Type something to search...
How to secure cPanel hosting accounts?

How to secure cPanel hosting accounts?

To secure a cPanel hosting account, you protect the login itself with a strong, unique password and two-factor authentication, remove or restrict extra FTP, email, and database accounts, switch to SFTP or SSH keys, keep your software and PHP version up to date, lock down file permissions, and take regular backups stored off the server. If you manage the whole server, WHM adds more layers like cPHulk brute-force protection, a firewall, and ModSecurity.

Your cPanel account is the master key to your website, email, databases, and DNS. Anyone who gets into it can replace your site, read your mail, or redirect your domain. This guide walks through the settings available to regular cPanel users first, then covers the extra hardening options available to resellers and server administrators in WHM. Menu names reflect the current cPanel Jupiter interface, but your host may hide or rename some tools.

Why cPanel Accounts Are Attractive Targets

A single cPanel login often controls:

  • Every website file in your home directory
  • All MySQL or MariaDB databases
  • Email accounts, forwarders, and autoresponders
  • DNS records (through the Zone Editor, if your host allows it)
  • SSL certificates, cron jobs, and backups

That makes the login a high-value target. Attackers use password lists leaked from other breaches, phishing emails pretending to be your host, and automated guessing against the login page on ports 2082 and 2083. Once inside, they commonly upload malware, create hidden FTP accounts for later access, add malicious cron jobs, or send spam from your mail accounts.

The good news is that a few settings shut down most of these routes.

Step 1: Use a Strong, Unique cPanel Password

Your cPanel password should be long, random, and used nowhere else. Reused passwords are the most common way accounts are taken over, because leaked credentials from unrelated sites get tried everywhere.

  1. Log in to cPanel and open Preferences > Password & Security.
  2. Enter your old password, then use the Password Generator or your password manager to create a new one of at least 16 to 20 characters.
  3. Save it in a password manager such as Bitwarden, 1Password, or KeePassXC.

If your host's client area (for example, a WHMCS or custom billing portal) can log you into cPanel automatically, secure that account just as carefully, since it's effectively another door to the same room. Enable two-factor authentication there too if it's available.

Step 2: Enable Two-Factor Authentication

Two-factor authentication (2FA) means a stolen password alone isn't enough to log in. cPanel supports time-based one-time codes from apps like Google Authenticator, Microsoft Authenticator, Authy, or any TOTP-compatible app.

  1. Open Security > Two-Factor Authentication in cPanel.
  2. Click Set Up Two-Factor Authentication.
  3. Scan the QR code with your authenticator app, or enter the secret key manually.
  4. Enter the six-digit code the app shows and click Configure Two-Factor Authentication.

Store your recovery information safely. If you lose your phone and have no backup, you'll need your host's support team to disable 2FA, which usually involves identity checks.

If the Two-Factor Authentication icon is missing, your host has disabled the feature in WHM. It's worth asking them to enable it, and if they refuse, consider whether that host takes security seriously.

Step 3: Review and Limit Additional Accounts

Over time, cPanel accounts collect extra logins: FTP accounts for a developer who left years ago, email accounts nobody reads, database users for an old test site. Each one is a potential way in.

FTP Accounts

  1. Open Files > FTP Accounts.
  2. Delete any accounts that aren't actively needed.
  3. For accounts you keep, restrict the directory to the specific folder the person needs, not your whole home directory.
  4. Set strong passwords, and change them when a contractor finishes their work.

Better still, avoid plain FTP entirely. It sends passwords unencrypted. Use SFTP (which runs over SSH) or at minimum FTPS (FTP over TLS). Check Files > FTP Connections occasionally to see who is currently connected.

Email Accounts

Open Email > Email Accounts and remove mailboxes that are no longer used. Compromised email accounts are commonly used to send spam, which can get your whole server's IP address blocklisted. Make sure every mailbox has a strong password, and consider forwarders instead of full mailboxes where someone only needs to receive mail.

Database Users

Under Databases > Manage My Databases (or the MySQL Database Wizard), check which users exist and which databases they can access. Each application should have its own database user with privileges only on its own database. Remove users tied to sites you've deleted.

Team Manager and User Manager

Newer cPanel versions include Preferences > Manage Team, which lets you invite team members with limited roles instead of sharing the main cPanel password. If someone needs access to only email or only files, give them a restricted team account. Never share the primary login.

Step 4: Use SSH Keys Instead of Passwords

If your host provides SSH access, use key-based authentication rather than a password.

  • Generate a key pair on your computer if you don't already have one:
ssh-keygen -t ed25519 -C "you@example.com"
  • Import the public key in cPanel under Security > SSH Access > Manage SSH Keys > Import Key, pasting the contents of ~/.ssh/id_ed25519.pub.
  • Authorize the key from the same screen. Imported keys aren't active until you click Manage > Authorize.
  • Connect using your cPanel username and your host's SSH port:
ssh -p 22 cpaneluser@your-server-hostname

Many hosts use a non-standard SSH port, so check their documentation. Protect your private key with a passphrase, and never upload the private key to the server. You can also generate keys inside cPanel, but creating them locally means the private key never leaves your machine.

If you don't use SSH, ask your host whether it can be disabled for your account.

Step 5: Restrict Access by IP Address

cPanel has a couple of tools for controlling who can reach your site or account.

  • Security > IP Blocker: Blocks specific IP addresses or ranges from accessing your websites. Useful for stopping a persistent attacker or scraper.
  • Security > Directory Privacy: Adds password protection to a directory, which is handy for staging sites or an admin area.

For the cPanel login itself, IP-based restrictions are typically set at the server level by your host or in WHM. If you have a static office IP, ask your host whether they can restrict access to ports 2083 and 2087 from that address.

You can also protect a sensitive directory such as wp-admin with IP-based rules in .htaccess, using Apache 2.4 syntax:

# Place in /public_html/wp-admin/.htaccess
<RequireAny>
    Require ip 203.0.113.10
    Require ip 198.51.100.0/24
</RequireAny>

# Allow admin-ajax.php, which the front end of many sites needs
<Files "admin-ajax.php">
    Require all granted
</Files>

Replace the example addresses with your own. Only use this if your IP address doesn't change often, or you'll lock yourself out. Keep a way back in, such as File Manager, so you can remove the rule if needed.

Step 6: Keep Software and PHP Up to Date

Most compromised cPanel accounts aren't hacked through cPanel at all. They're hacked through outdated WordPress plugins, abandoned themes, or old copies of applications sitting in forgotten subfolders.

  • Update your CMS, plugins, and themes regularly. cPanel's WordPress Toolkit (if your host offers it) or WP Toolkit can show available updates and apply them.
  • Delete unused installations. Old test sites in folders like /old/ or /dev/ are often the entry point for malware.
  • Use a supported PHP version. Open Software > MultiPHP Manager and pick a supported PHP 8.x version for each domain. Test on a staging copy first if you're jumping several versions.
  • Review PHP settings under Software > MultiPHP INI Editor. Make sure display_errors is off for live sites.

If you installed apps using Softaculous or a similar installer, it can also notify you about updates and take backups before upgrading.

Step 7: Set Correct File Permissions

Wrong file permissions can let other processes or users modify your files, or let attackers read configuration files. On most cPanel servers, PHP runs as your own user (via suPHP, PHP-FPM, or CGI with suEXEC), so these are good defaults:

  • Directories: 755
  • Files: 644
  • Sensitive config files like wp-config.php: 600 or 640

Never set anything to 777. On a properly configured cPanel server, it's never needed, and some servers will refuse to run PHP files in world-writable directories anyway.

You can fix permissions in bulk over SSH from your site's root folder:

cd ~/public_html
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;
chmod 600 wp-config.php

Take a backup before running bulk commands. If you don't have SSH, File Manager lets you change permissions by right-clicking a file and choosing Change Permissions.

Step 8: Install SSL on Every Domain

Every domain and subdomain in your account should use HTTPS, including the ones you use to log in to webmail and cPanel. Most cPanel servers include AutoSSL, which issues free certificates from Let's Encrypt or Sectigo automatically.

  1. Open Security > SSL/TLS Status.
  2. Check that every domain shows a valid certificate.
  3. Click Run AutoSSL if any are missing or expired.

If AutoSSL fails, it's often because DNS for that domain doesn't point to the server, or something is blocking the domain validation files. Once certificates are installed, use Domains > Domains to enable Force HTTPS Redirect for each domain.

Always log in to cPanel over the secure port (2083) or a URL like https://yourdomain.com/cpanel, never the unencrypted port 2082.

Step 9: Watch for Suspicious Activity

Checking a few places regularly helps you catch problems before they spread.

  • Cron jobs (Advanced > Cron Jobs): Attackers often add cron jobs that re-download malware after you clean it up. Delete any you don't recognise.
  • Last login information: cPanel shows the IP of your last login on the home screen. If it isn't yours, change your password immediately.
  • Raw Access logs and Errors (Metrics > Raw Access and Metrics > Errors): Useful for spotting unusual requests or repeated attacks on specific files.
  • Email Deliverability and Track Delivery: Sudden spikes in outgoing mail can mean a compromised mailbox or script.
  • Disk usage: An unexplained jump in disk usage can indicate uploaded malware, spam files, or phishing pages.

If your host provides ImunifyAV, Imunify360, or ClamAV Scanner in cPanel, run scans periodically and read the results.

Step 10: Back Up and Store Copies Elsewhere

Backups are your safety net when everything else fails. cPanel offers a few options:

  • Files > Backup: Download a full account backup or partial backups of your home directory, databases, and email forwarders.
  • Files > Backup Wizard: A guided version of the same tools.
  • JetBackup or Acronis (if your host includes them): Provide automatic, scheduled backups with point-in-time restore.

Whatever you use, keep at least one copy somewhere other than the server, such as cloud storage or your own computer. If the account is compromised or the server fails, backups stored only in your home directory may be lost or tampered with. Never leave backup archives inside public_html, where anyone could download them.

Extra Hardening for WHM and Server Administrators

If you run your own cPanel server or a reseller account, WHM gives you tools that protect every account on the server.

Enable cPHulk Brute Force Protection

WHM > Security Center > cPHulk Brute Force Protection blocks IP addresses after repeated failed logins to cPanel, WHM, webmail, FTP, and SSH. Enable it, review the default thresholds, and add your own static IP to the allowlist so you don't lock yourself out.

Run the Security Advisor

WHM > Security Center > Security Advisor scans your server's configuration and lists recommendations, such as disabling outdated protocols, enabling shell fork bomb protection, or turning on symlink protection. Work through its warnings; most can be fixed with a few clicks.

Use a Firewall

cPanel servers commonly use CSF (ConfigServer Security & Firewall), which is widely used but no longer actively maintained by its original developer, or a commercial product like Imunify360 that includes a firewall. Alternatively, rely on firewalld with cPanel's own rules. Whatever you choose, only expose the ports you actually use.

Enable ModSecurity

WHM > Security Center > ModSecurity Vendors lets you install the OWASP Core Rule Set or a commercial ruleset. ModSecurity acts as a web application firewall, blocking many common attacks before they reach your applications. Watch for false positives after enabling it.

Isolate Accounts

Enable CageFS (on CloudLinux) or jailed shell access for users so one compromised account can't browse others. Use PHP-FPM or suEXEC so each account's PHP runs as that account's user, and turn on symlink race condition protection.

Keep the Server Updated

In WHM > Server Configuration > Update Preferences, choose automatic updates for cPanel and ensure the operating system receives regular security patches.

Harden SSH

Disable root password logins and use keys instead, under WHM > Security Center > SSH Password Authorization Tweak and Manage root's SSH Keys. Before you disable password authentication, confirm your key works in a second session and keep your current session open so you can revert if something goes wrong.

A Quick cPanel Security Checklist

  1. Strong unique password saved in a password manager.
  2. Two-factor authentication enabled on cPanel and your host's client area.
  3. Extra accounts audited: FTP, email, database, and team users.
  4. SFTP or SSH keys instead of plain FTP.
  5. Software and PHP updated, unused installs removed.
  6. Permissions correct: 755 for directories, 644 for files, no 777.
  7. SSL on every domain with HTTPS redirects.
  8. Cron jobs and logs reviewed regularly.
  9. Backups stored off the server.
  10. WHM hardening applied if you manage the server.

FAQ: Securing cPanel

Yes. Open Security > Two-Factor Authentication in cPanel and scan the QR code with an authenticator app. If you can't see the option, your host has disabled it in WHM and you'll need to ask them to enable it.

Plain FTP sends your username and password unencrypted, so it isn't safe on untrusted networks. Use SFTP over SSH where possible, or at least FTPS with explicit TLS, and delete FTP accounts you no longer need.

On most cPanel servers where PHP runs as your user, use 755 for directories, 644 for files, and 600 or 640 for sensitive configuration files like wp-config.php. Never use 777.

Common signs include unfamiliar cron jobs, FTP or email accounts you didn't create, a last-login IP you don't recognise, unexpected files in public_html, spikes in outgoing mail or disk usage, and warnings from your host or Google. Change your passwords immediately and scan your files if you see any of these.

No. Use Manage Team to give them a limited team account, or create a restricted FTP or SFTP account for just the folder they need. Remove their access when the work is finished.

No. cPHulk is configured by server administrators in WHM. Regular users benefit from it automatically if their host has enabled it, but can't change its settings.

They're a good start, but keep at least one copy outside the server. If the account is compromised or the server fails, backups stored only in your home directory may be lost or altered.


Conclusion

Securing a cPanel hosting account doesn't require deep technical knowledge. A strong password with two-factor authentication, a tidy set of FTP, email, and database accounts, SFTP or SSH keys, up-to-date software, sensible permissions, SSL everywhere, and off-site backups will protect you from the vast majority of attacks that hit shared hosting accounts.

Set aside a few minutes each month to review cron jobs, logins, and installed applications, and act quickly on anything unfamiliar. If you manage the server itself, WHM's security tools add another strong layer across every account. Combined, these habits make your account a far harder target than the thousands of unprotected ones attackers are scanning for every day.

Tags :
Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
How does GDPR affect website security?

How does GDPR affect website security?

GDPR affects website security by turning it from a good habit into a legal obligation. If your website collects personal data from people in the EU (

Dive Deeper