that works when you are provisioning to a client timetable.

Per-account control

Shell access is disabled, jailed or normal per account from WHM, so the developer client and the shop owner can be treated differently.

The toolchain already present

Git, Composer and the usual command-line utilities are on the account, so a deploy is a pull rather than a drag.

Accounts that stay separate

Each account is jailed within its own environment, which is what keeps a compromised credential from becoming everybody's problem.

A cost that holds at renewal

The joining figure and the renewal figure match, which is what makes an account safe to bury inside a fixed retainer.

A second line that speaks the language

A desk staffed at any hour whose scope covers DNS, mail, certificates and restores rather than stopping at 'the server responds'.

Price Tags Compared

How we compare with the household names

Typical sign-up and renewal prices across the market, set next to ours — the second number most comparison charts leave off.

What Hosting Seller charges and what it includes, lined up against three rival hosts
Line itemHosting SellerBest sellerTypical big-brand hostTypical budget hostTypical loss-leader
Entry price / mo*$2.42/mo$4–$6$2–$4$1–$3
Price at renewal / mo$2.42/mo$10–$15$8–$12$4–$6
Renewal price on the entry plan is unchanged
SSL on every plan
Site migration included
The entry plan uses NVMe storage
Entry plan gets a backup daily
Live human support, 24/7

*The number in our column is the cheapest plan on our shelf, priced on an annual term and pulled live from the very catalogue that feeds the pricing page, so it cannot drift out of date. Other columns show the ranges shared hosting tends to advertise inside each bracket: introductory rates that normally ask for a one-to-four-year commitment, then climb once that term expires. Naming individual competitors and printing their prices is something we have stopped doing. A figure we cannot re-check on the day you read it has no business sitting in front of you. So compare us with whoever you are genuinely weighing up, and read the renewal line first. That line tells you more than the headline ever will.

First Steps

From choosing to live

  1. 1

    Default every client account to shell disabled

    Turn it on for the accounts that genuinely deploy, and leave it off everywhere else. The setting is per account in WHM, and off by default is the position you will not regret.

  2. 2

    Issue one key per person, never one per account

    Shared credentials cannot be revoked, only rotated, and rotation means telling everybody. Per-person keys make removing a departing contractor a one-line change.

  3. 3

    Run your real bulk job during the trial

    Do not test SSH by logging in. Test it by running the WP-CLI update sweep or the dump-and-restore you will actually be running monthly, and see whether the process limits hold.

In the Box

Packed with every plan

  • SSH switched on at account creation rather than by application
  • Jailed shell selectable per account from WHM
  • Key-based authentication supported for people and for automation
  • SFTP on the same credentials for file work
  • Git and Composer present without a support ticket
  • PHP version chosen per site from the panel
  • Process limits documented rather than discovered
  • Each account isolated within its own environment
  • Daily backups with restores you run yourself
  • Migration into the account carried out by our staff at no charge

Across the Counter

Things people ask us all the time

Should client accounts get shell access at all?

By default, no. Turn it on for the clients who genuinely deploy with Git and leave it disabled for everyone else — it is a per-account setting in WHM with a jailed option in between. Every shell you issue is a credential that can be phished or inherited by a departing developer, and the usual abuse is outbound mail rather than a defaced page.

What is the difference between jailed and normal shell in this context?

A jailed shell confines the session to the account's own environment, so the user sees their files and their processes and nothing above them. Normal shell is broader. For anybody who is not you, jailed is the correct default, and it is the setting you should confirm exists before you build a client offering on a supplier.

What bulk jobs actually justify having a terminal across a fleet?

WP-CLI update sweeps and search-replace, mysqldump before a risky change, tarballs before a migration, log tailing during a fault call, and Git pulls for release. All of them are repeatable and scriptable, which is the property that makes twenty accounts cost the same amount of attention as five.

How do I withdraw access from a contractor who has left?

Remove their key, not the account's. That only works if you issued one key per person rather than one shared key per account — which is why the inventory matters. Audit SFTP at the same time, because it rides on the same credentials and is the access most often granted once and never reviewed.

Read next

  • Web App Hosting

    Hosting a working application rather than a brochure site, judged on what it costs you to keep running.

  • Bots and Automation Hosting

    Keeping schedulers, bots and glue scripts alive around the clock, and what happens when one stops quietly.

  • Web Hosting

    cPanel hosting on NVMe with SSL, migration and the first year of the domain included.

  • Domain Names

    Search, register and transfer names — the first year free with annual hosting.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Order an account with the terminal already fitted.

SSH, Git and Composer from the first minute, jailed shell per account from WHM, and a renewal figure that matches the joining figure.

See Web Hosting plans