Cloudways Security: The Definitive Guide to Protecting Your Website

By ASRAF MASUM

Publish: 2 Aug, 2026
Updated: August 2, 2026 @ 2:04 PM
Reading Time: 27 minutes

Summarize this blog post with: ChatGPT | Perplexity | Claude | Grok

You have probably chosen managed hosting because you do not want to maintain every server component yourself. However, a secure Cloudways setup still depends on knowing which protections are automatic, which are plan-specific or paid, and which remain your responsibility. In this guide, we will explain the complete Cloudways security stack, how to configure it, and how to verify that your website is genuinely protected.

Key Takeaways

  • Cloudways security is a layered managed-hosting framework covering server protection, network filtering, SSL, account controls, vulnerability monitoring, backups, and optional edge-security services.
  • Cloudways Flexible includes an Imunify360-powered security layer, while Malware Protection remains a paid, disabled-by-default add-on for Flexible applications.
  • Cloudways Autonomous includes Cloudflare Enterprise and built-in Malware Protection, with newly launched Autonomous applications protected by default.
  • Cloudflare Enterprise adds edge-level DDoS mitigation, Web Application Firewall rules, rate limiting, bot controls, and malicious-request filtering.
  • Vulnerability scanning and malware scanning are different controls. The Vulnerability Scanner finds known WordPress weaknesses, while Malware Protection detects or removes malicious code.
  • Website owners remain responsible for application updates, administrator accounts, third-party code, user permissions, access credentials, and tested recovery procedures.
  • Managed hosting is a security foundation, not a security guarantee. Your final risk level depends on configuration, patching discipline, application quality, monitoring, and recovery readiness.

What Is Cloudways Security and How Does It Work?

Cloudways security is a layered managed-hosting framework that combines server protection, network filtering, account controls, application monitoring, backups, and optional edge-security services. Cloudways security is not a single product or plugin. It is a combination of controls managed by Cloudways, the underlying infrastructure provider, third-party security technologies, and the website owner.

For example, Cloudways can patch the managed server environment and block suspicious network traffic, but it cannot prevent an administrator from installing an abandoned WordPress plugin or sharing a weak password.

Cloudways Flexible and Cloudways Autonomous also use different operating models. Flexible gives customers more server-level control and supports WordPress, Magento, Laravel, and other PHP applications. Autonomous focuses on fully managed, autoscaling WordPress hosting with integrated Cloudflare Enterprise and less infrastructure administration.

A useful way to understand Cloudways website security is to divide it into nine layers:

  1. Cloud infrastructure
  2. Server and operating system
  3. Network and firewall
  4. Edge CDN, WAF, and DDoS protection
  5. Application and malware protection
  6. WordPress vulnerability and update management
  7. Account and administrative access
  8. Backups and disaster recovery
  9. Monitoring and incident response

[Insert image: A custom layered diagram showing Cloud infrastructure, Cloudways server controls, Cloudflare edge security, application security, access management, and backups | Alt text: “Visualize Cloudways security layers across hosting and WordPress”]

Cloudways Shared-Responsibility Matrix

The shared-responsibility model divides security duties among the infrastructure provider, Cloudways, integrated security services, and the customer. A managed host reduces technical workload, but application security and business risk do not transfer completely to the host.

Security layerCloud providerCloudwaysThird-party serviceCustomer
Physical data centerPrimaryOversightNot applicableNone
Compute and storage infrastructurePrimaryProvisioning and managementNot applicableCapacity selection
Operating-system patchingLimitedPrimaryImunify360 supportReview notifications
Server firewallInfrastructure controlsPrimaryImunify360Review incidents and rules
Edge WAF and DDoS mitigationNetwork-level supportIntegrationCloudflare EnterpriseActivation and configuration
WordPress core and plugin updatesNoneOptional toolingPatchstack/Site ManagerPrimary
Administrator accountsNonePlatform controlsAuthentication providerPrimary
Malware detection and cleanupNonePlatform integrationImunify360Activation, review, and follow-up
Backup creationStorage infrastructureBackup toolingStorage serviceFrequency and retention decisions
Restore testingInfrastructure supportRestore toolsNot applicablePrimary
Incident-response planNoneSupport assistanceSecurity vendorsPrimary

Managed hosting reduces the customer’s server-management workload, but it does not eliminate responsibility for application updates, credentials, user permissions, and third-party software.

Why Does Cloudways Security Matter for WordPress and Business Websites?

Cloudways security matters because a compromised website can create downtime, data exposure, fraudulent transactions, malicious redirects, browser warnings, SEO loss, and reputational damage. A hosting compromise can affect the infrastructure, while an application compromise can occur through plugins, themes, credentials, uploads, APIs, or custom code.

For example, malware injected through an outdated plugin may create thousands of spam URLs. Google can detect those pages, display security warnings, or remove affected URLs from search results until the site is cleaned and reviewed.

Google’s Search Console Security Issues report can identify signs of hacking, phishing, malware, harmful downloads, and other behavior that may endanger visitors. Google Safe Browsing also identifies unsafe websites and warns users or site owners about potential harm.

Common Business Consequences of a Website Compromise

A compromised Cloudways application may cause:

  • Checkout-page manipulation
  • Stolen administrator credentials
  • Unauthorized customer-data access
  • Malicious JavaScript injections
  • SEO spam and doorway pages
  • Affiliate-link replacement
  • Email-domain blacklisting
  • Cryptocurrency-mining scripts
  • Phishing pages hosted under your domain
  • Lost advertising traffic
  • Browser and search-result warnings
  • Extended recovery downtime

An affiliate website may lose rankings after malware creates Japanese keyword spam. A WooCommerce store may lose orders if injected code redirects customers away from the checkout. A SaaS landing page may become unavailable during a traffic flood if origin resources are overwhelmed.

Your security plan should therefore protect confidentiality, integrity, availability, recoverability, and search visibility, rather than focusing only on malware scanning.

How Does the Cloudways Security Architecture Work?

The Cloudways security architecture works by filtering threats at multiple stages before, during, and after a request reaches an application. Infrastructure protections defend the hosting environment, server controls inspect traffic and access attempts, edge services stop malicious requests earlier, and application controls detect vulnerable or infected software.

1. Cloud Infrastructure Layer

The cloud infrastructure layer supplies the physical facilities, storage, networking, and compute resources beneath Cloudways. Flexible customers may deploy infrastructure from providers such as DigitalOcean, Amazon Web Services, Google Cloud, Vultr, or Linode, while Autonomous uses a more abstracted managed architecture.

Infrastructure-provider compliance or certification does not automatically make your website compliant. PCI DSS, GDPR, HIPAA, SOC 2, or ISO requirements may also cover application design, access logs, data handling, business processes, vendors, and organizational controls.

2. Server and Operating-System Layer

Cloudways manages significant server-administration functions, including operating-system maintenance and server security. The current security-management documentation centers on Imunify360 for firewalling, brute-force protection, malicious-traffic analysis, reputation monitoring, and web-application filtering.

Cloudways states that key Imunify360 features other than the Malware Protection add-on are enabled by default across Cloudways plans at no additional cost. The documentation also says security-management activity reports are retained in the dashboard for the most recent 30 days.

3. Network and Firewall Layer

The network layer decides whether an IP address, request pattern, country, service, or connection should be allowed, challenged, limited, or blocked.

The Cloudways server-level firewall filters malicious traffic before it reaches hosted applications and allows administrators to control access using IP- and country-based rules. Cloudways also exposes security incidents so administrators can review suspicious activity and whitelist or blacklist individual IP addresses.

4. Edge, CDN, WAF, and DDoS Layer

Edge protection filters requests on a globally distributed network before those requests reach the origin server. Cloudflare Enterprise can provide an edge Web Application Firewall, DDoS mitigation, rate limiting, bot controls, caching, and request filtering.

For example, a rate-limiting rule can challenge an IP that makes excessive requests to /wp-login.php, while cached pages continue to load from Cloudflare’s edge network.

5. Application and Malware Layer

Application security protects WordPress, WooCommerce, Magento, Laravel, PHP applications, databases, files, themes, and plugins.

On Flexible, Malware Protection is a separately activated, per-application add-on. On Autonomous, Cloudways documents built-in Malware Protection with proactive defense, real-time scanning, automated detection, and automatic removal.

6. WordPress Vulnerability and Update Layer

The Cloudways Vulnerability Scanner checks installed WordPress core, plugin, and theme versions against Patchstack vulnerability data. It identifies known vulnerable versions but does not scan a site for existing malware.

How to Use the Cloudways Vulnerability Scanner

This official demonstration shows how to open the Vulnerability Scanner, review WordPress core, plugin, and theme findings, and access Patchstack remediation information for insecure components.

Video: “Secure Your WordPress Site with Vulnerability Scanner on Cloudways” by Cloudways.

Cloudways Site Manager and the SafeUpdates workflow can automate testing and deployment of WordPress updates. The current Cloudways Site Manager product builds on SafeUpdates with update management, visual regression testing, activity logs, and multi-site administration.

7. Account and Access-Control Layer

The account layer controls who can log in, manage servers, access applications, view billing information, create API credentials, or contact support.

Cloudways supports two-factor authentication for account owners and team members. It also provides team roles and permissions for servers, applications, projects, billing, and support functions.

8. Backup and Recovery Layer

Backups preserve application files and databases so they can be restored after malware, deletion, corruption, failed updates, or infrastructure problems.

Cloudways provides automated off-site backups, on-demand application backups, and restore-point workflows. Flexible customers can configure backup frequency and retention, while both product families have application-recovery mechanisms.

9. Monitoring and Incident-Response Layer

Monitoring identifies abnormal activity before a small problem becomes a prolonged incident. Useful evidence includes firewall incidents, Cloudflare analytics, access logs, error logs, malware reports, vulnerability alerts, uptime checks, and Google Search Console security notifications.

A monitoring system is valuable only when someone reviews and acts on its alerts. For example, a vulnerability notification should trigger an update, replacement, temporary mitigation, or vendor review rather than remaining unread.

→ Explore Cloudways Security Features

Which Cloudways Security Features Are Included and Which Cost Extra?

Cloudways includes core server, SSL, access, vulnerability, and backup controls, while advanced malware removal, edge security, update automation, and premium support may be paid or product-specific. The exact combination depends on whether you use Flexible or Autonomous and whether a feature must be activated manually.

Feature status last verified: August 2, 2026. Cloudways can change inclusions, pricing, interfaces, or product names, so confirm commercial details in your account before purchasing.

Security featureCloudways FlexibleCloudways AutonomousDefault or activation statusCost classification
Imunify360 server securityIncludedPlatform-managed securityCore protections enabledIncluded
Server firewall and incident logsIncludedLess server-level exposureEnabled on applicable environmentIncluded
IP and country allow/block rulesAvailable through Flexible security controlsCloudflare and managed controls differManual review/configurationIncluded or product-specific
Abusive-login protectionIncluded through server securityPlatform-managedAutomaticIncluded
Let’s Encrypt SSLAvailableAvailable; Cloudflare may provide end-to-end encryptionManual installation where requiredIncluded
HTTPS redirectionAvailableAvailableManual activation or setup promptIncluded
Automated backupsIncludedIncludedConfigurable or platform-managedIncluded
On-demand backupsAvailableAvailableManualIncluded
Point-in-Time RestoreAvailableAvailableManual restore selectionIncluded
Two-factor authenticationAccount-wideAccount-wideManual activation per userIncluded
Team roles and permissionsAvailableAvailableManual configurationIncluded
Vulnerability ScannerWordPress applicationsVerify current application dashboardIntegrated scannerIncluded/application-specific
Cloudflare EnterpriseOptional add-onIntegrated with AutonomousFlexible activation requiredPaid on Flexible; included on Autonomous
Cloudflare WAF and DDoS controlsThrough Cloudflare EnterpriseIntegratedConfigurablePlan-specific
Malware ProtectionAvailable for supported Flexible appsBuilt inDisabled by default on Flexible; default for new Autonomous appsPaid on Flexible; included on Autonomous
SafeUpdates/Site ManagerWordPress add-onVerify current plan workflowSubscription and configuration requiredPaid or plan-specific
Root-cause forensicsNot included in Malware ProtectionNot presented as complete forensicsSpecialist investigation requiredSeparate responsibility
Advanced or Premium SupportOptionalOptionalSubscription requiredPaid

Cloudways documents free Let’s Encrypt SSL support for Flexible and Autonomous. Its April 2026 instructions state that the certificate utility is included in all server plans, while integrated Cloudflare Enterprise can already provide end-to-end encryption.

Which Security Features Require Paid Add-Ons?

The most important paid or commercially variable features include:

  • Cloudflare Enterprise on Flexible
  • Malware Protection on Flexible
  • Cloudways Site Manager or SafeUpdates functionality
  • Advanced or Premium Support
  • Third-party WordPress security services
  • Independent off-platform backup storage
  • Security incident investigation or forensic services

Cloudways currently lists Cloudflare Enterprise from $4.99 per domain per month and Flexible Malware Protection from $4 per application per month. SafeUpdates or Site Manager pricing starts at $3 per site for smaller portfolios, although all prices can change.

“By default, it is disabled on all Cloudways applications. To activate this feature, you must subscribe to the add-on.”

— Syed Shabeeh Muhammad, Cloudways Help Center documentation author, 2026

This quotation specifically describes Malware Protection on Cloudways Flexible. It matters because basic server protection and paid application-level malware protection should not be treated as the same service.

Real Flexible Malware-Protection Cost for Multiple Websites

Cloudways’ June 29, 2026 documentation lists these Flexible pricing tiers:

  • 1–5 applications: $4 per application per month
  • 6–15 applications: $3 per application per month
  • 15 or more applications: $2 per application per month

Assuming the published tier applies to every protected application at that portfolio size:

Protected applicationsPublished rateEstimated monthly costEstimated annual cost
1$4 per app$4$48
5$4 per app$20$240
10$3 per app$30$360
25$2 per app$50$600

Agencies should calculate security add-ons at portfolio level rather than evaluating only the hosting-server price. Review Cloudways pricing and add-on costs before finalizing a multi-site budget.

What Is the Difference Between Cloudways Flexible and Autonomous Security?

Cloudways Flexible provides more server and application flexibility, while Cloudways Autonomous provides a more integrated WordPress security and autoscaling environment. Flexible is suitable for varied PHP workloads and users who want infrastructure choices. Autonomous is designed for WordPress users who prefer fewer server-management decisions.

Security considerationCloudways FlexibleCloudways Autonomous
Supported applicationsWordPress, WooCommerce, Magento, Laravel, PHPWordPress-focused
Server-management exposureMore server-level controlsInfrastructure abstracted
Cloud provider selectionMultiple infrastructure providersManaged Autonomous architecture
Scaling modelManual vertical scalingAutomatic scaling
High-availability modelDepends on selected architectureManaged autoscaling and load balancing
Cloudflare EnterpriseOptional paid integrationIntegrated
Malware ProtectionPaid per applicationIncluded by default for new applications
Server firewall visibilityDetailed security controls and incidentsManaged platform controls
WAF and edge controlsAvailable through Cloudflare EnterpriseIntegrated Cloudflare controls
Partial restore optionsCloudways documents full and partial restoreVerify current dashboard options
Best forAgencies, developers, mixed PHP apps, configurable environmentsWordPress sites needing hands-off scaling and integrated protection

Cloudways positions Autonomous as fully managed WordPress hosting with autoscaling, integrated Cloudflare Enterprise, and no direct server-management requirement. Flexible supports multiple application types and exposes more infrastructure and server-management controls.

You can review the broader product differences in the Cloudways Flexible vs. Autonomous comparison.

How Each Platform Responds to Common Attack Scenarios

ScenarioFlexible responseAutonomous responseCustomer action
WordPress brute-force attackServer firewall, anti-abuse controls, optional CloudflareIntegrated Cloudflare controls and managed securityEnforce strong passwords and 2FA
Sudden traffic floodServer protection plus optional edge serviceAutoscaling plus integrated edge protectionConfirm limits and monitor costs
Vulnerable WordPress pluginVulnerability notification and optional update automationWordPress-focused monitoring and managed toolingPatch, replace, or remove plugin
Malware injectionPaid Malware Protection or external scannerBuilt-in Malware ProtectionReset credentials and investigate cause
Stolen SFTP credentialsIP restrictions and credential rotationApplication-access controlsRevoke credentials immediately
DDoS attackCloudflare Enterprise strongly recommendedIntegrated Cloudflare protectionReview events and enable attack controls
Failed plugin updateRestore point or staging rollbackManaged restore workflowTest updates before production
Regional malicious trafficCountry-level or Cloudflare controlsCloudflare traffic controlsAvoid blocking legitimate markets

Is Cloudways Autonomous Always More Secure?

Cloudways Autonomous is not automatically the better choice for every workload. It provides a more integrated WordPress security model, but Flexible offers greater control for custom PHP, Laravel, Magento, and agency environments.

For example, a developer running a Laravel API may need Flexible’s server and application-access controls. A WooCommerce store expecting unpredictable campaign traffic may prefer Autonomous because autoscaling and Cloudflare Enterprise are integrated.

The right choice depends on application compatibility, operational skill, traffic patterns, required controls, recovery objectives, and total add-on cost.

How Does the Cloudways Firewall Protect Websites?

The Cloudways firewall protects websites by analyzing network and application traffic, blocking suspicious connections, identifying abusive access attempts, and exposing incidents for administrator review. Current Cloudways documentation describes Imunify360 as the central server-security layer for firewalling, WAF rules, brute-force protection, reputation monitoring, and anti-bot controls.

Imunify360 Server-Level Firewall

The Imunify360 firewall evaluates incoming traffic and can block patterns associated with:

  • Brute-force attempts
  • Port scanning
  • Denial-of-service activity
  • Malicious IP addresses
  • Known attack sources
  • Suspicious HTTP requests
  • SQL injection attempts
  • Cross-site scripting attempts

Cloudways states that Imunify360’s integrated WAF filters HTTP traffic and includes rule sets for popular content-management systems.

[Insert image: Cloudways Flexible Security Overview showing attack intensity and incident graphs | Alt text: “Review Cloudways security incidents in the Flexible dashboard”]

IP Whitelisting and Blacklisting

IP rules allow you to trust or block specific addresses. Whitelisting is useful for office networks, VPN exit addresses, developers, monitoring systems, or remote-database connections.

A whitelist should be narrow. For example, allow a developer’s static office IP for two weeks rather than allowing SSH access from every address worldwide.

Country-Level Blocking

Country-level rules can reduce attack traffic from regions where you do not operate. However, country blocking can also block customers, remote workers, search tools, payment services, uptime monitors, or international search crawlers.

An English-language affiliate website targeting the United States, United Kingdom, Canada, and Australia should not apply broad geographic restrictions without reviewing analytics, crawler logs, and conversion data.

The Old MalCare Bot Protection Is No Longer Current

Cloudways’ July 2, 2026 security documentation says the former WordPress-specific MalCare Bot Protection feature has been sunset across the fleet. The same documentation describes a newer server-level Anti-Bot Protection control within the Imunify360 firewall settings.

Therefore, instructions telling users to enable the old MalCare Bot Protection switch are outdated. Do not confuse the retired WordPress application feature with the newer server-security anti-bot controls.

Cloudways’ general features page also continues to mention Fail2ban, while its newer operational security documentation emphasizes Imunify360 PAM and firewall controls. The current Security dashboard should be treated as the operational source of truth.

Does Cloudways Protect Websites Against DDoS Attacks?

Cloudways provides layered DoS and DDoS defenses, but the strongest documented edge-level mitigation comes from Cloudflare Enterprise. Server-level controls can block abusive IPs and limit harmful traffic, while Cloudflare can absorb or challenge malicious requests before they consume origin-server resources.

Cloudways’ current security guide identifies several layers:

  • Cloudflare Enterprise DDoS mitigation
  • Cloudflare WAF and global rate limiting
  • Imunify360 server-level abusive-login and IP blocking
  • Firewall restrictions for SSH, SFTP, and remote MySQL
  • Enhanced DoS request tracking and anti-bot challenges

Server-Level DoS Protection vs. Edge DDoS Mitigation

Server-level protection acts near the origin server. Edge mitigation acts across a distributed network before attack traffic reaches the origin.

For example, a server firewall may block an IP after identifying abusive behavior. Cloudflare can challenge or discard attack traffic at edge locations without forwarding every request to your server.

Cloudflare Enterprise is therefore especially relevant for:

  • Campaign landing pages
  • WooCommerce stores
  • Membership websites
  • High-traffic publishers
  • SaaS marketing sites
  • Websites targeted by bot floods
  • Applications with expensive dynamic requests

Cloudflare Enterprise on Cloudways adds edge-level security controls such as DDoS mitigation, Web Application Firewall rules, rate limiting, and malicious-request filtering.

How to Integrate Cloudflare Enterprise With Cloudways

This official walkthrough shows how to activate Cloudflare Enterprise, configure the required CNAME record, manage protected domains, and review security-related features such as Under Attack Mode.

Video: “How to Integrate Cloudflare CDN With Your Website | Cloudways 101” by Cloudways.

A practical Cloudflare security configuration guide can help you document WAF rules, caching exclusions, challenge behavior, rate limits, and crawler allowances.

How Does Cloudways Malware Protection Work?

Cloudways Malware Protection detects suspicious files or behavior, scans applications, and can remove or quarantine malicious code, but its availability and cost differ between Flexible and Autonomous. Flexible customers must subscribe per application, while Autonomous includes built-in Malware Protection for newly launched applications.

Cloudways Flexible Malware Protection

On Flexible, Cloudways Malware Protection is an application-level security add-on that provides malware scanning, proactive detection, automated cleaning, URL analysis, file monitoring, and selected database protection.

Cloudways currently documents support for all application types hosted on Flexible. Database cleaning is specifically documented for WordPress, Magento, and Joomla.

[Insert image: Cloudways Application Security Malware Protection screen showing Protected, Unprotected, and Infected statuses | Alt text: “Enable Cloudways Malware Protection for a Flexible application”]

How to Enable Cloudways Malware Protection

This official tutorial demonstrates where to find Malware Protection in the Cloudways dashboard, how to activate the add-on, and how to review detected malware, scan history, and Proactive Defense events.

Video: “How to Activate Malware Protection on Cloudways” by Cloudways.

Cloudways Autonomous Malware Protection

Cloudways Autonomous includes built-in Malware Protection with continuous scanning, proactive defense, automated detection, removal, event logs, and alerts. Cloudways states that new Autonomous applications have Malware Protection enabled by default at no additional cost.

[Insert image: Autonomous Malware Protection dashboard showing Proactive Defense events and application status | Alt text: “Review Cloudways Autonomous malware protection events”]

Vulnerability Scanner vs. Malware Protection

The Cloudways Vulnerability Scanner identifies known vulnerabilities in WordPress core, plugins, and themes, while Malware Protection searches for malicious code and infected files.

ControlMain purposeExample resultRequired response
Vulnerability ScannerFind known software weaknessesPlugin version affected by a CVEUpdate, replace, remove, or mitigate
Malware scannerDetect malicious codeInjected PHP backdoorQuarantine, remove, or restore
WAFBlock suspicious requestsSQL injection payload challengedReview event and tune rule
Patch managementRemove vulnerable software versionsPlugin upgraded to fixed releaseValidate functionality
Backup restoreRecover an earlier stateClean version restoredPatch cause before reopening
Forensic analysisIdentify entry point and scopeCompromised admin account foundRevoke access and close root cause

A vulnerability does not prove that malware exists. Malware detection does not prove that every known vulnerability has been fixed.

Does Cloudways Automatically Remove Malware?

Cloudways documents automated cleanup and quarantine capabilities within Malware Protection. However, an automated cleanup should be followed by a security review rather than treated as the end of the incident.

After cleanup:

  1. Reset WordPress administrator passwords.
  2. Rotate Cloudways, SFTP, SSH, database, and API credentials.
  3. Review all administrator accounts.
  4. Update WordPress core, themes, and plugins.
  5. Remove abandoned software.
  6. Search for unauthorized scheduled tasks.
  7. Inspect database users and injected content.
  8. Review access and error logs.
  9. Check Cloudflare and firewall events.
  10. Verify a clean backup.
  11. Re-scan the site.
  12. Review Google Search Console Security Issues.

Does Cloudways Identify How the Website Became Infected?

Cloudways Malware Protection does not provide complete root-cause analysis identifying the exact plugin, theme, account, upload, or integration through which an infection entered. Cloudways says detailed forensic investigation falls outside the scope of the add-on.

Possible infection routes include:

  • Outdated plugins or themes
  • Compromised administrator accounts
  • Weak SFTP credentials
  • Insecure custom PHP code
  • Unsafe file uploads
  • Vulnerable third-party scripts
  • Leaked API tokens
  • Existing malware imported during migration

For an end-to-end process, use a dedicated website malware removal guide that covers containment, cleanup, root-cause investigation, validation, and reinfection prevention.

Do You Still Need a WordPress Security Plugin on Cloudways?

A WordPress security plugin may still be useful on Cloudways when it provides a required application-level control that is not already covered by the hosting stack. A plugin should solve a documented gap, not duplicate firewalling, malware scanning, login limiting, and bot filtering without a clear reason.

When a Security Plugin May Add Value

A WordPress security plugin may be useful for:

  • WordPress activity logging
  • Administrator login alerts
  • File-integrity monitoring
  • User-session management
  • Login-page controls
  • Plugin-specific virtual patching
  • Comment-spam controls
  • Change auditing
  • Compliance-oriented reporting

When a Plugin May Be Redundant

A plugin may be redundant when Cloudways, Imunify360, Cloudflare Enterprise, and Malware Protection already provide:

  • Server-level traffic filtering
  • Edge WAF rules
  • IP blocking
  • Bot challenges
  • Brute-force mitigation
  • Malware scanning
  • File monitoring
  • Rate limiting

Duplicate controls can create false positives, inconsistent allowlists, caching problems, blocked APIs, performance overhead, or confusing incident logs.

Use the following decision framework:

QuestionKeep the plugin if “Yes”
Does it provide a control missing from Cloudways?Yes
Can you explain which layer it protects?Yes
Can you test that it does not conflict with Cloudflare or caching?Yes
Does someone review its alerts?Yes
Does it provide useful evidence for incidents?Yes
Is the plugin actively maintained?Yes

→ Evaluate Cloudways Security Fit

Review the best WordPress security plugins by comparing unique controls rather than counting the number of features advertised.

How Do You Secure Cloudways Account and Administrative Access?

Cloudways account security requires two-factor authentication, least-privilege team permissions, restricted server access, separate credentials, and prompt removal of former users. Server protections cannot compensate for a stolen account with unrestricted access.

Enable Two-Factor Authentication for Every User

Cloudways allows account owners and team members to activate two-factor authentication. Authentication-app codes and backup codes can be used during login, while phone verification is documented for primary account holders.

[Insert image: Cloudways account Security tab showing the two-factor authentication activation option | Alt text: “Enable Cloudways two-factor authentication for account security”]

Store backup codes in a secure password manager. Do not save the only recovery copy inside the same email account used for Cloudways login.

Use Least-Privilege Team Permissions

Cloudways team roles can limit access to specific servers, applications, projects, billing functions, and support features.

For example:

  • A content editor does not need Cloudways access.
  • A freelance developer may need one application, not the entire server.
  • A finance employee may need billing access, not SFTP credentials.
  • A support contractor may need temporary application access with an expiry date.

Avoid Shared Administrator Accounts

Each person should have an individual Cloudways account and individual application credentials. Cloudways allows team members to create separate application credentials instead of sharing one master login.

Individual accounts make it easier to remove access, attribute changes, rotate credentials, and investigate incidents.

Restrict SSH, SFTP, and Database Access

Cloudways Flexible can block all SSH and SFTP connections except approved IP addresses. Cloudways describes this whitelist-only configuration as the more secure option, although dynamic residential IP addresses require additional planning.

Master credentials can access every application on a server and may also provide remote database access. Application credentials restrict access to a particular application and should be preferred for contractors or limited roles.

Prefer SSH Keys Over Passwords

SSH key authentication reduces exposure to password guessing and credential reuse. Protect private keys with a passphrase and revoke them when a developer leaves the project.

“SSH keys are very hard to decipher with these attacks.”

— Usama Zafar, Cloudways Help Center documentation author, 2025

The quotation refers to dictionary and brute-force attacks against password-based server access. SSH keys still require safe private-key storage, passphrases, device security, and revocation procedures.

[Insert image: Cloudways SSH Public Keys screen showing an authorized key entry | Alt text: “Add SSH keys to secure Cloudways server access”]

Protect API Tokens

API tokens should be treated like passwords. Store them in secret-management systems, limit which systems can read them, avoid including them in Git repositories, and rotate them after staff or vendor changes.

Cloudways documentation notes that an account-email change regenerates the API key, which means integrations must be updated afterward.

How Do Cloudways Backups and Point-in-Time Restore Work?

Cloudways backups preserve application files and databases at selected restore points, allowing recovery after accidental deletion, failed updates, corruption, or a security incident. Backups are a recovery control rather than a malware-prevention control because a backup does not stop an attacker from compromising the live application.

Cloudways Flexible includes automated off-site server-level backups and on-demand application backups. Cloudways states that new Flexible servers default to backups every 24 hours with one-week retention, although both settings can be customized.

“Backup is not just a feature but a business requirement to avoid business loss and unforeseen situations.”

— Usama Zafar, Cloudways Help Center documentation author, 2026

A backup becomes operationally valuable only after you confirm that it contains the required files, database records, configurations, and transaction data and that the restore process works.

Automated Backups

Automated backups should reflect how often your data changes.

  • A static brochure website may tolerate daily backups.
  • A lead-generation site may require backups every 6–12 hours.
  • A membership site may require hourly backups.
  • A busy WooCommerce store may require a shorter recovery point plus order-level redundancy.

How to Configure Cloudways Backups

This official tutorial explains server-level and application-level backups, including backup frequency, retention, scheduled backups, on-demand backups, and downloading a local backup through SFTP.

Video: “How to Backup Servers and Applications | Cloudways 101” by Cloudways.

On-Demand Backups

Create an on-demand backup before:

  • Updating WordPress core
  • Updating critical plugins
  • Changing PHP versions
  • Deploying custom code
  • Editing database tables
  • Changing DNS or CDN architecture
  • Running bulk content operations
  • Removing malware
  • Performing a migration

Point-in-Time Restore

Cloudways Point-in-Time Restore allows an application to be restored from a selected backup timestamp. Flexible supports complete, web-file-only, or database-only restore options in the documented workflow.

Cloudways’ June 18, 2026 restore documentation contains inconsistent wording about whether Autonomous permits only full restoration or also exposes file/database choices later in the workflow. Verify the options displayed in your current dashboard before relying on partial Autonomous restore.

[Insert image: Cloudways Backup and Restore screen showing available restore points | Alt text: “Select Cloudways backup restore points for application recovery”]

Deleted-Application and Server Recovery Limits

Cloudways states that deleted Flexible servers and applications may remain recoverable for up to 14 days when a usable backup exists. Staging applications cannot be recovered, and data becomes permanently unavailable after the retention window expires.

Recovered servers may receive new IP addresses. DNS records, SSL certificates, email services, and add-ons may therefore need to be reconfigured after restoration.

Recovery Time Objective and Recovery Point Objective

Recovery Time Objective is the maximum acceptable time required to restore service. Recovery Point Objective is the maximum acceptable amount of recent data that can be lost.

Website typeExample RTOExample RPOSuggested backup approach
Personal blog24 hours24 hoursDaily backup
Affiliate content site8 hours12–24 hoursDaily plus pre-change backup
Lead-generation site4 hours4–12 hoursMultiple backups per day
Membership site2 hours1–4 hoursFrequent database backups
WooCommerce store1 hour or less15–60 minutesHigh-frequency backup and order redundancy
SaaS applicationBusiness-definedBusiness-definedApplication-aware backup and database replication

These are planning examples, not Cloudways guarantees. Set objectives from the financial impact of downtime and lost data.

Use a detailed WordPress backup and restore guide to document restore ownership, test frequency, DNS dependencies, and off-platform copies.

How Do You Secure a Cloudways Website Step by Step?

A secure Cloudways configuration involves enabling account protection, restricting administrative access, patching applications, filtering malicious traffic, maintaining backups, and testing recovery procedures. The following order addresses the highest-impact risks before optional optimizations.

1. Enable Two-Factor Authentication

Enable two-factor authentication for the account owner and every team member. Save recovery codes securely and test account recovery.

2. Audit Team Access

Remove former employees, agencies, contractors, and unused invitations. Reduce each remaining user to the minimum required permissions.

3. Install SSL and Force HTTPS

Install Let’s Encrypt SSL where required and enable HTTPS redirection. Cloudways supports Let’s Encrypt for both Flexible and Autonomous, while integrated Cloudflare may already provide end-to-end encryption.

[Insert image: Cloudways SSL Certificate screen showing Let’s Encrypt and HTTPS redirection | Alt text: “Install Cloudways SSL and force HTTPS redirection”]

4. Confirm SSL Renewal and Domain Coverage

Verify that the certificate covers the root domain, www hostname, and required subdomains. Check renewal status after DNS or Cloudflare changes.

5. Restrict SSH, SFTP, and Database Access

Use whitelist-only access where practical. Prefer application credentials over master credentials, use SSH keys, and remove temporary access when work is completed.

6. Review Security Incidents

Open the Flexible server Security dashboard and inspect blocked requests, attack sources, affected applications, and repeated patterns.

Do not whitelist an IP simply because a developer says access is blocked. Confirm the IP, request path, user agent, action, and expected behavior first.

7. Configure Cloudflare Enterprise Where Appropriate

Flexible sites with meaningful commercial risk should evaluate Cloudflare Enterprise. Autonomous customers should review the integrated Cloudflare controls rather than assuming every option is correctly tuned.

Enable or review:

  • Web Application Firewall
  • DDoS protection
  • Rate limiting
  • Browser Integrity Check
  • Under Attack Mode procedures
  • Bot controls
  • Cache exclusions
  • Origin connectivity
  • AI crawler preferences

8. Review Vulnerability Scanner Findings

Treat each finding as an actionable risk.

  • Update when a fixed version exists.
  • Remove abandoned software.
  • Replace plugins with no patch.
  • Apply compensating WAF rules when immediate patching is impossible.
  • Test critical updates in staging.

[Insert image: Cloudways Vulnerability Scanner showing an affected WordPress plugin and recommendation | Alt text: “Fix Cloudways WordPress vulnerability scanner findings”]

9. Patch WordPress Core, Plugins, and Themes

Apply security updates promptly. Test high-risk updates in staging and maintain an inventory of every active plugin, theme, integration, and custom code component.

Use the WordPress security checklist to cover application-level settings beyond hosting.

10. Decide Whether Malware Protection Is Required

Flexible customers should consider Malware Protection when:

  • The website produces revenue.
  • The application stores customer data.
  • Multiple administrators upload files.
  • The site has a history of infection.
  • Manual malware monitoring is not realistic.
  • Rapid cleanup is operationally important.

A low-value test site may rely on basic protections and external scanning. A business-critical WooCommerce store should not depend on occasional manual checks.

11. Configure Backups Around Data Change

Choose backup frequency from your Recovery Point Objective. Create an on-demand backup before major changes and keep an independent copy for business-critical websites.

12. Test a Restore

Restore a backup to staging or a safe test environment. Confirm pages, database records, logins, forms, payment integrations, scheduled tasks, and media files.

13. Configure Notifications

Send important CloudwaysBot notifications to monitored email or Slack channels. Cloudways supports team notifications through connected channels.

14. Document an Incident-Response Procedure

The procedure should identify:

  • Who can disable access
  • Who contacts Cloudways Support
  • Who takes a forensic copy
  • Who resets credentials
  • Who restores backups
  • Who verifies payments and forms
  • Who communicates with customers
  • Who requests search-engine review
  • Who approves reopening the site

15. Verify Search and Monitoring Crawlers

Test Googlebot, Bingbot, SEO crawlers, uptime monitors, payment webhooks, email integrations, and APIs after changing firewall or Cloudflare rules.

By following these steps, you can build a repeatable how to secure a WordPress website workflow rather than relying on a one-time setup.

Can Cloudways Security Settings Block Googlebot or AI Crawlers?

Cloudways security settings can block legitimate crawlers when IP rules, country restrictions, WAF rules, rate limits, or bot challenges are too aggressive. Search engines, SEO tools, uptime monitors, payment services, and AI crawlers may resemble automated traffic, so every major rule change should be followed by log review and crawl testing.

Cloudways Autonomous includes controls for Under Attack Mode, WAF, rate limiting, Browser Integrity Check, and AI Crawler Blocking. Cloudways states that verified Googlebot and Bingbot are excluded from the Autonomous Under Attack Mode challenge.

“Verified search engine bots such as Googlebot and Bingbot are not affected.”

— Syed Abuzar Mehdi, Cloudways Help Center documentation author, 2026

The protection is helpful, but you should still verify crawl behavior because custom rules, origin firewalls, plugins, robots directives, or third-party services can block requests independently.

How to Verify Googlebot

A user-agent string can be spoofed. Google recommends verifying Googlebot through a reverse DNS lookup followed by a forward DNS lookup or by matching the source IP against Googlebot’s published IP ranges.

SEO Crawler Verification Checklist

After changing WAF or firewall rules:

  1. Inspect the URL in Google Search Console.
  2. Test live URL rendering.
  3. Review Cloudflare events.
  4. Review Cloudways incident logs.
  5. Check server access logs.
  6. Confirm Googlebot verification.
  7. Test XML sitemaps and robots.txt.
  8. Review crawl errors.
  9. Test important conversion URLs.
  10. Monitor indexing for at least several days.

AI Crawler Controls

AI crawler blocking should be a publishing-policy decision, not a default security action. Blocking training crawlers, retrieval crawlers, and search-related AI agents may have different consequences.

Document which crawlers are:

  • Allowed for search discovery
  • Allowed for citation or retrieval
  • Blocked from model training
  • Rate limited
  • Challenged
  • Monitored only

Avoid broad rules based only on the word “bot.” Separate malicious scrapers from legitimate search and retrieval systems.

How Can You Test Cloudways Security in Practice?

Cloudways security testing should verify that controls work as expected without disrupting legitimate users, crawlers, integrations, or business processes. A configuration is not fully implemented until it has been tested and the result has been documented.

Cloudways Security Incidents Dashboard

Use the dashboard to review:

  • Blocked IP addresses
  • Attack categories
  • Affected applications
  • Repeated request paths
  • Country distribution
  • False-positive patterns
  • Recent rule changes

[Insert image: Cloudways Security Incidents table showing blocked requests and IP actions | Alt text: “Analyze Cloudways firewall incidents and blocked traffic”]

Cloudways Vulnerability Scanner

Use the scanner to identify affected WordPress components. Confirm whether a fixed version exists and validate the update in staging.

[Insert image: Cloudways Vulnerability Scanner with issue details and remediation recommendation | Alt text: “Identify vulnerable WordPress plugins with Cloudways”]

Cloudflare Analytics and Security Events

Use Cloudflare analytics to understand:

  • Challenged requests
  • Blocked requests
  • WAF rule matches
  • Rate-limit actions
  • Bot traffic
  • Cached versus uncached traffic
  • Country distribution
  • Origin traffic reduction

[Insert image: Cloudflare security analytics showing WAF events and challenged requests | Alt text: “Review Cloudflare WAF events for a Cloudways website”]

Qualys SSL Labs

Qualys SSL Labs provides a free public test that analyzes SSL/TLS server configuration. Use it to identify certificate-chain problems, protocol weaknesses, cipher issues, and hostname mismatches.

[Insert image: Qualys SSL Labs result showing certificate, protocol, and cipher analysis | Alt text: “Test Cloudways SSL configuration with SSL Labs”]

SecurityHeaders.com

SecurityHeaders.com can review response headers such as Content Security Policy, HSTS, Referrer-Policy, X-Content-Type-Options, and frame restrictions.

A low score does not always mean a website is compromised. It indicates that additional browser-side protections may be missing or incomplete.

[Insert image: SecurityHeaders.com report showing detected and missing response headers | Alt text: “Check Cloudways website security headers online”]

Google Search Console

The Security Issues report can reveal hacking, malware, harmful downloads, phishing, or deceptive content. The URL Inspection tool can help confirm whether a critical page remains accessible to Google.

[Insert image: Google Search Console Security Issues report showing a clean status | Alt text: “Monitor Cloudways website security issues in Search Console”]

Google Safe Browsing

Google Safe Browsing can help determine whether Google currently identifies a domain as unsafe. Use it after malware cleanup and during post-incident validation.

[Insert image: Google Safe Browsing site-status result for a verified domain | Alt text: “Check Cloudways website status in Google Safe Browsing”]

Uptime Monitoring

An external uptime monitor can detect downtime, DNS failures, SSL expiry, slow responses, and unexpected status codes.

Free or low-cost options can complement Cloudways monitoring because they test the website from outside the hosting environment.

Harmless Verification Tests

Safe verification procedures include:

  • Attempting SSH from an unauthorized IP
  • Testing login rate limits with a controlled account
  • Confirming 2FA recovery codes
  • Checking SSL renewal status
  • Restoring a backup to staging
  • Submitting contact forms after WAF changes
  • Testing payment-provider webhooks
  • Running Google Search Console live inspection
  • Verifying cached and uncached pages
  • Confirming blocked countries through an approved test location

Do not perform disruptive load testing, aggressive scanning, or simulated attacks without written authorization and a controlled test plan.

What Should You Do If a Cloudways Website Is Hacked?

A hacked Cloudways website should be contained, preserved for investigation, cleaned, patched, restored where necessary, and monitored for reinfection. Restoring a clean backup without fixing the original weakness can return the site to a vulnerable state.

Immediate Containment

  1. Put the site into maintenance mode when necessary.
  2. Stop application access if the feature is available.
  3. Preserve files, databases, logs, and timestamps.
  4. Reset Cloudways and WordPress administrator credentials.
  5. Revoke active sessions.
  6. Remove unauthorized users.
  7. Rotate SFTP, SSH, database, API, and payment credentials.
  8. Contact Cloudways Support for infrastructure assistance.

Cloudways can disable application access while keeping backups and databases operational, although master-level access may remain available.

Investigation

Review:

  • Malware Protection reports
  • Modified-file timestamps
  • WordPress administrator accounts
  • Recently installed plugins
  • Vulnerable component history
  • Upload directories
  • Scheduled tasks
  • Access and error logs
  • Database injections
  • Cloudflare events
  • Cloudways incidents
  • Git deployment history
  • API activity

Cloudways application logs include Apache, Nginx, and PHP information. The platform displays a limited number of recent entries, while older available logs can be inspected through SSH or SFTP.

Cleanup and Recovery

Remove malicious files, backdoors, injected database content, unauthorized users, and compromised integrations. Restore a known-clean version when cleanup confidence is low.

Patch every known weakness before reopening the site. Otherwise, the attacker may reinfect the restored application.

Post-Recovery Validation

Confirm:

  • No malicious files remain.
  • No unauthorized administrators remain.
  • Checkout and forms work.
  • DNS records are correct.
  • SSL is active.
  • Security headers are correct.
  • Search crawlers can access the site.
  • Google Search Console reports are reviewed.
  • Safe Browsing status is checked.
  • Backups complete successfully.
  • Monitoring alerts reach the correct team.

How Can Agencies Secure Multiple Client Websites on Cloudways?

Agencies can secure multiple Cloudways websites by standardizing account roles, application credentials, add-on decisions, backup objectives, monitoring, and monthly review procedures. A repeatable operating standard is safer than configuring every client account differently.

Agency Security Standard

For every client:

  • Use a separate project or clearly defined grouping.
  • Assign individual team accounts.
  • Avoid shared master credentials.
  • Enable 2FA.
  • Document the website owner.
  • Record all active plugins and integrations.
  • Set an RTO and RPO.
  • Decide whether Malware Protection is required.
  • Record Cloudflare configuration.
  • Maintain an incident contact list.
  • Test one restore before launch.
  • Remove agency access after offboarding.

Monthly Portfolio Review

Review:

  • Team-member changes
  • Vulnerability findings
  • Malware status
  • Failed backups
  • SSL status
  • Cloudflare events
  • Uptime incidents
  • WordPress updates
  • Abandoned plugins
  • Search Console security warnings

Cloudways supports team collaboration across multiple accounts and allows assigned access to specific servers and applications.

Avoid Multi-Layer Configuration Drift

Configuration drift occurs when similar websites gradually receive different firewall rules, plugin settings, backup schedules, and access permissions.

For example, one client site may have 2FA and hourly backups while another comparable store has shared passwords and daily backups. A scorecard makes these inconsistencies visible.

What Is the Best Cloudways Security Configuration for WordPress?

The best Cloudways WordPress security configuration combines platform 2FA, least-privilege access, SSL, restricted server credentials, vulnerability remediation, edge protection, malware monitoring, frequent backups, and tested restoration. The correct intensity depends on revenue, data sensitivity, update frequency, traffic volatility, and acceptable downtime.

Recommended Configuration by Website Type

Website typeRecommended baseline
Personal blog2FA, SSL, updates, daily backup, vulnerability review
Affiliate websiteBaseline plus malware monitoring, Search Console alerts, off-platform backup
Lead-generation siteBaseline plus WAF, form protection, frequent backups, uptime monitoring
Agency portfolioStandardized roles, separate credentials, centralized updates, monthly audit
WooCommerce storeCloudflare Enterprise, malware protection, frequent backups, tested recovery, payment-log review
Membership websiteWAF, account monitoring, frequent database backups, session controls
SaaS marketing siteEdge protection, deployment controls, API security, uptime monitoring
Custom Laravel applicationFlexible server controls, SSH keys, restricted database access, code scanning, deployment logging

Is Cloudways Secure Enough for a Business-Critical Website?

Cloudways can provide a strong foundation for a business-critical website when the correct product and add-ons are selected and the application is maintained responsibly.

Cloudways is not sufficient by itself when:

  • Plugins remain unpatched.
  • Administrators share credentials.
  • 2FA is disabled.
  • Backups are never tested.
  • The application uses insecure custom code.
  • Malware alerts are ignored.
  • WAF rules block legitimate integrations.
  • No incident-response owner exists.

Before deciding, compare Cloudways with the operational model of the best managed WordPress hosting providers and review our complete Cloudways review.

Cloudways Security Scorecard

Score each category:

  • 0: Not configured
  • 1: Partially configured
  • 2: Configured and tested
Security categoryScore 0–2ConfiguredNeeds reviewNot applicable
Account 2FA
Team access
SSH/SFTP restrictions
SSL and HTTPS
Server firewall review
Edge WAF and DDoS protection
Vulnerability management
Malware protection
Backup configuration
Restore testing
Monitoring and alerts
Incident-response plan
SEO crawler accessibility
Credential-rotation process
Offboarding procedure

Interpretation:

  • 0–10: High operational risk
  • 11–20: Basic controls exist but need testing
  • 21–25: Strong configuration with limited gaps
  • 26–30: Mature configuration, assuming evidence is current

The score is an internal planning framework, not a certification or security guarantee.

After reviewing the configuration and total cost, compare current Cloudways hosting plans to determine whether Flexible or Autonomous better matches your security responsibilities.

What Should You Do Next to Improve Cloudways Security?

The next step is to prioritize controls that reduce account compromise, application exposure, and recovery failure before purchasing additional tools. Start with 2FA, access review, SSL, updates, and backups, then improve edge filtering, malware monitoring, and incident readiness.

Immediate Actions

Complete today:

  • Enable 2FA for every Cloudways user.
  • Remove unnecessary team members.
  • Install SSL and force HTTPS.
  • Update vulnerable WordPress components.
  • Confirm automated backups.
  • Create an on-demand backup.
  • Rotate exposed or shared credentials.

Actions Within Seven Days

Complete within one week:

  • Review firewall incidents.
  • Restrict SSH and SFTP access.
  • Evaluate Cloudflare Enterprise.
  • Review vulnerability findings.
  • Decide whether Malware Protection is required.
  • Configure security notifications.
  • Test a restore in staging.
  • Confirm Googlebot access.

Monthly Actions

Complete every month:

  • Audit team permissions.
  • Review administrator accounts.
  • Remove unused plugins and themes.
  • Review malware status.
  • Review backup failures.
  • Test one restore point.
  • Check Search Console Security Issues.
  • Review Cloudflare and firewall events.
  • Confirm SSL renewal.

Quarterly Actions

Complete every quarter:

  • Run an incident-response drill.
  • Review credential-rotation requirements.
  • Reassess Cloudflare rules.
  • Review API tokens.
  • Validate RTO and RPO.
  • Audit vendor access.
  • Review architecture and scaling requirements.
  • Recalculate security add-on costs.

→ Start Your Cloudways Setup

Conclusion: Is Cloudways Secure Enough?

Cloudways is secure enough for many WordPress, ecommerce, agency, and business websites when its layered protections are correctly configured and supported by disciplined application management. Cloudways provides a strong managed-security foundation, but the final outcome depends on product selection, activated add-ons, access controls, software quality, patching, monitoring, and recovery readiness.

Flexible is better suited to users who need application diversity and server-level control. Autonomous provides a more integrated WordPress experience with autoscaling, Cloudflare Enterprise, and included Malware Protection.

Do not assume that managed hosting secures every layer automatically. Audit the entire stack, test the controls, document responsibilities, and make recovery readiness part of normal website operations.

Frequently Asked Questions About Cloudways Security

Is Cloudways secure for WordPress?

Cloudways provides a strong WordPress security foundation through server protection, SSL, vulnerability monitoring, backups, account controls, and optional or integrated malware and edge protection. WordPress owners must still update plugins, secure administrator accounts, review permissions, and test backups.

Does Cloudways include malware protection?

Cloudways Flexible offers paid Malware Protection on a per-application basis, disabled by default. Cloudways Autonomous includes built-in Malware Protection, and Cloudways states that it is enabled by default for newly launched Autonomous applications.

Does Cloudways include a Web Application Firewall?

Cloudways documentation describes an Imunify360 WAF within its server security layer. Cloudflare Enterprise adds a separate edge WAF that filters malicious requests before they reach the origin.

Does Cloudways have DDoS protection?

Cloudways uses multiple layers for DoS and DDoS protection. Cloudflare Enterprise provides the strongest documented edge-level DDoS mitigation, while server-level controls block abusive IPs and suspicious request patterns.

Is Cloudways Malware Protection worth the additional cost?

Cloudways Malware Protection may be worth the cost for revenue-producing, client, ecommerce, or frequently attacked Flexible applications that need continuous scanning and automated cleanup. Lower-risk test sites may use alternative monitoring if someone can reliably review and respond to alerts.

Does Cloudways automatically update WordPress?

Cloudways offers WordPress update-management tools through SafeUpdates and Cloudways Site Manager. Update automation should be paired with staging, visual checks, backups, and rollback procedures rather than enabled without testing.

Can Cloudways identify how malware entered a website?

Cloudways states that its Malware Protection service does not provide complete root-cause analysis or confirm the exact plugin, theme, user account, file, or integration responsible for an infection. Detailed forensics may therefore be required.

Can Cloudways security block Googlebot?

Cloudways or Cloudflare rules can block legitimate crawlers when custom settings are too aggressive. Cloudways states that verified Googlebot and Bingbot are excluded from Autonomous Under Attack Mode, but site owners should still test crawlability after changing WAF, bot, country, or rate-limit rules.

How often should a Cloudways security audit be performed?

Critical alerts should be reviewed immediately, basic security status should be reviewed monthly, and permissions, credentials, recovery plans, architecture, and incident procedures should receive a deeper quarterly review.

What should I do first if a Cloudways website is hacked?

Contain access, preserve evidence, rotate credentials, review administrators, contact Cloudways Support, scan the application, remove malicious content, patch the entry point, restore clean data where needed, and verify Google Search Console and Safe Browsing status.

References

Cloudways. (2026, March 6). How to configure a server-level backup. Cloudways Help Center.

Cloudways. (2026, March 9; updated July 2, 2026). A brief guide to server security management. Cloudways Help Center.

Cloudways. (2026, April 24). How to install Let’s Encrypt SSL certificate. Cloudways Help Center.

Cloudways. (2026, June 2). How to enable Cloudflare on your application. Cloudways Help Center.

Cloudways. (2026, June 17). How to configure Cloudflare settings on Cloudways Autonomous. Cloudways Help Center.

Cloudways. (2026, June 18). How to do a point-in-time restore of your application. Cloudways Help Center.

Cloudways. (2026, June 29). How to use Malware Protection to protect your applications. Cloudways Help Center.

Cloudways. (2026, June 29). Understanding Malware Protection and Proactive Defense in Cloudways Autonomous. Cloudways Help Center.

Cloudways. (2026, March 13). How to recover or restore a deleted application or server on Cloudways. Cloudways Help Center.

Cloudways. (2026). Cloudways pricing and plans.

Cloudways. (2026). Cloudways managed cloud hosting platform.

Cloudways. (2025, July 15). Detect security bugs using Vulnerability Scanner. Cloudways Help Center.

Cloudways. (2026, January 30). Enabling two-factor authentication for Cloudways account. Cloudways Help Center.

Google. (n.d.). Security issues report. Google Search Console Help.

Google. (n.d.). What is Googlebot? Google Search Central.

Google. (n.d.). Safe Browsing site status. Google Transparency Report.

Qualys. (n.d.). SSL Server Test. SSL Labs.

Early-Bird-PPC-Blog-Side-banner_v3

By ASRAF MASUM

Entrepreneur. Marketer. Creator. I believe in learning by doing — and doing with purpose. From SEO and automation to building online businesses, I share insights that turn ideas into growth and passion into progress.

Check Out These Related Posts

Experience powerful and flexible managed cloud hosting with Cloudways. Elevate your website's performance with scalable, secure, and easy-to-manage cloud solutions.

Enjoy a 3-day free trial with no credit card required—risk-free!

FREE Trial Now!
Share This