Hosting Terms
What is SQL Injection?
What SQL Injection really means, with the jargon taken out — plus the example that makes it obvious.
Straight answer first
SQL injection smuggles database commands in through an input field — turning a search box or a login form into a channel for reading or rewriting your data.
Below: the fuller explanation, a picture that makes it stick, why it matters in practice, and where you will actually run into it.
Written by the Hosting Seller staff · Checked 1 August 2026
0
Terms left unexplained
100+
Definitions, cross-linked
Real
Examples from real kit
Free
To read, naturally
It works against code that glues user input straight into a database query. The cure is parameterised queries, which hand input to the database as data and never as instructions. Modern frameworks do this by default, and WordPress provides prepared statements for exactly this purpose.
For a site owner the exposure almost always arrives through a component. One plugin with a sloppy query is a door into your database, which is why keeping things updated and running a WAF that recognises injection attempts both earn their place.
The everyday comparison
Writing an instruction to the stockroom in the box marked 'your comments'. A careless clerk reads it out as an order; a disciplined one files the sheet exactly as written and asks no questions of it.
Comparisons simplify, naturally — but this one holds together well enough to reason with, and reasoning is the whole point of a glossary.
Why this one is worth knowing
It stays near the top of every attack list for good reason, because one vulnerable input can expose a whole database. What you can actually do about it is keep components current, give the database user only the permissions it needs, and let the WAF screen the attempts.
You do not need to work at this layer every day. You need to recognise it when it explains something, which is exactly the moment this page earns its keep.
What it looks like day to day
A probe submits ' OR 1=1-- into an old plugin's search field. The WAF recognises the shape and blocks it, and the patch released that week removes the flaw the probe was looking for.
Perfectly ordinary once you have seen it, which is rather the point: most hosting concepts are simple machinery wearing an intimidating name.
The Hosting Seller angle
You will meet it in the control panel and occasionally in a support conversation, usually already set the right way. If this term made sense, the natural next reads are WAF, Database, Cross-Site Scripting and Malware.
SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.

A glossary written by the people on the counter
Every confusing term in hosting turns into a support ticket sooner or later, so we defined the hundred most common ones properly, once, in the plain English we would use across the counter.
SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.
- 100+ terms, all in plain English
- Everyday comparisons and real examples
- Related concepts linked together
- Written by the people on the desk
Why Hosting Seller
On every plan, as standard
Pictures that stick
Each concept gets a comparison you will still remember at the moment you actually need it.
Grounded in real kit
Examples point at hosting you would actually use, not at an abstract diagram.
One term, fully landed
SQL Injection defined, pictured by comparison and placed in your own control panel — recognise-level in a single read.
Honest about what to skip
Most terms are recognise-level rather than operate-level, and the glossary says which is which.
Linked, never siloed
Related terms cross-reference each other, so one lookup grows into a working understanding.
Plain English first
Every term defined for people who run sites, not for other sysadmins — jargon translated rather than restated.
First Steps
From choosing to live
- 1
Find it in your own account
Open the control panel and find where this concept lives — seeing it attached to your own site is what turns a definition into understanding.
- 2
Check what the defaults are
Our platform ships sensible defaults for this — check rather than assume, and you will know your setup instead of hoping about it.
- 3
Follow the terms next door
Concepts travel in packs — WAF, Database and Cross-Site Scripting finish this one's picture, and each is a two-minute read away.
In the Box
Packed with every plan
- WebP image optimisation built in and costing nothing
- NVMe SSD storage on every shelf, not just the top one
- Real people on the counter, every hour of every day
- Site migration done for you by our staff, at no charge
- WordPress Toolkit, with updates applied for you
- The Softaculous installer for one-click application setup
- Upgrades apply to the account in place, with no move between plans
- Spam and virus filtering fitted to every mailbox
- SSH, Git and Composer on the plans built for developers
- Webmail in the browser plus IMAP, POP and SMTP for your own client
Across the Counter
The questions we get asked most
Can I do anything about SQL injection if I am not a developer myself?
You have three real levers. Keep every component updated, since patches remove the flaws. Run hosting with a WAF, since it blocks the attempts in the meantime. And keep backups, since they cap what a successful attempt can cost you. Fixing the code itself belongs to whoever wrote the component.
How would I even know whether an injection attempt succeeded?
Usually you find out sideways: your data turns up somewhere it should not, spam content appears, an admin account you never created shows up, or the database starts behaving oddly. That indirectness is the argument for prevention rather than for hoping to catch it in the act.
Do you shift an existing site across at no charge?
We do. Open a ticket with the login details for your current host and the whole lot comes over: files, databases, mailboxes and configuration. You check the copy before DNS changes hands, and the old site keeps serving customers until the new one takes the traffic, so nobody ever sees a gap.
What uptime do you commit to, and who is watching?
We commit to 99.9% uptime and watch it continuously. That figure is an operational target rather than a poster line, and the alerting behind it usually has an engineer on a problem before the first customer notices anything is wrong.
Are backups included, and can I put one back myself?
A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.
Is there a refund if it does not suit?
Yes — thirty days. Put the hosting through real work, and if it is not right, ask for the money back and you get it; there is no retention script to survive first. Domain registrations are the one carve-out, because registries take that fee the moment the name is placed.
Can I bring a domain I already own?
Yes, and transfers in are routine. Unlock the name at your present registrar, collect the auth code, then start the transfer from your client area. Whatever registration time is left comes across with it, and DNS keeps answering the whole way through.
Read next
Malware
Website malware is hostile code planted on a site somebody has broken into — spam injections, redirects, ph…
Cross-Site Scripting (XSS)
XSS plants an attacker's script into pages other people view — stealing sessions, defacing content or redir…
cPanel Reseller Hosting
The panel the trade already knows, sized for resellers, WHM in the box.
Web Hosting
cPanel hosting on NVMe disks, with SSL, migration and year-one domain included.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Do the launch properly this time.
From a first website to a rack of servers, moving up is a change to your account rather than a migration.
See the plans