Security

Protecting your account, your site and your visitors.

11 articles

Account security

Website security

  • Website security basics for small sites

    The handful of habits that prevent most website compromises on shared hosting: updates, logins, permissions, HTTPS, backups and fewer moving parts.

    ExplainerBeginner
  • Keeping website software updated

    Why updates are the most important security task, what needs updating beyond the CMS itself, and a routine that keeps a small site current.

    How-to guideBeginner
  • Brute-force login attacks: how to recognise and stop them

    Spot automated login attacks in your access log and stop them wasting resources, with login limits, xmlrpc blocking and strong passwords.

    How-to guideIntermediate
  • How to password-protect a folder Filed under DirectAdmin

    Adding a username and password prompt to any folder of your website with DirectAdmin’s password protected directories.

    How-to guideIntermediate
  • How to secure a WordPress site Filed under WordPress

    A practical WordPress security checklist for shared hosting: updates, logins, users, file permissions, wp-config.php and backups.

    How-to guideIntermediate
  • Keeping your databases secure Filed under Databases

    Protect your website’s databases: separate users, strong passwords, prepared statements, safe credential storage and backups.

    How-to guideIntermediate
  • File permissions explained (644, 755 and why never 777) Filed under Files & FTP

    What Linux file permissions mean, the correct values for website files and folders, and how to change them in DirectAdmin.

    How-to guideIntermediate
  • Storing configuration and secrets outside public_html Filed under Developer tools

    Keep database passwords, API keys and SMTP credentials out of the web root with config files above public_html, .env files and protective .htaccess rules.

    How-to guideIntermediate
  • Adding security headers with .htaccess Filed under Developer tools

    Add HTTP security headers — HSTS, X-Content-Type-Options, Referrer-Policy, frame protection and Permissions-Policy — safely with .htaccess.

    How-to guideAdvanced

When something is wrong

  • How to clean a hacked WordPress site

    A step-by-step recovery for a compromised WordPress site: contain it, restore or clean, close the way in, and check it’s clean afterwards.

    How-to guideAdvanced
  • My website has been hacked: what to do

    The signs a site is compromised and a clear recovery order: contain, preserve, restore or clean, close the hole, and check search engines.

    TroubleshootingIntermediate
  • Website redirecting to spam or scam sites

    Why a site redirects some visitors to spam, where the redirect code usually hides — .htaccess, PHP files, the database, JavaScript — and how to remove it.

    TroubleshootingIntermediate
  • How to find malicious files on your website

    Practical ways to spot injected and backdoor files: PHP where it shouldn’t be, recently modified files, obfuscated code and comparisons with clean copies.

    How-to guideAdvanced
  • My email account is sending spam

    Signs a mailbox has been compromised, how to secure it, check for rules and forwarders an attacker added, and recover your sending reputation.

    TroubleshootingIntermediate

Learn it step by step

Popular

Tip: press / to search from any pageSee all results