Security
Protecting your account, your site and your visitors.
11 articles
Account security
- Hosting account security checklist
Protect your Traxio client area, DirectAdmin, email, FTP and database logins with a practical checklist — and what to do after a suspected breach.
- Strong passwords and password managers
What actually makes a password strong, why reuse is the real danger, and how a password manager makes unique passwords effortless.
- Recognising phishing emails that pretend to be your host
How to spot fake ‘account suspended’, ‘renew your domain’ and ‘mailbox full’ emails, and how to check a message is genuine.
- How to change your DirectAdmin password Filed under DirectAdmin
Changing the DirectAdmin password on your hosting account, what else uses that password, and what to update afterwards.
- FTP vs SFTP: which should you use? Filed under Files & FTP
How FTP, FTP with TLS (FTPS) and SFTP differ in security and setup, and which one to use with your Traxio hosting.
Website security
- Website security basics for small sites
The handful of habits that prevent most website compromises on shared hosting: updates, logins, permissions, HTTPS, backups and fewer moving parts.
- Keeping website software updated
Why updates are the most important security task, what needs updating beyond the CMS itself, and a routine that keeps a small site current.
- Brute-force login attacks: how to recognise and stop them
Spot automated login attacks in your access log and stop them wasting resources, with login limits, xmlrpc blocking and strong passwords.
- How to password-protect a folder Filed under DirectAdmin
Adding a username and password prompt to any folder of your website with DirectAdmin’s password protected directories.
- How to secure a WordPress site Filed under WordPress
A practical WordPress security checklist for shared hosting: updates, logins, users, file permissions, wp-config.php and backups.
- Keeping your databases secure Filed under Databases
Protect your website’s databases: separate users, strong passwords, prepared statements, safe credential storage and backups.
- File permissions explained (644, 755 and why never 777) Filed under Files & FTP
What Linux file permissions mean, the correct values for website files and folders, and how to change them in DirectAdmin.
- Storing configuration and secrets outside public_html Filed under Developer tools
Keep database passwords, API keys and SMTP credentials out of the web root with config files above public_html, .env files and protective .htaccess rules.
- Adding security headers with .htaccess Filed under Developer tools
Add HTTP security headers — HSTS, X-Content-Type-Options, Referrer-Policy, frame protection and Permissions-Policy — safely with .htaccess.
When something is wrong
- How to clean a hacked WordPress site
A step-by-step recovery for a compromised WordPress site: contain it, restore or clean, close the way in, and check it’s clean afterwards.
- My website has been hacked: what to do
The signs a site is compromised and a clear recovery order: contain, preserve, restore or clean, close the hole, and check search engines.
- Website redirecting to spam or scam sites
Why a site redirects some visitors to spam, where the redirect code usually hides — .htaccess, PHP files, the database, JavaScript — and how to remove it.
- How to find malicious files on your website
Practical ways to spot injected and backdoor files: PHP where it shouldn’t be, recently modified files, obfuscated code and comparisons with clean copies.
- My email account is sending spam
Signs a mailbox has been compromised, how to secure it, check for rules and forwarders an attacker added, and recover your sending reputation.