SPARKZ Network

Platform security

security you should
not have to think about.

Every plan sits behind the same defence in depth — a web application firewall, malware scanning that removes what it finds, brute-force blocking and a server firewall. Built into the platform, run by us, not sold back to you as a bolt-on.

WAF + malware removal
Imunify360WAF + malware removal
Brute-force blocking
fail2banBrute-force blocking
On every site
Free SSLOn every site
Backups, 30 days
DailyBackups, 30 days

a lot has to get past a lot.

No single control keeps a site safe. These run together on every plan, so an attack has to defeat each one in turn rather than find the one door left open.

Imunify360 web application firewall

A WAF inspects every request before it reaches your site and turns away the common attacks — SQL injection, cross-site scripting, malicious bots — that make up the bulk of what hits a website. It runs in front of every account, not as an upgrade.

Malware scanning, removed automatically

Imunify360 continuously scans your files against known-malware and known-exploit data, and cleans what it finds automatically — rather than emailing you an alert and leaving the removal to you.

fail2ban brute-force protection

Attacks usually start by guessing passwords at scale. fail2ban watches login attempts across the control panel, FTP, SSH and mail, and automatically bans the IP addresses that hammer them — before a guess ever lands.

Server firewalls

At the network layer, a firewall means only the services that should be reachable are. Everything else is turned away at the door, so the surface an attacker can even reach is kept as small as possible.

Free SSL, auto-renewed

Every site gets a Let's Encrypt certificate that issues and renews itself, so traffic is encrypted and the padlock never quietly lapses. Not free for a year and then billed — free, and self-renewing.

Daily backups, 30 days of history

The last line of defence is being able to undo. Every site is backed up daily and kept for 30 days, and you restore it yourself from the panel — so ransomware, a bad plugin or a fat-fingered delete is a rollback, not a disaster.

and two more, when a site earns them.

The included protection covers most sites well. Two optional layers are worth it when the stakes rise — a busy shop, or a domain under attack.

Cloudflare, per domain

Route any domain through Cloudflare and visitors reach its global network first — which hides your server's real IP address and puts a CDN and DDoS filtering in front of the site. Optional, per domain, on request.

About DNS & Cloudflare

SiteLock, for a deeper per-site layer

The platform protects the server and catches known malware. SiteLock adds per-site scanning on a schedule, a trust seal, and its own application firewall — worth it for a shop or any site where a defacement costs real money.

See SiteLock

what security actually is.

No honest host will tell you a site is unhackable, and you should distrust one that does. Security is layers and upkeep, not a magic shield — the more an attack has to get through, the less likely it is to bother.

We run the layers around the platform and keep them patched. The part only you can do is the account itself: keep your applications and plugins current, use a strong and unique password, and switch on two-factor authentication. Do that, with everything above running underneath, and a small site is a genuinely hard target.

security questions

Is shared hosting actually secure?

It can be more secure than a server you run yourself, precisely because the security is our job rather than a side-task you have to remember. Every account sits behind an Imunify360 web application firewall, continuous malware scanning with automatic removal, fail2ban brute-force protection and a server firewall — kept patched and tuned by people who do only this. On an unmanaged server all of that is yours to build and maintain.

Do you remove malware for me?

Yes — Imunify360 detects and removes known malware automatically, rather than leaving you to clean infected files by hand. The one thing scanning cannot do is close the hole that let the malware in: if an out-of-date plugin was the way in, the site will simply be reinfected. Cleaning and patching have to happen together, which is why keeping WordPress and its plugins updated still matters.

What is the difference between this and SiteLock?

The protection on this page is included on every plan and works at the platform level — the firewall, malware removal and brute-force blocking that guard the whole server. SiteLock is an optional paid add-on that adds a deeper per-site layer: scheduled scanning of your specific site, a trust seal for visitors, and its own application firewall. Most sites are well covered by the included protection; a shop or a high-value site is where the extra layer earns its keep.

What about DDoS attacks?

For a domain that needs it, we can route traffic through Cloudflare, whose network absorbs and filters volumetric attacks before they reach your server and hides your origin IP address in the process. It is optional and set per domain. The server firewalls also drop obviously abusive traffic at the network edge.

So what is left for me to do?

The platform is our half; your account is yours. Keep your applications and plugins updated, use a strong and unique password, and turn on two-factor authentication in your client area and control panel. Security is layers, not a single magic shield — we run the layers around your site, and good account hygiene is the one nobody else can do for you.

hosting that guards itself.

The firewall, the scanning, the backups — already on, on every plan. Pick one and the protection comes with it.