r/webhosting 22h ago

Advice Needed Hosting change after hacker attack

Over the last year my website got hacked twice, maybe cuz of an outdated plugin, there is nothing unusual in the website, just a regular business page. Can the hosting provider somehow save from hacking?

I'm now on GoDaddy, checkin out Host inger, they seem pretty popular - seen that they're fast and secure, but Idk how to check if this is true.

Who was hacked, did changing the hosting help reducing the risk?

3 Upvotes

20 comments sorted by

9

u/IxBetaXI 21h ago

No unless you pay them for doing it.
You get hacked twice because you messed up twice.

Either you have to keep the website secure or pay someone doing it.

The Hostingprovider doesn't protect you.

6

u/VeruseXM 21h ago

most shared hosts will provide you with something like Imunify360. I work for a fairly large hosting company and malware removal does fall out of our support remit as your responsible for what you have running on your hosting account. it may not be the same for everywhere but we do provide a lot of guidance. im not name dropping it for obvious reasons but I imagine the amount of help with this can change depending on the company.

4

u/wegwerfi08 20h ago

Change the plugin not the hosting

4

u/TheExG 19h ago

If you are being hacked multiple times, I would say 95% of the time it’s likely your fault in some way. Yes hosting providers get hacked all the time, but most of the recent malware found on websites have been due to security flaws within the website itself. You need to teach yourself some basic security and also ensure you have daily backups stored on offsite servers.

3

u/mxroute 22h ago

They "can" but you should make no assumption that they will. It's up to you to keep your software secure. Going around updating people's software without their involvement risks breaking websites, and a WAF should be thought of as a courtesy.

2

u/harrymurkin 20h ago

"In 2024, the gap between a vulnerability being discovered and it being exploited was two months. By 2026, that window collapsed to just eight hours."

Platform Resilience to defend against accelerated threats.

2

u/Grumpy-Man19 19h ago

popular does not mean the best , only that they advertise the most. we don't advertise but our customers never leave us because we are trouble free.

2

u/corobo 19h ago

If you switch to managed hosting, maybe. Depends what they offer. It's gonna cost a bit more though.

Unmanaged hosting is gonna be on you wherever it's at 

2

u/Rado_Scala 18h ago

Website security is always a shared responsibility between the provider and the client. You can be at the best provider, pay thousands of dollars for security, but if you keep adding vulnerable plugins or keep weak passwords - no one can help you. Sure, some providers are better at keeping secure networks and some hosting services give you more security out-of-the-box, but that never takes the responsibility to keep your online premises safe off your shoulders.

As for malware cleanup, as this often requires development work, most providers can provide such a service for an extra fee. Still, it's always best to go for a provider with above average support as they can help you easily detect the issue and give valuable advice as to what you can do fix it and mitigate the risks in the future.

2

u/HostNocOfficial 17h ago

Changing hosts can help, but it won’t fix an outdated plugin or vulnerable code by itself. You can keep WordPress, plugins, themes, and PHP updated, and use strong authentication, backups, and server-level security. The host matters, but ongoing maintenance matters just as much.

2

u/Bitter_Anteater2657 16h ago

You shouldn’t be using just one source for protection. You need to keep things updated. Tons of security vulnerabilities are found everyday and it’s just going to stay like this as long as ai is running. The last few updates to WordPress for example patched remote code execution issues where people could just upload arbitrary code and have it run. Same is true if you’re using JS and it’s popular frameworks too(maybe not in its most recent updates but I know it was recently lol).

Keep your core version and plugins updated and use something like cloudflare. Then just let the host focus on protecting the hosting side, it’s what managed hosts are (or should be) good at.

2

u/TinyNiceWolf 15h ago

Outdated plugin? Don't you have things configured to automatically back up your site and update it whenever a new version of anything is available? My hosting provider does this automatically. It supposedly restores the old site automatically if an update goes wrong, but in many years, I've never had an update go wrong enough to be worth not installing it.

2

u/bribir123 15h ago

No, since the hosting provider doesn't have anything with hacking. It's your responsibility.

2

u/sleekpixelwebdesigns 9h ago

The issue is WordPress, not sure why people still use it.
Because WordPress powers so many websites, it is a popular target for automated attacks and malicious bots.

-1

u/Sharp_Complaint3637 22h ago

Yes. I offer Patchstack integration on my hosting, so outdated plugins receive virtual patches. It is possible.