Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

Where Your Host's Security Stops and Yours Starts on a WordPress Site

If you are skim reading
TL;DR: Your host secures the server your WordPress site runs on. You secure what runs on top of it: WordPress itself, plugins, themes, user accounts and anything inside your files and database.

By DeShea Witcher

TL;DR: Your host secures the server your WordPress site runs on. You secure what runs on top of it: WordPress itself, plugins, themes, user accounts and anything inside your files and database. Find out in writing which parts your plan covers, then spend 30 minutes a month on the rest.

Most hosting plans promise "secure hosting" somewhere on the pricing page. A lot of business owners read that as "my website is protected." Your web host is responsible for WordPress security only up to a point. The host protects the building. What happens inside your unit is mostly on you.

Two flaws disclosed on September 22, 2026 show where that line sits. One needed a fix from hosting companies. The other needed a WordPress fix on each site, applied by the owner or through automatic updates. Here's where the line usually sits, what those two cases show, and how to find out exactly what your own host covers.

Business owner looking at a hosting panel and a website dashboard side by side

1. What your host usually handles

Your host secures the machine your site runs on. That means the server's operating system and software, the network, the physical hardware, and usually backups and some kind of firewall in front of your site.

Two terms help here. Shared hosting means your site sits on one server alongside many other customers' sites, which keeps the price low. Managed WordPress hosting means the host runs servers built only for WordPress and takes on more of the upkeep, often including WordPress updates.

The official WordPress.org hardening guide puts the host's job simply. The web server and its software can have security holes, so you either keep them updated yourself or use a trusted host that does it for you. The same guide flags the main risk of shared hosting: if another site on your server is compromised, yours can be affected even if you do everything right.

Here's how the work usually splits. Your plan may differ, so check it and ask.

TaskShared hostingManaged WordPress hosting
Server software and security patchesHostHost
Network firewallHostHost
Firewall in front of your site (WAF)SometimesUsually
BackupsOften; ask how long they're keptUsually
WordPress core updatesYou, unless automatic updates runOften the host; check
Plugin and theme updatesYouUsually you; some hosts help
Admin accounts and passwordsYouYou
Malware inside your files and databaseYouVaries; check your plan

A WAF (web application firewall) filters traffic before it reaches your site and blocks requests that look like known attacks.

"Managed" is the word that causes the most confusion. It usually means the host handles more of the routine upkeep, like server tuning, caching and sometimes core updates. It rarely means the host takes responsibility for every plugin you install or every user you add. Read the plan's feature list for the word "security" and see exactly what sits next to it.

Watch Out: "Daily backups" can mean backups kept for only a few days. If a hack goes unnoticed for two weeks, every backup you have may already include it. Ask how long backups are kept.

2. What stays with you

Everything inside WordPress is yours. That covers WordPress core updates (unless your host manages them), every plugin and theme, every user account, and whatever ends up in your site's files and database.

Plugins are the biggest part of that job. Patchstack's 2026 security report found that 91% of the WordPress vulnerabilities disclosed in 2025 were in plugins and 9% were in themes. Your host didn't choose your plugins, so it rarely updates them for you.

WordPress core is a little different. Automatic updates for minor and security releases are on by default for most sites, as they have been since WordPress 3.7. But a host, a developer or a plugin can turn them off, and many site owners never check. If yours are off, core updates are back on your list.

User accounts are the third piece. Think about old admin logins for a contractor who left two years ago, one password shared by the whole team, and no two-factor login (a second code at sign-in, usually from your phone). Your host can't see which of your users should still have access. Only you know that.

The last piece is what sits inside your files. A host firewall watches traffic at the door. It has no idea which files belong in your theme, or whether a new one appeared last Tuesday.

Who secures what on a WordPress site: host versus site owner

3. Two September cases on either side of the line

On September 22, 2026, two critical flaws went public on the same day. One could only be fixed by hosting companies. The other could only be fixed on each WordPress site.

The host's side: cPanel CVE-2026-87899

cPanel is the control panel many hosts give customers to manage their hosting accounts. cPanel's September 22 advisory described a flaw that let any logged-in cPanel account holder use the calendar and contacts feature to run code as root, which meant full control of the server. Root is the top-level admin account on a server, with control over everything on it. The flaw affected cPanel and WHM version 120 and later, and the advisory listed fixed builds. GitHub's advisory database rated it 9.4 out of 10, which is critical.

As a site owner, you couldn't patch this. You didn't control the server. On a shared server, the danger also came from someone else's account, since any customer on the machine could have used it. Your only move was to ask your host whether they'd updated.

Your side: WordPress core CVE-2026-87902

The same day, WordPress 7.1.2 fixed a critical core flaw that needed no login to attack, with the fix also released for older versions as far back as 4.7. Patchstack's timeline recorded the first attack activity at 11:49 UTC that day and attempts to write files onto servers by 15:34 UTC.

If automatic updates were running, most sites got the fix without anyone lifting a finger. If they were off, applying it was the site owner's job, and every hour counted.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

Why the host's firewall doesn't close the gap

A good host firewall might seem like enough to stop attacks like that. Patchstack tested that in 2025. Traditional defenses such as host firewalls and Cloudflare blocked only 12% of WordPress-specific exploit attempts in one study, and 26% of attacks in a wider study. The first study focused on known exploited WordPress flaws, and the second added more generic ones. Results also varied a lot from one hosting setup to another.

Key Insight: A host firewall is worth having. It just can't be your whole plan for flaws inside WordPress.

Put the two cases side by side and the split gets concrete. In the same week, a WordPress site on cPanel hosting needed two separate fixes: one applied by the host to the server, and one applied to WordPress itself. Neither party could do the other's job. A site owner who assumed the host had it all covered would have missed the WordPress fix if automatic updates were off.

4. Questions to ask your host before assuming you're covered

Ask these in writing, and save the answers with your hosting login details. A clear written answer tells you what's covered. A vague one tells you which parts are yours, so follow up until you get specifics.

  1. Do you update WordPress core, plugins and themes, or only the server?
  2. Are automatic WordPress updates turned on for my site?
  3. How long do you keep backups, and can I restore one myself?
  4. Do you scan my site's files and database for malware? If you find some, do you remove it or just notify me?
  5. Is there a firewall in front of my site, and does it cover WordPress-specific attacks?
  6. If you use cPanel, when did you apply the fix for the September cPanel flaw (CVE-2026-87899)?
  7. If my site is hacked, what do you do, and what does it cost?
  8. How is my account kept separate from other customers on the same server?

Here's what the difference looks like on three of the questions:

QuestionA clear answerA vague answer
Do you update plugins?"We update plugins weekly and roll back if one breaks the site.""We keep your site up to date."
How long are backups kept?"Daily backups, kept for 30 days, restorable from your dashboard.""We back up regularly."
Do you remove malware?"Cleanup is included on this plan.""We have malware protection."

The clear answers above are examples of what to look for. They don't describe any particular host.

Good hosts answer these quickly, and many publish the answers already. Either way, you stop guessing about what's covered.

5. A monthly checklist for the parts that are yours

Thirty minutes a month covers most of your side of the line. Pick a fixed day and work through the list:

  1. Update plugins and themes, and delete any you no longer use.
  2. Confirm WordPress core is current and automatic updates are on.
  3. Review admin users and remove anyone who shouldn't have access.
  4. Turn on two-factor login for every admin account.
  5. Restore one backup to a test site to prove it works.
  6. Read any security or malware notices from your host.
  7. Scan the site for malware and unexpected file changes.

For step 7, the important part is using monitoring consistently. (Disclosure: I work at Guardian Gaze.) Guardian Gaze is an AI-powered WordPress malware scanner and website security monitoring platform. It detects malicious code, suspicious file changes, compromised plugins and themes, and other indicators of compromise. Its analysis runs outside the site, so a hacked site isn't checking itself.

Keep a short log of what you did each month and when. If something ever goes wrong, that log tells you, your host or anyone helping you which updates ran and which backups are safe to use. It also makes handing the job to someone else easier.

Quick Win: Schedule this checklist for the same day your hosting invoice arrives. The reminder is already built in.

Monthly WordPress security checklist with seven steps

Frequently asked questions

Is my web host responsible for WordPress malware?

Usually not for malware inside your site's files or database, unless your plan says otherwise. Hosts secure the server. Some managed plans include malware scanning or cleanup, so check your plan and ask before you need it.

Is shared hosting less secure for WordPress?

It adds one extra risk: other customers on the same server. WordPress.org's hardening guide notes that a compromised site on a shared server can affect yours. Ask your host how accounts are kept separate.

Do all web hosting companies provide security for WordPress sites?

Every host secures its own servers to some degree. Plugin updates, malware cleanup and WordPress-specific firewalls vary a lot by host and by plan, which is why it's worth getting the details in writing.

Who should take responsibility for WordPress security?

It's split. The host owns the server, and the site owner owns WordPress, plugins, themes and user accounts. An agency or care plan can take over the owner's share, as long as that's written down.

Know where the line sits

Splitting security with your host is normal. The trouble starts when nobody knows where the split is. Send your host the questions above this week, and put the monthly checklist on your calendar.

About the author

DeShea Witcher handles partnerships at Guardian Gaze, an AI-powered WordPress malware scanner and website security monitoring platform that detects malicious code, suspicious file changes, compromised plugins and themes, and other indicators of compromise. He writes about how WordPress sites get compromised and how owners recover. guardiangaze.com/wp

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.