Defence Built In
A guard posted at the door, day and night
Each plan arrives with a managed WAF, Imunify360 malware scanning, DDoS filtering, free SSL, daily backups and 24/7 monitoring already switched on. No add-ons, no upgrade to buy.
Free
Each domain you add gets SSL
Daily
Backups taken without asking
24/7
Eyes on the platform, always
Layer 7
Firewall and DDoS filtering
Defence In Layers
Six layers stand between an attacker and your site
The sort of protection you'd normally shop around for and pay extra to add. Here it's priced into the plan from day one.

Application firewall (WAF)
Before a request meets your code, it is held against a library of attack patterns that never stops being refreshed. SQL injection gets caught on the way in. So does cross-site scripting, along with the other well-known exploits.
Malware scanning by Imunify360
Inspection of your files runs without pause, and an infected one is put in quarantine the moment it shows up. Plugins that have fallen behind get a virtual patch to shield them until you update.
DDoS filtering
Out at the network edge, traffic is read and sorted: heavy floods and malicious packets are pulled out well before they ever arrive at your server. A genuine visitor notices none of it.
Free SSL that renews itself
Each domain on the account gets its own certificate, renewed for you before it lapses, so the connection stays encrypted and the padlock never falls off the address bar.
Backups every day
Once a day, files and databases are copied away to storage off the server, which leaves you a known-good point to fall back on inside minutes.
Watched around the clock
Server health, uptime and intrusion attempts are watched by automated systems and by people, hour after hour, day after day, all the way through the year.

Firewall
Attacks sent packing at the door
Every request is read by the firewall before your code ever sees it. Bad payloads get turned back at the edge, probing bots with them, and a real visitor carries on without noticing a thing. No plugin to install. No rules for you to write.
- Injection and XSS attempts stopped dead
- Known bad bots and exploits screened out
- Abusive traffic throttled automatically
- Tuned and managed on your behalf

Malware Scanning
Imunify360 gets there before the spread does
Your files are under the eye of Imunify360 without a break. Find malicious code and it isolates the file, flags it up for you, and boxes the trouble in before it has a chance to travel. Virtual patching covers software you have not updated yet, holding the line until you are ready.
- Scanning that runs nonstop and on upload
- Bad files quarantined without your input
- Virtual patches over out-of-date plugins
- Plain alerts waiting in your dashboard
Layers In Action
How each layer hands over to the next one
No single safeguard catches everything alone. Here's the handoff between them, so an attacker has to beat all six rather than one.

- 1
DDoS filtering meets the traffic first
Heavy floods and obvious junk get soaked up and dropped right at the edge of the network, never reaching your server, and your uptime holds.
- 2
The firewall reads what's left
Anything that survives that stage walks into the managed WAF, where injection attempts, cross-site scripting and the rest of the exploits aimed at your application are turned back.
- 3
Isolation keeps any damage boxed in
Each site sits in a walled-off environment of its own, which leaves trouble on a neighbouring account, sharing the same server, with nowhere to travel.
- 4
Imunify360 inspects every file that lands
Whatever gets written to disk is scanned on arrival. Infected files land in quarantine without anyone lifting a finger, and software left out of date collects a virtual patch.
- 5
SSL seals every connection
Every exchange between a visitor and the site is encrypted end to end, which means nothing in transit can be read or altered on the journey.
- 6
Daily backups catch whatever slips past
Should something still slip past all that, the daily off-server backups put the entire site back to a known-good point within minutes.
Plans
Every tier gets the same security
The full security stack ships with all three tiers. Take the size your site needs today and move up when it grows.
Launch
Room for a single website, live today, at the plainest price we quote anywhere
$2.42/mo
$29.04 today · billed annually
the renewal price is the same
- SSD storage
- 10 GB
- Websites
- 1
- Bandwidth
- 500 GB
- CPU / RAM
- 1 core / 2 GB
- Databases
- 25 MySQL
- We register your domain name and charge nothing for the first year
- Your SSL certificate costs nothing, and we reissue it before expiry
- Sitting with another host? We move the site over at no charge
- An AI site builder comes with it: describe the site, then publish
- WordPress Toolkit included, and a backup runs daily
- SSH, Git and Composer at the command line
- Softaculous puts 240+ apps up in one click
- ImunifyAV+ watches every site for malware
- NVMe SSD underneath, LiteSpeed cache in front
- Mailboxes on your own domain, included
- MailChannels carries your outbound mail
- The latest cPanel, and real people to answer
- The account is live minutes after you order
Orders are rung up on Hosting Cheap, which is the billing platform behind our checkout.
Pro
One account, and enough shelf space on it for twenty-five separate sites
$4.66/mo
$55.92 today · billed annually
the renewal price is the same
- SSD storage
- 20 GB
- Websites
- 25
- Bandwidth
- 1 TB
- CPU / RAM
- 1 core / 2 GB
- Databases
- 50 MySQL
- First year of domain registration is on us, with nothing to pay
- SSL comes free, with a fresh certificate issued before the old lapses
- Already with another provider? We carry the site over and bill nothing
- An AI site builder is thrown in: say it, publish it
- WordPress Toolkit, plus a backup taken for you daily
- SSH, Git and Composer at the command line
- Softaculous puts 240+ apps up in one click
- ImunifyAV+ watches every site for malware
- NVMe SSD underneath, LiteSpeed cache in front
- Mailboxes on your own domain, included
- MailChannels carries your outbound mail
- The latest cPanel, and real people to answer
- The account is live minutes after you order
Orders are rung up on Hosting Cheap, which is the billing platform behind our checkout.
Elite
200 GB of NVMe storage, with enough processing power behind it to keep up
$7.08/mo
$84.96 today · billed annually
the renewal price is the same
- SSD storage
- 200 GB
- Websites
- 100
- Bandwidth
- 2 TB
- CPU / RAM
- 2 cores / 4 GB
- Databases
- 100 MySQL
- We register your domain name, free for the first year
- WordPress Toolkit Deluxe sits on the plan, nothing added
- Imunify360 watches the account, and a backup lands every 6 hours
- CloudLinux Pro with PHP X-Ray, which traces the slow code
- Python, Node.js and Ruby runtimes, installed and ready
- Priority support, whatever hour you need it
- An SSL certificate at no cost, renewed by us ahead of its expiry
- Currently parked with another host? We migrate the site for nothing
- An AI site builder is bundled in. Describe the thing, publish it
- NVMe SSD underneath, LiteSpeed cache in front
- SSH, Git and Composer at the command line
- Softaculous puts 240+ apps up in one click
- The account is live minutes after you order
Orders are rung up on Hosting Cheap, which is the billing platform behind our checkout.
Extra Safeguards
Three further things at work in the background

Brute-force lockouts
Fail a login often enough and throttling kicks in, then an IP block. Bots battering your admin or mail passwords get shut out before they make progress.
Patched ahead of the exploit
The moment a vulnerability goes public, a virtual patch closes it at the firewall. That often happens before the software vendor has an official fix out of the door.
Accounts kept apart
Walls sit between your account and every other account on that server, which leaves a problem next door with no road through to your site.

Recovery & Uptime
Daily copies, plus someone watching
Even sound defences need something to fall back on. A backup runs itself every day, which puts the whole site back inside minutes, and the monitoring never looks away from uptime or intrusion attempts, with people ready to step in when the alert goes off.
- Daily backups held off-server
- Whole-site restore in one click
- Monitoring that never clocks off
- Free SSL that renews itself
How It Works
Secured in three straightforward steps

- 1
Choose a plan
Take any tier you like and the WAF, malware scanning, DDoS filtering and daily backups are running before you arrive. Nothing to bolt on afterwards.
- 2
Bring the site across
Aim your domain at us, or hand the migration over and we will carry the site across for nothing. SSL is issued the minute the site goes live.
- 3
Leave it to run
Look in on clean scan results and uptime from the dashboard whenever the mood takes you. Underneath, monitoring and backups keep working without a word.
Included
Everything listed below comes with every plan
- A managed WAF in front of your site
- Imunify360 malware scanning
- Infected files quarantined automatically
- DDoS filtering at network level
- Free SSL, renewed on its own
- Off-server backups taken daily
- Restores in a single click
- Brute-force login protection
- Hosting accounts walled off from each other
- Monitoring and support at any hour
FAQ
Straight answers on secure hosting
Which attacks does the firewall actually turn away?
Every request is weighed against a library of known attack signatures before it can touch your site's code, and that library is kept current by us rather than by you. SQL injection aimed at your database gets picked up. So do cross-site scripting payloads written to hijack a visitor's session, remote file inclusion, directory traversal and command injection. Abusive bots are strained out too, along with credential-stuffing scripts and traffic sniffing around for well-known plugin or theme weaknesses. Writing a rule is never your job. We tune the firewall and update it as fresh threats appear. Real visitors come through with no delay and no friction, while harmful requests are dropped at the edge, so your server is spared the work of processing them. In practice a large share of common attacks gets nowhere near your application, your database or your files.
How does malware scanning spot an infection in practice?
Imunify360 comes as standard on every secure plan. It works away in the background without stopping, and it looks again the instant a file is uploaded or edited. Find something malicious, whether a planted backdoor, a defaced page, a phishing kit or a script pumping out spam, and that file goes straight to quarantine, where the trouble sits still instead of spreading across the account. Your dashboard lists what turned up and where it was hiding, and you can inspect or restore any of it yourself. Detection is only half the story. Virtual patching covers out-of-date plugins and themes against known exploits until you get round to updating, which shuts the gap attackers normally aim for. Since the scanning never pauses, rather than running once a day, most problems are caught and closed down within minutes, so the site stays clean and your visitors stay out of trouble.
Is that free SSL certificate genuinely free, with no catch?
Yes. No trial window, no first-year-only offer, no upsell lurking at the end of it. Every domain and subdomain on a secure plan picks up an SSL certificate as it goes live, and the certificate renews itself ahead of expiry for as long as you host here. That padlock your visitors look for stays put. No bill for it ever lands, and no renewal reminder either. The job SSL does is encrypt the link between visitor and server, so login details, contact-form submissions, checkout information and anything else typed into your pages stay private on the way through. Search rankings count it as well, and it keeps browsers from pinning a 'Not secure' label on you. Setting it up is not your problem: the certificate is issued and kept current for you, so the site is encrypted from its first day online.
How often does a backup run, and can I restore it myself?
A backup runs every day on its own, and each copy is held off-server, well away from the machine it exists to protect. Files and databases are taken together, so what comes back is a whole working copy of the site rather than parts you have to bolt together yourself. Restoring is entirely in your hands. Open the dashboard, pick a recovery point, and roll back the whole account, one site, or a single database. It takes a few clicks and is usually done inside minutes. That makes the daily copy the answer to nearly everything that goes wrong: a broken update, a bad edit, a file deleted by mistake, or worse than any of those. Nobody has to remember to start one. Because the copies sit off-server, they are still there waiting even when the live environment runs into trouble.
Does DDoS protection add any lag to my site?
No. The filtering sits out at the network edge, a long way ahead of your server, and it reads the volume and shape of what is arriving rather than pulling apart every page request. Real visitors are waved through with not a millisecond added to their load time. A barrage of packets sent to swamp the site, on the other hand, is absorbed and stripped out before it ever touches your hosting. That filtering capacity spans the whole network rather than a single machine, which is why it can soak up attacks far bigger than one server could ever cope with. For you it means a site that carries on trading through an attack that would knock an unprotected one clean offline. There is nothing to enable and nothing to configure. It is on by default across every plan, guarding your uptime whether or not anyone is aiming at you today.
What exactly does round-the-clock monitoring watch for?
Two things do the watching: automated systems, and people looking at the platform every hour of every day. The automated half tracks server health, uptime, resource usage, disk and network activity, and the known signatures of an intrusion, firing an alert the second anything looks wrong. Someone then reads that alert and starts looking into it, rather than waiting until you notice and open a ticket. Hardware faults come up that way. So do odd traffic spikes, repeated failed logins and the other small signs of trouble, which is why a problem is often settled before a single visitor meets it. Next to the firewall, the malware scanning and the daily backups, this is the layer keeping watch while you sleep or work on something else. Spot it first yourself and the same 24/7 support team is one message away, ready to dig in beside you.
More hosting worth a look
Web Hosting
Our main cPanel platform, sitting on the quick NVMe stack these plans run on.
SSL Certificates
SSL at no cost, renewing itself, with every connection to your site encrypted.
WordPress Hosting
Managed WordPress with the same WAF and malware scanning running beneath it.
Business Hosting
Extra resources and headroom for growing sites that take security to heart.
Get a security team standing behind your site.
Managed WAF, malware scanning, DDoS filtering, free SSL, daily backups and monitoring at any hour — all in the price.
View Secure PlansMost sites are attacked by scripts, not by people. Scripts are beaten by patching, filtering and backups, all of which should be running long before you think to ask about them. It runs on NVMe arrays with LiteSpeed in front, in data centres with conditioned power and more than one road to the internet.
A good fit for owners who treat protection as part of the job. The certificate is free, the move is free, the backups run themselves, and support answers in minutes whatever the clock says.
Protection that is already switched on
DDoS filtering happens at the network edge, so junk traffic never reaches your account at all. Accounts are isolated from one another, PHP runs per user, and kernel, panel and PHP patches are applied across the fleet by our engineers as releases land. Free SSL covers everything travelling between visitor and server.
None of that depends on which tier you buy. NVMe storage, LiteSpeed with HTTP/2 and the 99.9% uptime SLA are the same on the cheapest plan and the largest one.
What the hardening covers
You can compare Hosting Seller properly because nothing is hidden to compare. The listed price already includes the certificate, the migration, the backups and the support — the parts other hosts add on later. Every hosting plan carries a 30-day money-back guarantee, so trying us out costs you an afternoon at worst.
Security here is not a tier you climb towards. Filtering, isolation, patching, certificates and daily backups sit on every plan, including the one that starts at $2.42 a month.

The layers between your site and the internet
Sites live in our London datacentre behind edge filtering, on NVMe storage with a backup taken every day. Restores are yours to run from the panel, so a bad plugin or a bad afternoon costs minutes rather than a rebuild.
Backups run daily and restores are yours to trigger from the panel: no ticket, no queue, and no waiting for office hours that do not exist here anyway.
- Edge DDoS filtering ahead of every account
- Account isolation with per-user PHP
- a 99.9% uptime target credited against the SLA
- Daily backups with self-service restores
Worth Knowing
What else you get in the box
Backups you can actually restore
A daily copy only helps if you can put it back. Restores run from the panel, without opening a ticket.
A panel that makes sense
Files, databases, mail, DNS and installers in one place, kept on a current release.
Move up without moving out
Upgrade when the site needs it; your files, settings and address all stay exactly where they are.
Nothing holding you here
Your data exports the same way it arrived, and we will help you pack if it comes to that.
Speed you never configure
Every site runs on NVMe with caching already switched on at the server — nothing for you to tune.
Certificates included
SSL is bundled and self-renewing on every domain, so encryption never turns into an upsell.
Starting Out
From order to live in three steps
- 1
Choose your tier
Take any plan — the protections are identical across every tier.
- 2
Bring your domain
Point the domain; SSL is fitted and renewed automatically.
- 3
Open for business
Move in free, then let the patching, filtering and backups get on with it.
On the Shelf
Also included, no extra charge
- Every hosting plan comes with 30 days to change your mind
- Patching handled fleet-wide by our engineers
- Self-service restores from daily backups
- Move up a tier without moving your files
- Registered in the UK, priced in US dollars
- Built for owners who treat protection as part of the job
- Free SSL on every domain you host
- Migration done by our engineers, no charge
Still Asking
Other questions that keep coming up
What happens if my site is compromised anyway?
Tell our desk and we help. There is a daily backup to restore from, logs that show when the change happened, and engineers who will help you find the plugin or password that let it in. Nobody suspends you and walks away, and the restore costs nothing extra.
Is there a wait after I order?
Minutes after checkout. A migration from another host adds a day at most and costs nothing — our engineers handle files, databases, mail and DNS.
Is there a charge for certificates?
Free, fitted and self-renewing. The only reasons to buy a certificate here are a wildcard or a validated seal for procurement.
What if secure web hosting is not the right fit?
There is a 30-day money-back guarantee on the plan. Ask inside the month and you get your money back: no exit interview, and nobody transferring you to a team whose job is talking you out of it.
Read next
SSL Certificates
Free and paid certificates that renew themselves.
Mail Filtering
Spam stopped before it ever reaches the inbox.
Web Hosting
cPanel on NVMe from $2.42/mo, SSL and the move included.
Pulled from the Resource Library
How to Secure Your Hosting Account
Account-level hardening most owners never get round to.
How to Scan a Site for Malware
Spotting trouble ahead of Google's blocklist.
What is a WAF?
The web application firewall, defined without mystique.