Keeping Your Website Safe and Secure
Websites are an essential part of how many organisations communicate, provide services, and conduct business. As our reliance on online technology increases, attackers also continue to look for new opportunities to exploit vulnerable websites, applications, and user accounts.
No website can be guaranteed to be completely immune from attack. However, combining secure hosting with good website management can significantly reduce the risk.
This guide explains the protections Hipposerve provides and the important steps you should take to help keep your website, account, and visitors safe.
What Hipposerve Does to Protect Your Website
Hipposerve uses several layers of protection across its managed hosting platform. These measures are designed to reduce common security risks, isolate hosting accounts, protect important server functions, and help customers recover if something goes wrong.
Our protections include:
- Hipposerve® Rewind backups, with seven days of backup history included as standard on eligible hosting plans.
- Extended backup-retention options of 30, 180, or 365 days for customers who need longer recovery periods.
- Hipposerve® Sentinel protection to help detect and respond to suspicious website activity.
- CageFS account isolation, which helps separate individual hosting accounts from other users on the server.
- Restrictions on potentially dangerous PHP functions that are not normally required by websites.
- Restricted direct server access on hosting services where SSH access is not required.
- Server and hosting-platform security controls.
- Regular operating-system, control-panel, and service updates.
- Ongoing reviews of our security systems and procedures.
- Continued development of new tools and protections as threats change.
For security reasons, we do not publish the complete technical configuration of our hosting platform. We continually monitor, review, patch, and improve our systems to help keep customer websites safe.
Please note: Backups provide an important recovery option, but they should not be treated as a replacement for keeping your website secure and up to date.
What Hipposerve Cannot Protect
Hipposerve protects the hosting environment, but the website application and its user accounts must also be managed securely.
Think of it like renting a property. The landlord can provide strong doors, locks, and an alarm system, but those protections cannot help if somebody leaves the front door open or gives their key to the wrong person.
The same principle applies to websites. Even a well-protected hosting platform can be undermined by:
- Weak or reused passwords.
- Compromised administrator accounts.
- Outdated website software.
- Vulnerable or abandoned plugins, themes, modules, and extensions.
- Untrusted software or code.
- Unused administrator accounts that still have access.
- Compromised computers or email accounts.
- Website code containing security vulnerabilities.
The maintenance and security of your website application remain the responsibility of you or your website developer. This includes WordPress and any other content-management system, e-commerce platform, custom application, plugin, theme, module, or extension installed within your hosting account.
Protect Your Hipposerve Account
Your Hipposerve account provides access to important services, settings, and information. Protecting this account should be one of your first priorities.
- Use a strong password that you do not use anywhere else.
- Store passwords securely using a reputable password manager.
- Enable two-factor authentication.
- Never share your login details by email or messaging services.
- Check that the email account linked to Hipposerve is also protected by a strong password and two-factor authentication.
- Review your account information regularly and remove access that is no longer required.
For instructions, see Setting Up Two-Factor Authentication.
Protect Your Website Login
If your website has an administration area, protect it with a strong and unique password. Enable two-factor authentication whenever the website application supports it.
Do not reuse your Hipposerve, email, or website-administrator password on another service. If one service is compromised, a reused password may give an attacker access to several accounts.
Only provide administrator access to people who genuinely need it. Other users should receive the lowest level of access required to perform their work.
Secure Your WordPress Installation
If you use WordPress, Hipposerve® WordPress Manager includes security measures that can help harden your installation and reduce common risks.
For instructions, see Securing Your WordPress Installation.
Security hardening is an important additional layer of protection, but it does not replace secure passwords, software updates, backups, and careful user management.
Keep WordPress Up to Date
WordPress, its plugins, and its themes should all be kept up to date. Updates frequently include security fixes, compatibility improvements, and corrections for known problems.
Hipposerve® WordPress Manager allows you to update WordPress and enable automatic updates for WordPress core, plugins, and themes.
For instructions, see Keeping Your WordPress Installation Up to Date.
After an update, check your website to confirm that its pages, forms, checkout, and other important features continue to work correctly.
Manage Your WordPress Plugins and Themes
Only install plugins and themes that your website genuinely needs. Every additional component requires maintenance and may create another potential security risk.
- Install plugins and themes only from trusted sources.
- Keep all active components up to date.
- Remove plugins and themes that are no longer required.
- Avoid components that are no longer actively maintained.
- Do not use unauthorised, modified, or “nulled” premium plugins and themes.
- Take a backup before performing significant updates or removals.
- Use a staging website to test major changes whenever possible.
If a paid plugin or theme licence expires, you may stop receiving updates. To continue receiving security and compatibility updates, you may need to renew or repurchase the licence from its developer.
For further guidance, see Managing Your WordPress Plugins.
Review Your WordPress Users
Review the users with access to your WordPress administration area regularly. A developer, employee, or contractor who worked on the website several years ago may still have an active account.
- Remove accounts that are no longer required.
- Limit the number of administrators.
- Give each person their own account rather than sharing login details.
- Use the lowest suitable WordPress role for each user.
- Check that every administrator uses a strong, unique password.
- Enable two-factor authentication for administrators whenever possible.
Important: A WordPress administrator can make significant changes to your website, install software, manage other users, and access sensitive information. Administrator access should only be given to trusted people who require it.
Protect Non-WordPress Websites
The same basic security principles apply if your website uses another content-management system, an e-commerce platform, or custom code.
- Keep the website application and all dependencies up to date.
- Update themes, modules, extensions, libraries, and frameworks.
- Remove unused applications, test files, development tools, and old website copies.
- Use strong, unique passwords and two-factor authentication wherever available.
- Give users only the access they need.
- Store passwords, API keys, and other credentials securely.
- Do not place passwords or secret keys inside publicly accessible files.
- Use supported versions of PHP and other server-side software.
- Ask your developer to review custom code for security issues.
- Test important changes on a staging website before applying them to the live site.
If your website is no longer actively maintained, speak to your developer about arranging regular maintenance or replacing unsupported software.
Protect the Devices and Email Accounts You Use
Website security also depends on the computers, phones, and email accounts used to manage it.
- Keep computers, phones, browsers, and security software up to date.
- Protect devices with a password, PIN, fingerprint, or facial recognition.
- Use two-factor authentication on important email accounts.
- Be cautious of unexpected login links, attachments, and password-reset messages.
- Do not manage your website from a shared or untrusted computer.
- Avoid entering passwords while connected to an untrusted public network.
An attacker who gains access to an administrator’s email account or computer may be able to reset website passwords and bypass other protections.
Check Your Website Regularly
Regular checks can help you identify a problem before it becomes more serious.
- Visit the website regularly and test its important features.
- Check forms, payment pages, and customer-account areas.
- Look for unexpected pages, users, redirects, pop-ups, or changes.
- Review security and update notifications.
- Investigate unexpected increases in traffic, storage, or resource usage.
- Make sure your contact details are current so you receive important notices.
Use Backups as Part of Your Security Plan
Backups can help you recover from a failed update, accidental deletion, website problem, or security incident.
Hipposerve® Rewind provides seven days of backup history as standard with eligible hosting plans. Longer retention options may be available if your organisation needs additional recovery points.
Consider how quickly you would notice a problem. If a compromised website might remain undetected for more than seven days, a longer backup-retention period may be appropriate.
You should also keep independent copies of any business-critical website content or data that cannot easily be recreated.
If You Notice Something Suspicious
If you notice an unexpected change, unfamiliar administrator, suspicious redirect, security warning, or other unusual behaviour, do not ignore it.
- Avoid making unnecessary changes that could remove useful evidence.
- Change compromised passwords from a trusted device.
- Record what you noticed and when it occurred.
- Contact your website developer if the issue involves the website application.
- Contact Hipposerve support if you need help with your hosting service.
Please visit the Hipposerve Support Centre if you need further assistance.