GREAT HOSTS KNOWLEDGE BASE

Website Security Controls in GreatHosts CP

Security claims should be specific. GreatHosts CP visibly exposes several controls that customers can configure themselves. This guide documents those controls without claiming unsupported datacenter, DDoS or malware-scanning guarantees.

Last verified: 2026-10-03Evidence: GreatHosts CP + live catalogue + factual baseline

1. Separate verified controls from broad security claims

GreatHosts documents what the customer can actually see and use. The live CP exposes ModSecurity, IP Blocking, Password Protection, Hotlink Protection, DNSSEC and Cloudflare controls. That is different from making vague claims about every layer of infrastructure security.

  • Use the controls that match the application threat model.
  • Do not treat one control as a replacement for secure application code.
  • GreatHosts deliberately does not infer unsupported DDoS, malware-scanning or physical-security claims from these menu items.
EvidenceLive GreatHosts CP + factual integrity baseline

2. ModSecurity web application firewall

GreatHosts CP labels ModSecurity as a Web Application Firewall. It can help block classes of malicious HTTP requests before they reach the application.

  • Keep it enabled unless a verified application conflict requires a targeted exception.
  • When a legitimate request is blocked, capture the rule/event information before changing configuration.
  • Do not disable broad protection merely to make one request pass.
EvidenceLive GreatHosts CP Web Tools menu

3. IP blocking and password protection

IP Blocking can deny selected addresses or ranges, while Password Protection can restrict access to a page or an entire site. These are useful controls for staging, private tools and abusive-source containment.

  • Use password protection for non-public staging areas.
  • Use IP blocking for clearly identified abusive or administrative restrictions.
  • Avoid permanent broad IP blocks that accidentally exclude legitimate customers or crawlers.
EvidenceLive GreatHosts CP Web Tools menu

4. Hotlink protection

Hotlink Protection is intended to reduce third-party embedding of your hosted images or other assets where that traffic is not wanted.

  • Enable it only when external embedding is actually undesirable.
  • Allow legitimate CDN or partner origins when required.
  • Verify social previews and integrations after changing rules.
EvidenceLive GreatHosts CP Web Tools menu

5. DNSSEC and Cloudflare controls

The current Web Tools menu exposes DNSSEC and Cloudflare management. DNSSEC protects DNS authenticity when the full delegation chain is configured correctly; Cloudflare integration can be used when that service is part of the customer architecture.

  • Enable DNSSEC only when registrar and authoritative DNS settings can be coordinated correctly.
  • Do not change nameservers or signing records without a rollback plan.
  • Cloudflare is an external service; its own account, terms and configuration remain separate from GreatHosts hosting.
EvidenceLive GreatHosts CP Web Tools menu

6. SSL/TLS and certificate workflow

Certificate management belongs with the domain and HTTPS workflow. GreatHosts supports SSL/TLS and the CP exposes certificate and CSR controls.

  • Use HTTPS for public logins, forms and normal production websites.
  • CSR generation is available when a certificate workflow requires it.
  • Confirm renewal and certificate term details in the current domain/SSL order path.
EvidenceLive GreatHosts CP Domains menu + verified SSL baseline

7. Secure configuration still matters

Control-panel security features do not correct weak passwords, exposed secrets, vulnerable application code or outdated software. Keep the application itself maintained and minimize unnecessary access.

  • Use unique credentials and protect administrative accounts.
  • Keep application frameworks, CMS software and plugins current.
  • Back up before risky changes and verify restoration capability.
EvidenceGeneral secure hosting practice

Common questions

Does GreatHosts claim DDoS protection from these controls?

No. The factual baseline intentionally avoids unsupported DDoS, malware-scanning, physical-security and shared-account-isolation claims unless separately documented.

Should I disable ModSecurity if it blocks my application?

Prefer a targeted diagnosis or rule exception. Broadly disabling protection to solve one conflict is usually the wrong first response.

Is Cloudflare included with hosting?

The live CP exposes Cloudflare management, but Cloudflare remains an external service with its own account and configuration. Check the current service terms before assuming any paid Cloudflare feature is included.

Services related to this guide

Turn the requirements into a hosting choice

Use the hosting chooser if you are not sure whether the project belongs on Shared, Semi-Dedicated, VPS or Dedicated.

Choose hosting