WordPress security is shared between your host and you. Domain India secures the server your site runs on; you look after the WordPress installation itself: its plugins, themes, users and passwords. Most hacked WordPress sites are broken into through the owner's half, usually an outdated plugin or a stolen password, which no server firewall can fully fix.
This page explains who is responsible for what. For the complete step-by-step checklist, read Useful tips to secure WordPress from hackers, then The complete WordPress hardening guide.
On Domain India cPanel and DirectAdmin hosting, the server side is handled for you: each account is isolated, a web application firewall blocks many attacks, malware is cleaned automatically, and weekly backups run on cPanel and DirectAdmin. What the server cannot do is update your plugins, remove a pirated theme you installed, or stop someone who logs in with your real password. Update every week, delete what you do not use, use unique passwords with two-factor authentication, and keep your own backup off the server.
1. Who secures what
| Area | Who looks after it | What that means |
|---|---|---|
| Server software and firewall | Domain India | The server itself, the CSF firewall and brute-force protection |
| Account isolation | Domain India | CloudLinux CageFS keeps each hosting account's files separate from the others |
| Web application firewall and malware cleanup | Domain India | Imunify360 runs server-wide with the same settings for every plan |
| Weekly backups | Domain India | JetBackup 5 on cPanel and DirectAdmin, five copies kept |
| WordPress core, plugins and themes | You | Updates, removing unused or abandoned ones, never using pirated copies |
| WordPress users and passwords | You | Unique passwords, two-factor authentication, as few administrators as possible |
| Your own code and forms | You | Validating input, spam protection on forms, safe file uploads |
| Your own off-server backups | You | A copy that survives if the hosting account is lost or infected |
The server-side items were measured on our cPanel and DirectAdmin servers in September 2026. They apply to every plan, so the protection does not change when you upgrade.
2. Why server security cannot fix a site-level hole
A server firewall inspects requests and blocks known attack patterns. It cannot tell a legitimate login from an attacker who has your password, and it cannot patch the code of a plugin you installed. So these problems always come back to the site owner:
- Outdated plugins and themes. Once a security fix is published, bots scan the internet for sites that have not installed it yet.
- Pirated ("nulled") themes and plugins. They often ship with a hidden backdoor and can never be updated safely.
- Weak or reused passwords. A password leaked from another website is tried against your WordPress login within hours.
- Custom code that trusts user input. A form that does not validate what visitors type can lead to SQL injection or cross-site scripting.
- Old copies left online. A forgotten test install in a subfolder is still a way in.
For the attack patterns in detail, read Why and how your WordPress website gets hacked.
3. Your maintenance routine
Two settings are worth adding once, in wp-config.php:
define( 'DISALLOW_FILE_EDIT', true );This removes the theme and plugin code editor from the dashboard, so a stolen administrator login cannot be used to paste malicious code. The full list of one-time hardening steps, including safe permissions and blocking PHP in the uploads folder, is in the hardening guide.
On our cPanel servers, Imunify360 removes malicious code from infected files automatically and keeps the original for 14 days, but you are not notified, and you cannot start a scan yourself from the control panel. A security plugin with email alerts, such as Wordfence, Solid Security or Sucuri Security, fills that gap. Use one security plugin, not several.
4. If your site has already been hacked
Do not just restore a backup and carry on: the hole that let the attacker in is still there. Follow the security checklist for a hacked website, which covers changing every password, finding the entry point, cleaning or reinstalling files, and asking Google to review the site. Our weekly JetBackup copies can help you get a clean version back; see backup and restore with JetBackup.
5. Where Domain India hosting fits
On our cPanel and DirectAdmin servers every plan gets the same server-side protection, so choose a plan by resources. On cPanel, WP Toolkit and Softaculous make it easier to keep WordPress installations updated; see WP Toolkit in cPanel.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
Plan cards show live Domain India list prices, excluding 18% GST.
Does Domain India keep my WordPress site secure?
Domain India secures the server: account isolation with CloudLinux CageFS, a web application firewall and automatic malware cleanup with Imunify360, the CSF firewall, and weekly JetBackup backups on cPanel and DirectAdmin. Updating WordPress, plugins and themes, and protecting your WordPress logins, is the site owner's job.
Why was my site hacked if the server has a firewall?
Most WordPress hacks use an outdated plugin, a pirated theme or a stolen password. A firewall blocks many known attacks, but it cannot patch a plugin you have not updated or tell an attacker with your real password apart from you.
Will Domain India update my WordPress plugins for me?
No. Updates are made by the site owner, from the WordPress dashboard or with WP Toolkit on cPanel. You can turn on auto-updates for plugins and themes you trust.
Will I be told if malware is found on my hosting account?
Not automatically. On our cPanel servers Imunify360 cleans infected files and keeps the original for 14 days, but it does not email you. A WordPress security plugin with alerts tells you about changed files and new administrators.
Are Domain India's backups enough on their own?
Treat them as a safety net. Weekly JetBackup backups with five copies run on cPanel and DirectAdmin, but malware can go unnoticed for weeks, so keep your own copies off the server too.
Ready to tighten up your site? Start with the WordPress security tips, and if something on your hosting account looks wrong, open a support ticket.
Account isolation, a web application firewall, automatic malware cleanup and weekly backups on every Domain India cPanel plan.
See cPanel hosting plans