WordPress

Importance of Website Owner's Maintenance in Preventing WordPress Hacking Issues

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (5 sections)

WordPress security is shared between your host and you. Domain India secures the server your site runs on; you look after the WordPress installation itself: its plugins, themes, users and passwords. Most hacked WordPress sites are broken into through the owner's half, usually an outdated plugin or a stolen password, which no server firewall can fully fix.

For the full guide

This page explains who is responsible for what. For the complete step-by-step checklist, read Useful tips to secure WordPress from hackers, then The complete WordPress hardening guide.

Key takeaways

On Domain India cPanel and DirectAdmin hosting, the server side is handled for you: each account is isolated, a web application firewall blocks many attacks, malware is cleaned automatically, and weekly backups run on cPanel and DirectAdmin. What the server cannot do is update your plugins, remove a pirated theme you installed, or stop someone who logs in with your real password. Update every week, delete what you do not use, use unique passwords with two-factor authentication, and keep your own backup off the server.

1. Who secures what

AreaWho looks after itWhat that means
Server software and firewallDomain IndiaThe server itself, the CSF firewall and brute-force protection
Account isolationDomain IndiaCloudLinux CageFS keeps each hosting account's files separate from the others
Web application firewall and malware cleanupDomain IndiaImunify360 runs server-wide with the same settings for every plan
Weekly backupsDomain IndiaJetBackup 5 on cPanel and DirectAdmin, five copies kept
WordPress core, plugins and themesYouUpdates, removing unused or abandoned ones, never using pirated copies
WordPress users and passwordsYouUnique passwords, two-factor authentication, as few administrators as possible
Your own code and formsYouValidating input, spam protection on forms, safe file uploads
Your own off-server backupsYouA copy that survives if the hosting account is lost or infected

The server-side items were measured on our cPanel and DirectAdmin servers in September 2026. They apply to every plan, so the protection does not change when you upgrade.

2. Why server security cannot fix a site-level hole

A server firewall inspects requests and blocks known attack patterns. It cannot tell a legitimate login from an attacker who has your password, and it cannot patch the code of a plugin you installed. So these problems always come back to the site owner:

  • Outdated plugins and themes. Once a security fix is published, bots scan the internet for sites that have not installed it yet.
  • Pirated ("nulled") themes and plugins. They often ship with a hidden backdoor and can never be updated safely.
  • Weak or reused passwords. A password leaked from another website is tried against your WordPress login within hours.
  • Custom code that trusts user input. A form that does not validate what visitors type can lead to SQL injection or cross-site scripting.
  • Old copies left online. A forgotten test install in a subfolder is still a way in.

For the attack patterns in detail, read Why and how your WordPress website gets hacked.

3. Your maintenance routine

Every week
Update WordPress, plugins and themes, or turn on auto-updates for the ones you trust. Leave automatic core security updates on.
Every month
Delete unused plugins and themes, review the administrator list, and check for plugins with no update in over a year.
Every login
Use a unique password from a password manager, and two-factor authentication for every administrator.
Every change
Keep a recent backup before you update, and keep copies off the server as well.

Two settings are worth adding once, in wp-config.php:

php
define( 'DISALLOW_FILE_EDIT', true );

This removes the theme and plugin code editor from the dashboard, so a stolen administrator login cannot be used to paste malicious code. The full list of one-time hardening steps, including safe permissions and blocking PHP in the uploads folder, is in the hardening guide.

The server will not email you when it cleans malware

On our cPanel servers, Imunify360 removes malicious code from infected files automatically and keeps the original for 14 days, but you are not notified, and you cannot start a scan yourself from the control panel. A security plugin with email alerts, such as Wordfence, Solid Security or Sucuri Security, fills that gap. Use one security plugin, not several.

4. If your site has already been hacked

Do not just restore a backup and carry on: the hole that let the attacker in is still there. Follow the security checklist for a hacked website, which covers changing every password, finding the entry point, cleaning or reinstalling files, and asking Google to review the site. Our weekly JetBackup copies can help you get a clean version back; see backup and restore with JetBackup.

5. Where Domain India hosting fits

On our cPanel and DirectAdmin servers every plan gets the same server-side protection, so choose a plan by resources. On cPanel, WP Toolkit and Softaculous make it easier to keep WordPress installations updated; see WP Toolkit in cPanel.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

Plan cards show live Domain India list prices, excluding 18% GST.

Does Domain India keep my WordPress site secure?

Domain India secures the server: account isolation with CloudLinux CageFS, a web application firewall and automatic malware cleanup with Imunify360, the CSF firewall, and weekly JetBackup backups on cPanel and DirectAdmin. Updating WordPress, plugins and themes, and protecting your WordPress logins, is the site owner's job.

Why was my site hacked if the server has a firewall?

Most WordPress hacks use an outdated plugin, a pirated theme or a stolen password. A firewall blocks many known attacks, but it cannot patch a plugin you have not updated or tell an attacker with your real password apart from you.

Will Domain India update my WordPress plugins for me?

No. Updates are made by the site owner, from the WordPress dashboard or with WP Toolkit on cPanel. You can turn on auto-updates for plugins and themes you trust.

Will I be told if malware is found on my hosting account?

Not automatically. On our cPanel servers Imunify360 cleans infected files and keeps the original for 14 days, but it does not email you. A WordPress security plugin with alerts tells you about changed files and new administrators.

Are Domain India's backups enough on their own?

Treat them as a safety net. Weekly JetBackup backups with five copies run on cPanel and DirectAdmin, but malware can go unnoticed for weeks, so keep your own copies off the server too.

Ready to tighten up your site? Start with the WordPress security tips, and if something on your hosting account looks wrong, open a support ticket.

WordPress hosting with the server side handled

Account isolation, a web application firewall, automatic malware cleanup and weekly backups on every Domain India cPanel plan.

See cPanel hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
WordPress Security: Host vs Owner Duties | Domain India