r/webhosting • u/Arkupathak • 22h ago
Advice Needed Hosting change after hacker attack
Over the last year my website got hacked twice, maybe cuz of an outdated plugin, there is nothing unusual in the website, just a regular business page. Can the hosting provider somehow save from hacking?
I'm now on GoDaddy, checkin out Host inger, they seem pretty popular - seen that they're fast and secure, but Idk how to check if this is true.
Who was hacked, did changing the hosting help reducing the risk?
6
u/VeruseXM 21h ago
most shared hosts will provide you with something like Imunify360. I work for a fairly large hosting company and malware removal does fall out of our support remit as your responsible for what you have running on your hosting account. it may not be the same for everywhere but we do provide a lot of guidance. im not name dropping it for obvious reasons but I imagine the amount of help with this can change depending on the company.
4
4
u/TheExG 19h ago
If you are being hacked multiple times, I would say 95% of the time it’s likely your fault in some way. Yes hosting providers get hacked all the time, but most of the recent malware found on websites have been due to security flaws within the website itself. You need to teach yourself some basic security and also ensure you have daily backups stored on offsite servers.
2
u/harrymurkin 20h ago
"In 2024, the gap between a vulnerability being discovered and it being exploited was two months. By 2026, that window collapsed to just eight hours."
2
u/Grumpy-Man19 19h ago
popular does not mean the best , only that they advertise the most. we don't advertise but our customers never leave us because we are trouble free.
2
u/Rado_Scala 18h ago
Website security is always a shared responsibility between the provider and the client. You can be at the best provider, pay thousands of dollars for security, but if you keep adding vulnerable plugins or keep weak passwords - no one can help you. Sure, some providers are better at keeping secure networks and some hosting services give you more security out-of-the-box, but that never takes the responsibility to keep your online premises safe off your shoulders.
As for malware cleanup, as this often requires development work, most providers can provide such a service for an extra fee. Still, it's always best to go for a provider with above average support as they can help you easily detect the issue and give valuable advice as to what you can do fix it and mitigate the risks in the future.
2
u/HostNocOfficial 17h ago
Changing hosts can help, but it won’t fix an outdated plugin or vulnerable code by itself. You can keep WordPress, plugins, themes, and PHP updated, and use strong authentication, backups, and server-level security. The host matters, but ongoing maintenance matters just as much.
2
u/Bitter_Anteater2657 16h ago
You shouldn’t be using just one source for protection. You need to keep things updated. Tons of security vulnerabilities are found everyday and it’s just going to stay like this as long as ai is running. The last few updates to WordPress for example patched remote code execution issues where people could just upload arbitrary code and have it run. Same is true if you’re using JS and it’s popular frameworks too(maybe not in its most recent updates but I know it was recently lol).
Keep your core version and plugins updated and use something like cloudflare. Then just let the host focus on protecting the hosting side, it’s what managed hosts are (or should be) good at.
2
u/TinyNiceWolf 15h ago
Outdated plugin? Don't you have things configured to automatically back up your site and update it whenever a new version of anything is available? My hosting provider does this automatically. It supposedly restores the old site automatically if an update goes wrong, but in many years, I've never had an update go wrong enough to be worth not installing it.
2
u/bribir123 15h ago
No, since the hosting provider doesn't have anything with hacking. It's your responsibility.
2
u/sleekpixelwebdesigns 9h ago
The issue is WordPress, not sure why people still use it.
Because WordPress powers so many websites, it is a popular target for automated attacks and malicious bots.
-1
u/Sharp_Complaint3637 22h ago
Yes. I offer Patchstack integration on my hosting, so outdated plugins receive virtual patches. It is possible.
9
u/IxBetaXI 21h ago
No unless you pay them for doing it.
You get hacked twice because you messed up twice.
Either you have to keep the website secure or pay someone doing it.
The Hostingprovider doesn't protect you.