Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

Defence Built In

A guard on the door, day and night

Each plan arrives with a managed WAF, Imunify360 malware scanning, DDoS filtering, free SSL, daily backups and 24/7 monitoring already switched on. No add-ons, no upgrade to buy.

Free

SSL on every domain you add

Daily

Backups taken without asking

24/7

Eyes on the platform, always

Layer 7

Firewall and DDoS filtering

Defence In Layers

Six layers between an attacker and your site

The sort of protection you'd normally shop around for and pay extra to add. Here it's priced into the plan from day one.

Layers of firewall and malware defence wrapped around a website

Application firewall (WAF)

Requests are matched against a constantly refreshed library of attack patterns before they reach your code, which catches SQL injection, cross-site scripting and the other well-known exploits on the way in.

Malware scanning by Imunify360

Files are inspected continuously, and anything infected goes into quarantine as soon as it's spotted. Out-of-date plugins pick up a virtual patch that shields them until you update.

DDoS filtering

Traffic is read at the network edge, where large floods and malicious packets are stripped out long before they reach your server. Genuine visitors never notice it happening.

Free SSL that renews itself

Every domain on the account is issued a certificate and kept current automatically, so connections stay encrypted and the padlock never drops off.

Backups every day

A fresh copy of files and databases is stored off-server daily, leaving you a known-good point you can return to within minutes.

Watched around the clock

Automated systems and real people keep an eye on server health, uptime and intrusion attempts every hour of every day, right through the year.

A shield icon standing in for site security and DDoS filtering

Firewall

Attacks turned away at the door

The firewall reads every request before it reaches your code. Bad payloads and probing bots are turned back at the edge while genuine visitors carry on unimpeded — no plugin to install, no rules for you to write.

  • Injection and XSS attempts stopped dead
  • Known bad bots and exploits screened out
  • Abusive traffic throttled automatically
  • Tuned and managed on your behalf
A cloud icon standing in for backups taken automatically each day

Malware Scanning

Imunify360 catches it before it spreads

Imunify360 watches your files continuously. The moment it finds malicious code it isolates that file and flags it to you, boxing the problem in before it can spread quietly — and virtual patching covers out-of-date software until you're ready to update it.

  • Scanning that runs nonstop and on upload
  • Bad files quarantined without your input
  • Virtual patches over out-of-date plugins
  • Plain alerts waiting in your dashboard

Layers In Action

How one layer hands off to the next

No single safeguard catches everything alone. Here's the handoff between them, so an attacker has to beat all six rather than one.

Security team reading a threat-detection dashboard for server activity
  1. 1

    DDoS filtering meets the traffic first

    Large floods and obvious junk are soaked up and dropped at the network edge, before they reach your server at all, so uptime holds.

  2. 2

    The firewall reads what's left

    Whatever passes that point runs into the managed WAF, which turns away injection attempts, cross-site scripting and the other exploits aimed at your application.

  3. 3

    Isolation keeps any damage boxed in

    Your site lives in its own walled-off environment, so trouble on a neighbouring account on the same server has nowhere to go.

  4. 4

    Imunify360 inspects every file that lands

    Anything written to disk is scanned as it arrives — infected files are quarantined automatically, and out-of-date software picks up a virtual patch.

  5. 5

    SSL seals every connection

    Each exchange between visitor and site is encrypted end to end, so data in transit can't be read or tampered with along the way.

  6. 6

    Daily backups catch whatever slips past

    If something still gets through, off-server daily backups put the whole site back to a known-good point in minutes.

Plans

Every tier, secured the same way

The full security stack ships with all three tiers. Take the size your site needs today and move up when it grows.

Launch

One website, online today, on the plainest price tag we print

$2.09/mo

the renewal price is the same · billed annually

SSD storage
10 GB
Websites
1
Bandwidth
500 GB
CPU / RAM
1 core / 2 GB
Databases
25 MySQL
  • A domain name registered free for your first year
  • Free SSL, reissued for you before it ever runs out
  • Hosted elsewhere now? We shift the site across, free
  • An AI site builder included — describe it, publish it
  • WordPress Toolkit, with a backup taken every day
  • SSH, Git and Composer at the command line
Protect My Site

The till is on Hosting Cheap, the billing platform we run orders through.

Best seller

Pro

Shelf room for twenty-five sites on the one account

$2.79/mo

the renewal price is the same · billed annually

SSD storage
20 GB
Websites
25
Bandwidth
1 TB
CPU / RAM
1 core / 2 GB
Databases
50 MySQL
  • A domain name registered free for your first year
  • Free SSL, reissued for you before it ever runs out
  • Hosted elsewhere now? We shift the site across, free
  • An AI site builder included — describe it, publish it
  • WordPress Toolkit, with a backup taken every day
  • SSH, Git and Composer at the command line
Protect My Site

The till is on Hosting Cheap, the billing platform we run orders through.

Elite

200 GB of NVMe, and the power to keep pace with it

$5.59/mo

the renewal price is the same · billed annually

SSD storage
200 GB
Websites
100
Bandwidth
2 TB
CPU / RAM
2 cores / 4 GB
Databases
100 MySQL
  • A domain name registered free for your first year
  • WordPress Toolkit Deluxe on the shelf at no extra charge
  • Imunify360 on guard, with backups taken every 6 hours
  • CloudLinux Pro and PHP X-Ray to trace slow code
  • Python, Node.js and Ruby runtimes ready to use
  • Priority support, whatever hour you need it
Protect My Site

The till is on Hosting Cheap, the billing platform we run orders through.

Extra Safeguards

Three more things working in the background

Engineer locking a server down against brute-force login attempts

Brute-force lockouts

Repeated failed logins bring throttling and IP blocks, so bots hammering away at your admin or mail passwords are shut out quickly.

Patched ahead of the exploit

As soon as a vulnerability is disclosed, a virtual patch shuts it at the firewall — frequently before the software vendor has published an official fix.

Accounts kept apart

Your account is walled off from every other one on the server, so a problem next door has no route through to your site.

A monitoring screen showing 99.9% website uptime

Recovery & Uptime

Daily copies, plus someone watching

Even good defences want a fallback. Daily automated backups let you put the whole site back within minutes, and continuous monitoring keeps watch on uptime and intrusion attempts around the clock, with real people ready to step in.

  • Daily backups held off-server
  • Whole-site restore in one click
  • Monitoring that never clocks off
  • Free SSL that renews itself

How It Works

Secured in three straightforward steps

Small business owner setting up a hardened hosting plan with SSL included
  1. 1

    Choose a plan

    Whichever tier you take, the WAF, malware scanning, DDoS filtering and daily backups are already running. Nothing to bolt on.

  2. 2

    Bring the site across

    Point your domain at us, or hand the migration to our team at no charge. SSL is issued automatically the moment the site goes live.

  3. 3

    Leave it to run

    Check clean scan results and uptime in your dashboard whenever you feel like it, while monitoring and backups carry on quietly underneath.

Included

Every line below ships with every plan

  • A managed WAF in front of your site
  • Imunify360 malware scanning
  • Infected files quarantined automatically
  • DDoS filtering at network level
  • Free SSL, renewed on its own
  • Off-server backups taken daily
  • Restores in a single click
  • Brute-force login protection
  • Hosting accounts walled off from each other
  • Monitoring and support at any hour

FAQ

Straight answers on secure hosting

What kinds of attacks does the firewall stop?

Before any request touches your site's code, the managed firewall weighs it against a library of known attack signatures that our team keeps current. That picks up SQL injection aimed at your database, cross-site scripting payloads written to hijack visitor sessions, remote file inclusion, directory traversal and command injection. It also strains out abusive bots, credential-stuffing scripts and traffic hunting for well-known plugin or theme weaknesses. You never write a rule yourself — we tune and update the firewall as new threats appear. Genuine visitors pass through with no delay or friction at all, while harmful requests are dropped at the edge so your server never has to process them. The practical effect is that a large share of common attacks gets nowhere near your application, your database or your files.

How does the malware scanning actually catch infections?

Imunify360 is standard on every secure plan. It runs in the background continuously and again the instant a file is uploaded or edited. When it finds something malicious — a planted backdoor, a defaced page, a phishing kit, a script pumping out spam — that file goes straight into quarantine, so the problem stays put instead of spreading through the account. Your dashboard shows exactly what was found and where, and you can inspect or restore anything yourself. Alongside detection, virtual patching covers out-of-date plugins and themes against known exploits until you get round to updating them, which closes the gap attackers usually aim for. Because scanning never pauses — rather than running once a day — most problems are caught and shut down within minutes, which keeps the site clean and your visitors out of trouble.

Is the free SSL certificate actually free, no catch?

Yes — no trial window, no first-year-only offer, no upsell waiting at the end. Every domain and subdomain on a secure plan is issued an SSL certificate as it goes live, and that certificate renews itself before it can expire, for as long as you host with us. The padlock your visitors look for never disappears, and no bill or renewal reminder ever arrives for it. What SSL does is encrypt the link between visitor and server, so login details, contact-form submissions, checkout information and anything else typed into the site stays private in transit. It counts toward search rankings too, and it stops browsers pinning a 'Not secure' label on your pages. There's nothing to set up at your end: the certificate is issued and kept current for you, so the site is encrypted from its first day online.

How often do backups run, and can I restore one myself?

Backups run automatically every day and are held off-server, well away from the machine they exist to protect. Each one takes files and databases together, so what comes back is a whole working copy of the site rather than pieces you have to reassemble. Restoring is entirely yours to do: open the dashboard, choose a recovery point, and roll back the whole account, a single site, or just one database — a few clicks, and it's usually finished within minutes. That makes the daily backup the answer to almost anything that goes wrong: a broken update, a bad edit, something deleted by mistake, or worse. You never have to remember to start one, and because the copies live off-server, they're still waiting for you even if the live environment runs into trouble.

Does DDoS protection add any lag to my site?

No. Filtering happens out at the network edge, long before traffic reaches your server, and it works by reading the volume and shape of incoming traffic rather than picking apart each page request. Real visitors are waved through with nothing added to their load time, while a barrage of packets sent to overwhelm the site is absorbed and stripped away before it touches your hosting. Because that filtering capacity spans the whole network instead of one machine, it can soak up attacks far larger than a single server could ever handle. What that means for you is a site that keeps trading through an attack that would knock an unprotected one clean offline. Nothing needs enabling or configuring: it's on by default across every plan, quietly guarding your uptime whether or not anyone happens to be aiming at you.

What exactly does round-the-clock monitoring watch for?

Monitoring mixes automated systems with real people keeping watch over the platform every hour of every day. On the automated side we track server health, uptime, resource usage, disk and network activity, and the known signatures of intrusion, with an alert firing the moment something looks off. Our team then reads those alerts and digs into anything suspicious immediately, rather than waiting for you to notice and open a ticket. That covers hardware faults, odd traffic spikes, repeated failed logins and other signs of trouble, so problems are often dealt with before a visitor sees them. Sitting alongside the firewall, malware scanning and daily backups, this is the layer standing watch while you're asleep or busy elsewhere. And if you spot something first, the same 24/7 support team is one message away and ready to dig in with you.

Put a security team behind your site.

Managed WAF, malware scanning, DDoS filtering, free SSL, daily backups and monitoring at any hour — all in the price.

View Secure Plans

Most sites are attacked by scripts, not by people. Scripts are beaten by patching, filtering and backups, all of which should be running long before you think to ask about them. It runs on NVMe arrays with LiteSpeed in front, in data centres with conditioned power and more than one road to the internet.

A good fit for owners who treat protection as part of the job. The certificate is free, the move is free, the backups run themselves, and support answers in minutes whatever the clock says.

Protection that is already switched on

DDoS filtering happens at the network edge, so junk traffic never reaches your account at all. Accounts are isolated from one another, PHP runs per user, and kernel, panel and PHP patches are applied across the fleet by our engineers as releases land. Free SSL covers everything travelling between visitor and server.

None of that depends on which tier you buy. NVMe storage, LiteSpeed with HTTP/2 and the 99.9% uptime SLA are the same on the cheapest plan and the largest one.

What the hardening covers

You can compare Hosting Seller properly because nothing is hidden to compare. The listed price already includes the certificate, the migration, the backups and the support — the parts other hosts add on later. Every hosting plan carries a 30-day money-back guarantee, so trying us out costs you an afternoon at worst.

Security here is not a tier you climb towards. Filtering, isolation, patching, certificates and daily backups sit on every plan, including the one that starts at $2.09 a month.

A shield icon standing in for site security and DDoS filtering

The layers between your site and the internet

Sites live in tier-3 halls behind edge filtering, on NVMe storage with a backup taken every day. Restores are yours to run from the panel, so a bad plugin or a bad afternoon costs minutes rather than a rebuild.

Backups run daily and restores are yours to trigger from the panel: no ticket, no queue, and no waiting for office hours that do not exist here anyway.

  • Edge DDoS filtering ahead of every account
  • Account isolation with per-user PHP
  • 99.9% uptime written into the SLA
  • Daily backups with self-service restores

Worth Knowing

More of what comes with it

Backups you can actually restore

A daily copy only helps if you can put it back. Restores run from the panel, without opening a ticket.

A panel that makes sense

Files, databases, mail, DNS and installers in one place, kept on a current release.

Move up without moving out

Upgrade when the site needs it; your files, settings and address all stay exactly where they are.

Nothing holding you here

Your data exports the same way it arrived, and we will help you pack if it comes to that.

Speed you never configure

Every site runs on NVMe with caching already switched on at the server — nothing for you to tune.

Certificates included

SSL is bundled and self-renewing on every domain, so encryption never turns into an upsell.

Starting Out

Three steps and you're set up

  1. 1

    Choose your tier

    Take any plan — the protections are identical across every tier.

  2. 2

    Bring your domain

    Point the domain; SSL is fitted and renewed automatically.

  3. 3

    Open for business

    Move in free, then let the patching, filtering and backups get on with it.

On the Shelf

Also included, no extra charge

  • Every hosting plan comes with 30 days to change your mind
  • Patching handled fleet-wide by our engineers
  • Self-service restores from daily backups
  • Move up a tier without moving your files
  • Registered in the UK, priced in US dollars
  • Built for owners who treat protection as part of the job
  • Free SSL on every domain you host
  • Migration done by our engineers, no charge

Still Asking

A few more we hear often

What happens if my site is compromised anyway?

Tell our desk and we help. There is a daily backup to restore from, logs that show when the change happened, and engineers who will help you find the plugin or password that let it in. Nobody suspends you and walks away, and the restore costs nothing extra.

Is there a wait after I order?

Minutes after checkout. A migration from another host adds a day at most and costs nothing — our engineers handle files, databases, mail and DNS.

Is there a charge for certificates?

Free, fitted and self-renewing. The only reasons to buy a certificate here are a wildcard or a validated seal for procurement.

What if secure web hosting is not the right fit?

There is a 30-day money-back guarantee on the plan. Ask inside the month and you get your money back: no exit interview, and nobody transferring you to a team whose job is talking you out of it.