All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Web hosting is where your website lives. It can be on a computer in your office, or (as is more likely) on a server managed by a hosting company. I’m here to explain how it works, what a web host provides, what it protects, and what you’re responsible for securing yourself.
If you want to know how hosting works and how to keep your website safe, start here. Maybe grab something to drink. I’m having tea.
How to pick a web host
What your web host secures, and what you secure
Web hosting security features, explained
Common web hosting security risks
Types of web hosting
Bottom line
FAQs
What is web hosting?
Here’s the short, short version: web hosting is the space you rent on someone else’s computer/server where you put your website. That makes the website available to the whole internet.
If you want to know more about how web hosting works, here’s a more detailed example:
A party typically consists of a host and guests. The host provides the venue, while the guests make up the party. Without a venue, the party can't happen. Similarly, web hosting is like the host providing space on the internet, and the website's files are the guests. These website files need a place to live, and web hosting provides that space. A website can't exist without web hosting.
We surveyed 1,000 U.S. adults and found that most Americans haven't used web hosting services and only vaguely understand what web hosting is.
Web hosting vs. web builder
Web hosting is the service that allows your website to exist. Meanwhile, a web builder helps you create a professional website. It may involve predesigned templates or drag-and-drop functionality to create a custom look. Some web builders even offer comprehensive AI tools to help you design your website.
Many web builders include hosting in their services. They may also offer additional features, such as robust ecommerce tools, email hosting, and a content management system for blogging. Consider whether you need these features when picking a hosting provider or web builder.
With traditional web hosting, you're generally responsible for securing your website and its software, while the host protects the underlying infrastructure. Website builders typically manage more of the technical security for you, although you're still responsible for things like your account credentials and how you handle sensitive data.
Web hosting vs. domain name
Going back to our earlier example, if your web host is a house, a domain name is the address to that house. Your browser uses the domain name to find the server, locate the website, and display it.
There are two different types of domains. A custom domain is an address that you own and fully control. It helps to establish your brand identity. A custom domain typically appears as www.example.com.
If you don't have a custom domain, you end up with a subdomain. The address includes your hosting provider. It looks like this: www.yourbusiness.hostingprovider.com.
Free web building platforms, such as Wix or WordPress, typically offer a subdomain with their free plans. This lets the platform gain more visibility while giving users an affordable web builder.
How to pick a web host
Several factors influence which web host best suits your website. Price may get the most attention, but it isn't the only thing to consider. In our survey, 80% of hosting users cited cost as a top factor when choosing a provider, followed by ease of setup (46%) and security and backups (39%).
Some web hosting features to consider:
- Support: 24/7 technical support can provide quick and knowledgeable assistance. Check whether the web hosting service offers support via phone, live chat, or email.
- Control panel: Opt for a user-friendly interface, especially if your team lacks technical expertise. For more complex environments, you may need to hire an expert to manage them.
- Scalability: As your online business grows, your website needs to keep pace. Choose a hosting provider that can handle increased traffic and data on your site.
- Performance and uptime: A website that loads slowly will cost you customers. Look for a 99% uptime guarantee to ensure your website is accessible.
- Storage space: Check storage capacity for your website. If you plan to post images and videos, ensure that your site has sufficient space for them.
- Bandwidth: Bandwidth determines how much traffic your website can handle. Unmetered bandwidth is ideal for handling traffic fluctuations and preventing slowdowns.
- Shared vs. dedicated hosting: You can share a hosting server with other users, which reduces your costs. But it may limit your bandwidth. A dedicated server means you get the space all to yourself, but it's a pricey choice. Learn more about how shared and dedicated hosting compare.
Of course, security is also a major factor, and we can't cover it in a single bullet point. That’s what this next part of the article is for.
What your web host secures, and what you secure
Getting hosting from a hosting company splits security responsibility in two. You’ll need to work together to keep your data safe, but that division isn't always obvious. In our survey of 1,000 U.S. adults, more than 1 in 5 respondents confused web hosting with services such as website design, email, or security features.
What the web host should handle on their end:
- Basic server security. Firewalls, underlying server software updates, malicious traffic scanning, antivirus scanning, and backups are things your host should handle, especially on shared hosting. But if you go with a virtual private server as opposed to shared hosting, you’ll need to do some of this stuff yourself. More on that below.
- Separation of concerns. Sometimes your website can get hacked because someone else on the same server had an insecure website. The best hosts use technologies such as containers or virtual machines to essentially keep everybody’s sites separate, so this can’t happen.
- Account security. Your host should provide common-sense security features like requiring strong passwords, multi-factor authentication, and other tools to keep your account safe. If an attacker gains access to your hosting account, they also have access to your website.
What you handle on your end:
- Build a secure website, designed to resist hacking. This particularly applies to sites built on dynamic content management systems or web apps such as WordPress or Ghost. Static pages usually can’t be hacked directly; they can only be changed if the server they run on has been hacked. But the caveat is that if you bought a package where the host promises to build your whole site for you (and not just install a CMS like WordPress), then they are responsible for this as well.
- Secure storage of all sensitive data, including user data. It’s not just good business; it’s a legal liability.
- Web software security updates. Again, if you’re using software like WordPress, you’ll need to keep it up to date to keep it secure. While many hosts offer automatic security upgrades for WordPress and similar CMS options, especially with managed hosting, you still need to double-check that it’s working.
Web hosting security features, explained
I mentioned a lot of security features above, so let’s look at each one in a little more detail. These are things that hosts can either do automatically or provide the means for you to do them yourself, just as long as they come included:
Account isolation
Account isolation helps prevent activity or security problems on one website from affecting other websites sharing the same server. Hosting providers can use technologies such as containers, virtual machines, and other isolation measures to separate customer environments and reduce the risk of one compromised account affecting another. Any hosting company worth the money will ensure one badly maintained website can’t take down the whole server.
Ask your host how it isolates customer accounts and websites from others sharing the same server.
Automated backups
You want to recover your website if anything goes wrong. Not all hosts offer this feature, though most major shared hosting providers do. People with VPS or dedicated hosting plans may have to pay extra or set up their own backup solution, which is inconvenient, but still necessary.
Check whether backups are included with your plan, how often they run, how long they’re retained, and how you restore one if something goes wrong.
DDoS mitigation
Distributed Denial-of-Service (DDoS) attacks are when thousands upon thousands of machines try to connect to your server at once, clogging up the connection. Almost all hosts these days take measures to protect their servers from these attacks. I’d go so far as to say that if you’re considering a host that doesn’t have it, look elsewhere. You can implement your own solutions, but you shouldn’t have to.
Check whether DDoS protection is included with your plan and whether there are any limits or additional charges for mitigation.
Malware scanning and removal
Just like desktop PCs, servers can get viruses. Malware can infect servers and websites, compromising your site or putting visitors at risk. Some web hosts provide automatic malware scanning to detect malicious files, while malware removal or remediation may depend on your plan or cost extra.
Find out whether your host only scans for malware or also removes it, and whether remediation costs extra.
Multi-factor authentication (MFA)
MFA is when you sign in to the host’s admin panel and have to click a link in an email. Or input a token from an authenticator app or any one of a number of different methods for confirming that you are, in fact, the owner of the account.
Because access to your hosting account can give someone significant control over your website, prioritize hosts that let you protect the account with MFA in addition to a password. Look for MFA on the hosting account and control panel, especially for accounts with administrative access. But definitely don’t settle for anything less than two-factor authentication (2FA).
Look for a host that offers MFA for your hosting account and control panel, especially for accounts with administrative access.
Software updates
Outdated software can leave known vulnerabilities unpatched, so find out which updates your host handles and how quickly it applies critical security patches. Most hosts maintain the underlying server software, while updates to your CMS (like WordPress), plugins, themes, or other website software may still be your responsibility. Some hosts automate those updates, particularly with managed hosting, so check exactly what your plan includes.
Ask your host which software it updates automatically, how quickly it applies critical security patches, and which updates you're still responsible for.
SSL/TLS Certificates
SSL/TLS certificates allow your website to be accessed via Hypertext Transfer Protocol Secure (HTTPS). This means that all connections to your website are encrypted, helping to protect your site and your users’ data. Every website needs HTTPS in some form, so your host should offer either their own free SSL certificates or the means to install them via Let's Encrypt, etc.
Check whether SSL/TLS certificates are included for free, whether they renew automatically, and whether HTTPS is easy to enable across your site.
Web Application Firewalls
Regular firewalls are great, but if you’re building a web application, you want a Web Application Firewall. These monitor traffic to and from your application, check for common attacks, and stop them before they happen. A WAF isn’t needed for every website, but if yours has advanced app-like functionality, then you want one.
If your site needs a WAF, check whether one is included with your hosting plan or available as an add-on, and what types of traffic or attacks it filters.
Common web hosting security risks
And these are the things you’ll want to look out for when hosting a website:
- Neighbors on a shared server. While this is slowly becoming less of a problem as separation of concerns becomes more common, it’s still worth watching. If other people don’t update their CMS, for example, an attacker might find a way to get in and gain access to the rest of the server. It happens.
- No working backup. No system is perfect, and eventually your website will go down. You usually want a couple of backups, if you can, including one stored somewhere other than the server your site is hosted on. Ideally, it should be in an entirely different data center, in another city. Just like in the old days of Word, save early, and save often.
- Outdated software. I harp on updates because they’re that important. Developers constantly discover and patch new vulnerabilities in all software, including plugins and themes for your CMS. Having the latest version thus means that you’re less likely to get hacked. (The main exception to this rule seems to be Windows 11.) Always, always update.
- Unencrypted file transfer. Any unencrypted traffic between your website and your users can potentially be hijacked to cause harm to one or both parties. HTTPS and SSL certificates solve this problem. If you transfer website files to and from your hosting server, avoid protocols that send your login credentials or files without encryption. Traditional FTP doesn't encrypt the connection, leaving that information vulnerable to interception. Use an encrypted option such as SFTP instead, and check which secure file transfer methods your web host supports.
- Unused software installs. If you installed, for example, an extra CMS on your hosting server just to try it out, and you didn’t use it in the end, make sure to delete/uninstall it later. Unused and unmaintained software has the same problem as any other outdated software: it can open ways for attackers to get in and mess up your main website.
- Weak or reused credentials. Watch out for this one. Multi-factor authentication helps, but it's not infallible. Don’t use the same password for everything, alright? Get yourself a password manager, and use it. That way, if one service you use gets hacked, bad actors can’t access every service you use.
Types of web hosting
Of course, the security tools available to you and what you have to do to protect your site can vary wildly according to a number of factors. One big factor is the type of hosting you choose. With shared hosting, for example, the provider handles more (including security). With virtual private servers, you have more control and can install pretty much any kind of web software you like, but you also (usually) handle more of your own maintenance and security.
Here’s a quick overview of the different types of hosting available out there, and what they entail:
Shared hosting
Shared hosting means multiple websites share the same server resources. The main benefit of shared web hosting is its cost-effectiveness for low-traffic sites. Small businesses and personal websites can often run well on shared hosting. Another benefit is that your provider manages the server, so you don't need technical expertise.
Because you share processing power, other sites on your server could slow your website during traffic spikes. Likewise, if your site gets heavy traffic, your hosting provider may throttle performance to manage server resources.
Security-wise, you’re also (potentially) exposed to the security vulnerabilities in every other website on the server. If someone else on the same host as you isn’t keeping their software updated, your site could be compromised too. This is becoming less of a problem as more hosts adopt practices that minimize risk, but it’s still worth considering.
- Cost effective
- Ideal for small businesses or personal sites
- Hosting provider manages the server
- No technical expertise needed
- Not a scalable web hosting solution
- Other sites on the shared server could impact your performance
- Other sites on the server could impact your site’s security
Virtual Private Server (VPS) hosting
VPS hosting is similar to shared hosting. The difference is that VPS hosting creates separate partitions for each website. Each site receives a dedicated reserve of processing power, storage, and memory. Unlike shared hosting, websites are less likely to affect each other if one experiences a sudden surge in traffic.
VPS hosting offers more configuration options and controls than shared hosting. You may welcome the customization, but it does require technical expertise. Overall, VPS hosting suits medium-sized businesses that need features such as ecommerce and blogs.
VPS hosting is, for the most part, fully under your control. You can often choose what operating system you want to run, and all the software you want to run on top of that. That also means that security is mostly up to you. But if you get your VPS from a host with managed hosting, they’ll actually take care of most of that stuff for you, but it may cost more.
- Other sites are less likely to impact your performance
- More server control
- Dedicated space
- More technical and security management may be required
- Costs more than shared hosting
Cloud hosting
Instead of physical servers, cloud hosting uses multiple virtual servers. Large businesses benefit from cloud hosting because there's little downtime. If your site experiences an increase in traffic, other virtual servers step in to keep the site operational. Another benefit of cloud hosting is scalability. It can grow or shrink as your website's needs change.
Cloud hosting is a bit all over the place when it comes to responsibility. Some cloud hosting providers offer a service similar to VPS hosting, where you have a lot of control and nearly all responsibility for your own security. Others offer a much more limited experience, like shared hosting. Make sure you know what you’re getting before you dive in.
- Easy to scale
- Extremely reliable
- Low chance of downtime
- May have limited control
- Security responsibilities vary by provider and hosting setup
Dedicated hosting
Dedicated hosting means your site gets an entire server, so you don't have to worry about other sites crashing your party. Your dedicated host server has you covered. It gives businesses complete control over server configurations. Large sites will find dedicated hosting ideal for reliability and uptime.
Dedicated hosting also gives you near-complete control over the system. Beyond whatever firewalls protect the network, the machine is your responsibility. Install whatever you want, build whatever you want, and protect it yourself. Now, a couple of hosts provide managed dedicated hosting where they’ll handle many technical and security concerns for you, but it’s typically quite expensive.
- More customization options
- Greater reliability
- Full control of the server
- Can host multiple websites
- Most expensive hosting option
- Server maintenance and security may be your responsibility
WordPress hosting
WordPress is a popular content management system (CMS), but it requires a hosting service. A dedicated WordPress hosting provider can offer easy site management, enhanced security, and optimized performance.
In practice, “enhanced security” usually means that they install WordPress along with a few plugins designed to harden your website against attack. They may also include a suite of server security tools specifically designed to work with WordPress. In both cases, these solutions often come from third-party vendors, and they’re usually pretty good. A few hosts have developed proprietary WordPress plugins to better integrate with their in-house security solutions, and that’s also a valid approach.
- Optimized for WordPress
- Specialized WordPress support
- Simplifies site management
- May include WordPress-specific security tools and managed updates
- Only works with WordPress
- May need more technical skills
Bottom line: What to look for in web hosting
The right web host depends on how much traffic, control, and technical responsibility you're prepared to handle. Shared and managed hosting generally put more server maintenance in the provider's hands, while VPS and dedicated hosting can give you greater control but may also leave more security work to you.
Before choosing a host, check what it provides for backups, DDoS protection, malware scanning, account isolation, software updates, HTTPS, and account security. Just as importantly, find out what it doesn't include. A secure host can protect the infrastructure your website runs on, but keeping your website software, accounts, and sensitive data secure may still be your responsibility.
FAQs
Why do I need web hosting?
You need web hosting to make your website available on the internet. A web host stores the files your website needs to function and provides the server infrastructure that makes them accessible to visitors. Depending on your plan, your host may also provide tools for performance, backups, security, and site management, although you're still responsible for some aspects of securing and maintaining your website.
Which type of web hosting should I choose?
The right type of hosting depends on your website's size, traffic, budget, technical expertise, and how much control you need. Shared hosting is typically simpler and more affordable for smaller sites, while VPS hosting provides more resources and control but may require more technical and security management. Dedicated hosting gives you an entire server and the most control, but it's also more expensive and typically requires greater technical expertise. Managed hosting can be a good option if you want the provider to handle more of the maintenance and security for you.
How much does web hosting cost?
Web hosting costs vary by hosting type, provider, and the features included with your plan. In our survey, roughly six in 10 Americans expected web hosting to cost $25 per month or less. Shared hosting is generally the least expensive option, while VPS and dedicated hosting typically cost more in exchange for additional resources and control. When comparing prices, check what's included with the advertised rate, such as backups, SSL/TLS certificates, security features, support, and renewal pricing.
Can I host my website for free?
Yes, some providers offer free web hosting, but free plans typically limit storage, bandwidth, features, and support. Check the security features carefully, too. A free plan may not include protections or services such as automated backups, SSL/TLS certificates, malware scanning, or hands-on support that are included with paid hosting plans. Make sure you understand what the provider handles and what you'll need to secure or maintain yourself.
Is shared hosting safe?
Shared hosting can be a safe option when the provider properly maintains its servers and isolates customer accounts. Because multiple websites share the same physical server, vulnerabilities or poor security practices on another account can potentially create additional risk. Look for a reputable shared hosting service that provides account isolation, regular server updates, malware protection, backups, and strong account security.
What security features should a web host include?
Look for features such as account isolation, automated backups, DDoS protection, malware scanning, multi-factor authentication, regular security updates, and SSL/TLS certificates. Depending on your website, a web application firewall may provide additional protection. Also check which security features are included with your plan, which cost extra, and which protections you must manage yourself.