30 days free — a full hosting account, no card required. Then £0.99/month, community-supported. 30 days free, no card. Then £0.99/mo, community-supported.

Start free
🔒 Security & SSL

Security & SSL

Certificates, HTTPS, and keeping your site locked down.

SSL certificates are issued and renewed automatically for domains pointed at Traxio, so for most people this section is about confirming it worked and forcing traffic to use it. The articles here cover enabling SSL, redirecting HTTP to HTTPS, and the basic security practices that prevent the majority of site compromises.

The single highest-value habit is keeping WordPress core, themes and plugins updated. Outdated plugins account for the overwhelming majority of hacked shared-hosting sites, far ahead of anything involving the server itself. Website Security Basics covers the rest in more depth.

Yes to both. Certificates are issued through Let's Encrypt at no charge and renew automatically about 30 days before expiry. There is no charge for SSL at any point, and never will be — certificates have been free since 2016.
Keep WordPress core, themes and plugins updated. Outdated plugins account for the overwhelming majority of compromised sites on shared hosting, far ahead of anything involving the server itself. Delete plugins you are not using rather than just deactivating them.
Usually DNS has not propagated yet — validation requires your domain to actually reach our servers. Other causes are a CAA record naming a different certificate authority, a Cloudflare proxy intercepting the validation request, or an .htaccess rule catching the /.well-known/ path.