Protect WordPress on Shared Hosting 2026: cPGuard, Login, File Permission

WordPress powers over 43% of all websites on the internet, making it the world's most popular CMS — and its most targeted. Automated bots and hackers launch thousands of attacks against WordPress sites daily, probing for outdated plugins, weak passwords, and misconfigured file permissions. When running WordPress on Shared Hosting, understanding the specific risk landscape is essential to maintaining a secure site.

This complete 2026 guide walks you through every step to protect WordPress on Shared Hosting — from understanding shared environment risks to configuring cPGuard, setting correct File Permissions, enabling 2FA Login, hiding wp-login.php, refreshing WordPress Salts, disabling Directory Listing, and keeping your installation fully up to date.

✅ AsiaGB Hosting includes cPGuard Security Suite free on every plan — no purchase or manual installation required. The malware scanner and WAF start protecting your account from the moment your DirectAdmin hosting is activated.

Why WordPress on Shared Hosting Carries Greater Risk Than VPS

Many website owners choose Shared Hosting for its cost and ease of use, but it is important to understand how the shared environment creates unique security dynamics compared to a dedicated VPS.

Shared Hosting Characteristics to Understand

On Shared Hosting, multiple users run websites on the same physical server. If another account on the server is compromised and infected with malware, that malware may attempt to spread across accounts through a process known as Cross-Site Contamination — especially when PHP processes have permission to read files across directory boundaries on poorly isolated servers.

Additionally, Shared Hosting offers less flexibility to modify PHP-level settings than a self-managed VPS. Functions considered risky — such as allow_url_fopen or exec() — must be restricted through per-account php.ini or .htaccess directives rather than server-wide configuration.

Security Advantages of Shared Hosting That Are Often Overlooked

Despite these risks, quality Shared Hosting like AsiaGB offers built-in security protections that self-managed VPS users must configure themselves:

In summary: Shared Hosting has specific risks worth addressing, but it also comes with powerful server-level protections already in place. The key is knowing how to leverage both sides effectively.

cPGuard: The Security System AsiaGB Hosting Provides Free

cPGuard is an enterprise-grade Security Suite built specifically for Web Hosting environments. Unlike WordPress security plugins that operate at the PHP Application layer, cPGuard works at the Server and OS level directly — meaning it can detect and remove threats even if WordPress itself has already been compromised, because it sits deeper than the layer attackers can reach through CMS vulnerabilities.

Key cPGuard Features That Protect WordPress

Malware Scanner & Auto-Cleaner

Scans every file on the server in real time, detecting malware, web shells, obfuscated PHP code, and phishing pages, then automatically quarantines threats without waiting for admin action.

Web Application Firewall (WAF)

Filters dangerous HTTP requests to block SQL Injection, Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Remote File Inclusion (RFI) before they reach WordPress.

Brute Force Protection

Detects repeated failed login attempts and automatically blocks offending IPs across all login vectors — wp-admin, DirectAdmin, FTP, and phpMyAdmin — simultaneously.

Outbound Spam Prevention

Prevents your hosting account from being used to send spam email — a common consequence of malware that site owners often discover too late when their IP lands on email blacklists.

Checking cPGuard Status Through DirectAdmin

On AsiaGB Hosting you can monitor and review cPGuard reports directly through DirectAdmin without any external tools:

1
Log in to DirectAdminUse the URL yourdomain.com:2222 or the link in your AsiaGB Welcome email, then enter your username and password.
2
Navigate to the Security SectionLook for the cPGuard icon on the main dashboard or in Advanced Features, depending on your DirectAdmin version.
3
Review Scan HistoryThe panel shows all files flagged as suspicious along with their disposition — Cleaned, Quarantined, or Whitelisted.
4
Check Brute Force AlertsView IPs blocked due to repeated failed logins, complete with attack statistics and timestamps.

💡 cPGuard runs in the background at all times — there is no need to manually trigger scans every day. The system performs automatic scanning and sends email alerts whenever suspicious activity is detected in your account files.

Setting the Correct File Permissions for WordPress (755/644)

File permissions are one of the most fundamental and impactful security settings for WordPress on Shared Hosting. Incorrect permissions can allow unauthorized modification of critical files — or in the opposite direction, prevent WordPress from functioning at all and produce server errors.

How Linux File Permissions Work

In Linux, every file and directory has permissions expressed as a 3-digit octal number defining who can do what:

Each digit is the sum of: Read=4, Write=2, Execute=1. So 7=rwx (read+write+execute), 5=rx (read+execute), 4=r (read only). For example, 755 means the Owner can do everything (7=4+2+1) while Group and Others can only read and execute (5=4+1) but cannot write.

Standard WordPress Permission Reference Table

TypeCorrect PermissionExample PathReason
General directories755/wp-content/, /wp-includes/Owner can write; Others read+execute to access the directory
General files644*.php, *.js, *.cssOwner can write; Others read only, cannot modify
wp-config.php600wp-config.phpOnly Owner can read/write — protects database credentials
.htaccess644.htaccessApache must read it, but Others should not be able to modify it
Uploads directory755/wp-content/uploads/WordPress needs to write images here; PHP execution not needed
Dangerous permission777Never use on PHP filesAllows anyone to write and execute PHP — critical vulnerability on shared servers

Setting Permissions via DirectAdmin File Manager

1
Open DirectAdmin and navigate to File ManagerGo to public_html or the directory where WordPress is installed.
2
Select the target files or directoriesRight-click or use checkboxes to select multiple items at once.
3
Click Permissions or chmodEnter the octal value — 755 for directories or 644 for files.
4
Enable Apply Recursively if neededFor directories containing nested subdirectories, this applies the permission to all files inside.

With SSH access, you can set permissions across your entire WordPress installation in one pass:

find /home/user/public_html -type d -exec chmod 755 {} \;
find /home/user/public_html -type f -exec chmod 644 {} \;
chmod 600 /home/user/public_html/wp-config.php

⚠️ Warning: Never set everything to 777 even if it makes an error go away temporarily. On a shared server, 777 means PHP scripts belonging to other users can overwrite your files, creating a severe security hole.

Protect the wp-admin Login Page with 2FA and Login Limiting

The wp-admin login page is the primary gateway to your WordPress site and the most relentlessly targeted endpoint by automated bots. The average WordPress site receives hundreds to thousands of login attempts from bots every single day without the site owner being aware. Hardening the login page is one of the highest-ROI security steps available.

What Is Two-Factor Authentication (2FA)?

2FA, or Two-Factor Authentication, adds a second layer of security by requiring both your password and a time-based OTP from a mobile app such as Google Authenticator or Authy during every login attempt. Even if an attacker knows your password, they cannot gain access without also having your phone to generate the current OTP, which changes every 30 seconds.

Recommended Plugins for 2FA and Login Protection

Adding HTTP Authentication as a Second Gate

Beyond plugins, you can add HTTP Basic Authentication over the entire wp-admin directory via .htaccess. This prompts for a username and password before PHP executes at all, blocking most bots before they ever reach WordPress:

# Create or append to /wp-admin/.htaccess
AuthType Basic
AuthName "Admin Area - Authorized Access Only"
AuthUserFile /home/yourusername/.htpasswd
Require valid-user

Create the password file with: htpasswd -c /home/yourusername/.htpasswd yourusername and follow the prompt to set a password for this layer.

Strong Passwords Are Non-Negotiable

Before discussing advanced tools, strong passwords are the absolute foundation. A good WordPress admin password must:

Hide wp-login.php by Changing the Login URL

The default WordPress login URL — yourdomain.com/wp-login.php — is universally known by every bot on the internet. Changing this to an unpredictable URL eliminates the vast majority of automated brute force attempts with zero additional server cost. It is one of the most cost-effective hardening steps available.

Popular Plugins for Changing the Login URL

Blocking wp-login.php Directly via .htaccess

To restrict direct access to wp-login.php to specific trusted IP addresses, add the following to your WordPress root .htaccess:

<Files wp-login.php>
Order deny,allow
Deny from all
Allow from 203.0.113.100
</Files>

Replace 203.0.113.100 with your actual IP, which you can check at whatismyip.com. Note that this approach does not work well if your ISP assigns a dynamic IP that changes frequently.

💡 Pro tip: Immediately bookmark the new login URL after changing it and inform all admin users. If the URL is forgotten, you can deactivate the plugin via FTP by renaming the plugin folder inside /wp-content/plugins/ to temporarily disable it and restore access to the default URL.

Refresh WordPress Salts and Secret Keys

WordPress uses a set of "Salts" and "Secret Keys" stored in wp-config.php to encrypt user cookies and sessions. If your server or database was ever accessed without authorization, regenerating the Salts immediately invalidates all active sessions — forcing every user to log out and re-authenticate with their actual password, and rendering any stolen session tokens useless.

When Should You Regenerate Salts?

How to Regenerate WordPress Salts Step by Step

1
Visit the WordPress Secret Key GeneratorGo to https://api.wordpress.org/secret-key/1.1/salt/ — it generates a new cryptographically random set on every page load.
2
Open wp-config.phpAccess it through DirectAdmin File Manager or your FTP client such as FileZilla.
3
Replace all 8 existing Salt definitionsFind the block starting with define('AUTH_KEY',...) through define('NONCE_SALT',...) and replace the entire block with the newly generated values.
4
Save and verifyAll logged-in users will be immediately signed out. Test login with correct credentials to confirm the site is working normally.
# Structure of Salts in wp-config.php — always generate fresh values from WordPress API
define('AUTH_KEY',         'value from api.wordpress.org/secret-key/1.1/salt/');
define('SECURE_AUTH_KEY',  'value from api.wordpress.org/secret-key/1.1/salt/');
define('LOGGED_IN_KEY',    'value from api.wordpress.org/secret-key/1.1/salt/');
define('NONCE_KEY',        'value from api.wordpress.org/secret-key/1.1/salt/');
define('AUTH_SALT',        'value from api.wordpress.org/secret-key/1.1/salt/');
define('SECURE_AUTH_SALT', 'value from api.wordpress.org/secret-key/1.1/salt/');
define('LOGGED_IN_SALT',   'value from api.wordpress.org/secret-key/1.1/salt/');
define('NONCE_SALT',       'value from api.wordpress.org/secret-key/1.1/salt/');

Disable Directory Listing in .htaccess

By default on Apache servers, accessing a directory URL that contains no index.html or index.php causes Apache to display a full file listing of that directory in the browser — known as Directory Listing or Directory Browsing.

This is a significant security risk. Attackers can map your entire site structure, discovering forgotten backup files, log files containing sensitive data, or configuration files that were never intended to be publicly accessible. Disabling this feature is a quick and essential hardening step.

Disable Directory Listing with a Single .htaccess Line

Open the .htaccess file at your WordPress root and add this directive:

Options -Indexes

This single line disables Directory Listing across the entire site including all subdirectories, because Apache inherits directives from parent directories downward. The change is immediate with no restart required.

Comprehensive .htaccess Security Hardening for WordPress

# Disable Directory Listing site-wide
Options -Indexes

# Protect wp-config.php from HTTP access
<Files wp-config.php>
Order deny,allow
Deny from all
</Files>

# Protect .htaccess itself from being read
<Files .htaccess>
Order deny,allow
Deny from all
</Files>

# Block PHP execution inside the uploads directory
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule ^wp-content/uploads/.*\.php$ - [F]
</IfModule>

# Disable XML-RPC if not needed (prevents DDoS amplification attacks)
<Files xmlrpc.php>
Order deny,allow
Deny from all
</Files>

⚠️ Important: Always back up your .htaccess before editing it. A single syntax error can cause your entire site to return a 500 Internal Server Error immediately. Test your site after every edit and keep the backup for quick rollback.

Keep WordPress Core, Plugins, and Themes Updated Regularly

Keeping software updated is the simplest security measure yet the most commonly neglected. Statistics from Sucuri Security show that over 60% of successfully compromised WordPress sites were running outdated core versions or plugins with known vulnerabilities already documented in public security databases.

Why Updates Are Critical for Security

When the WordPress team or a plugin developer patches a vulnerability, that vulnerability detail becomes public at the same time. Bots scanning the web begin targeting unpatched sites within hours or even minutes of a disclosure. The attack window is the time between a patch being released and you applying it — the faster you update, the smaller your exposure.

Configuring WordPress Auto-Updates

WordPress supports automatic updates for multiple components:

Safe Plugin Management Practices

✅ Best Practice: Test major updates on a Staging site before applying them to production, especially when many plugins are installed — major version bumps can introduce compatibility breaks that would impact live visitors.

Scanning for Malware on Your Hosting with cPGuard

Even with robust preventive measures in place, periodic proactive scanning remains important. Zero-day vulnerabilities emerge constantly, and some malware is designed to lie dormant before activating. cPGuard provides an on-demand scanner that can sweep your account for malware that may have slipped through — particularly sophisticated obfuscated malware designed to evade detection.

Running a cPGuard Scan Through DirectAdmin

1
Log in to DirectAdmin, go to Security, then select cPGuardThe dashboard shows scan statistics including the number and types of threats detected in recent history.
2
Click Scan Now or Manual ScanChoose a specific directory or select Scan Entire Account for a comprehensive sweep.
3
Wait for resultsScan duration depends on account size; typically 2 to 10 minutes for a standard 1-2 GB hosting account.
4
Review and act on flagged filesSuspicious files are listed with options to Quarantine, Delete, or Whitelist if confirmed as a false positive.
5
Set up Scheduled Scanning and Email AlertsConfigure weekly automatic scans and enable email notifications so you are alerted immediately when anything is detected.

Warning Signs Your WordPress Site May Already Be Compromised

🔒 AsiaGB Hosting alerts you immediately: The AsiaGB team sends automatic email notifications whenever cPGuard detects malware or suspicious activity in your account — you do not need to check the dashboard manually. This enables a rapid response before your visitors are affected.

FAQ — Frequently Asked Questions About WordPress Security on Shared Hosting

How does cPGuard differ from Wordfence — do I need both?
cPGuard operates at the Server and OS level; Wordfence operates at the WordPress Application layer. cPGuard scans every file on the server regardless of whether it belongs to WordPress, and blocks IPs before requests reach PHP. Since AsiaGB Hosting already includes cPGuard, Wordfence is not required. If you specifically want Wordfence's 2FA feature, you can install it for that purpose alone — consider disabling Wordfence's own firewall component to avoid resource duplication with cPGuard.
What is the practical difference between 755 and 644 permissions?
755 grants the Owner full access (read+write+execute) while Group and Others can read and execute but not write. It is used for directories because the execute bit is required to enter and traverse a directory. 644 grants the Owner read and write access while Group and Others get read only. It is used for regular files such as PHP, HTML, CSS, and JS — Apache executes PHP through its module system and does not need the execute bit set on the file itself.
If I set wp-config.php to 600, will WordPress still function correctly?
Yes. On a properly configured Shared Hosting server using suEXEC or per-user PHP-FPM pools, the web server runs with the same privileges as the file owner. PHP can therefore read wp-config.php even at permission 600. Other users on the server and other processes cannot read it, which is exactly the desired outcome for protecting database credentials stored in that file.
Will changing WordPress Salts immediately log out all users?
Yes. Every currently logged-in user will be signed out immediately and must re-authenticate with their actual password. This is the intended behavior — the authentication cookies all users hold are validated against the Salts, so changing them invalidates every existing session including any that an attacker may have stolen. Notify admin users before performing this action so they are not caught off guard.
Does "Options -Indexes" in .htaccess disable Directory Listing across the whole site?
Yes, when placed in the .htaccess at the WordPress root, it applies to the entire site including all subdirectories, because Apache inherits directives from parent directories automatically. To restrict the rule to a single directory, create a separate .htaccess file inside that specific directory containing the same directive.
Does AsiaGB Hosting support the latest PHP version for WordPress?
Yes. AsiaGB allows you to select your PHP version through DirectAdmin, with support for PHP 8.1, 8.2, and 8.3. WordPress 6.x fully supports PHP 8.x. Running a current PHP version is also a security benefit, since end-of-life PHP releases no longer receive security patches — meaning newly discovered vulnerabilities in those versions will never be fixed.

Hosting with cPGuard Included Free on Every Plan

AsiaGB Hosting ships cPGuard Security Suite with every account on fast SSD Storage, with 99% Uptime and easy-to-use DirectAdmin. Secure, reliable, and fully WordPress-ready.

View Hosting Plans

View all cheap Thailand web hosting plans →