Keeping a website secure can be hard. Many factors can lead to a site being hacked, and not all of them are related to the server or the hosting company. Here are the things you can do to reduce the risk as much as possible.
Use strong passwords #
Use at least 15 characters with a mix of letters, numbers and symbols, and make them random. A password generator or a password manager makes this easy.
Use unique passwords #
Never reuse a password on another account. If one site’s database leaks or a password is guessed, your other accounts stay safe.
Change passwords when in doubt #
If you think a password may have been exposed, change it right away. Because you do not reuse passwords, you only need to change it in one place.
Use SSL everywhere #
Without SSL, data sent from pages with logins or sensitive information can be read on the way. SSL encrypts the connection between the visitor and the server. See how to enable HTTPS and SSL.
Keep your software updated #
New security problems are found every day. Keep your website software, plugins and themes up to date, following each product’s documentation. Running old, vulnerable versions is the single biggest reason websites get hacked. Also avoid software with a poor security reputation.
Use a well-reviewed security plugin #
If your platform supports plugins, install a trusted security plugin, for example a well-known WordPress security plugin, or Admin Tools for Joomla.
Follow the official hardening guides #
Most platforms publish a security or hardening guide with best practices, for example “Hardening WordPress” in the WordPress documentation, and the security guides for Joomla, Magento and WHMCS. Search for your application’s name plus “security”.
Server security #
If you have a VPS or server, its security is your responsibility; our server management service can apply security hardening for you. On our shared hosting, Hyyat Host manages server security: we keep server software updated, use CloudLinux to isolate customer sites from each other, run a firewall with brute force protection on every server, and make it easy to use Cloudflare to block more attacks. See also brute force protection and scanning WordPress for vulnerabilities.
Related service: Secure WordPress hosting from Hyyat Host with free SSL, brute force protection and 24/7 support.

