Securing your cPanel/WHM server is essential to protect websites, customer data, email accounts, and server resources from unauthorized access.
Recommended Security Practices
-
Use Strong Passwords
Use unique and complex passwords for WHM, cPanel, FTP, email, and database accounts. Never reuse your root password. -
Enable Two-Factor Authentication (2FA)
Enable 2FA for WHM and cPanel accounts to provide an additional layer of protection. -
Keep cPanel and Server Software Updated
Regularly update cPanel/WHM, operating system packages, PHP, web server, and other installed software to receive the latest security fixes. -
Use a Firewall and Brute-Force Protection
Configure a server firewall and enable cPHulk Brute Force Protection to block repeated unauthorized login attempts. -
Secure SSH Access
Disable direct root SSH login where practical, use SSH keys instead of passwords, and restrict SSH access to trusted IP addresses whenever possible. -
Install Malware/Security Protection
Use security tools such as Imunify360 or another trusted server security solution to detect malware, suspicious files, and malicious activity. -
Secure Hosted Websites
Keep WordPress and other CMS software, plugins, and themes updated. Remove unused or nulled/cracked plugins and themes. -
Use SSL Certificates
Enable HTTPS/SSL for websites and other supported services to protect data transmitted between users and the server. -
Take Regular Backups
Maintain regular backups and keep at least one backup in a secure off-server location. -
Monitor Your Server
Regularly review login history, security alerts, resource usage, malware scan results, and system logs for unusual activity.
Important
No server can be made completely immune to attacks. Using multiple layers of security, keeping software updated, and continuously monitoring the server significantly reduces the risk of compromise.