DrivenHost

Blog / security monday

Notes from the field.

Short, practical pieces on the problems we fix most often. No trends, no fluff.

Oct 5, 2026
4 min

Spam Sent From Your Email? Here's What to Do

What a compromised hosting mailbox looks like from the server side, and the order to work through locking it down, cleaning it up and keeping it shut.

security mondayemailaccount security

Sep 28, 2026
4 min

What File Permissions Should WordPress Use?

The file permissions WordPress needs on a cPanel account, why 777 is never the fix, and a ten-minute check you can run today.

security mondaywordpressfile permissions

Sep 21, 2026
4 min

Old Site Copies Are a Security Risk

Abandoned staging folders, /old directories and backup zips are a common way into a hosting account. Here is how to find and clear them out.

security mondaywordpresshosting account

Sep 14, 2026
4 min

Who Still Has Access to Your Website?

A quarterly access review takes about twenty minutes and closes the door on old developer accounts, stale FTP logins and shared passwords.

security mondayaccess controlwordpress

Sep 7, 2026
4 min

How to Spot Phishing Emails About Your Site

Phishing aimed at website owners is specific and convincing. Here is how we tell a fake renewal, host or plugin email from a real one.

security mondayphishingemail

Sep 1, 2026
4 min

How to tell if a WordPress plugin is safe

Plugins are a common way WordPress sites get broken into. How to vet one before you install it, and how to spot the ones going quietly stale.

security mondaywordpressplugins

Aug 31, 2026
4 min

How to keep your domain name from being stolen

Domain hijacking usually starts at the registrar, not the server. Here is how to lock your domain, protect the account email and stay on top of renewals.

security mondaydomainsdns

Jul 6, 2026
3 min

What a hacked site looks like from the server side

The signs we see on our servers when a site is compromised, from outbound spam to rogue admins, and why cleanup fails without finding the way in.

security mondaymalwareincident-response

Jun 1, 2026
3 min

SSL beyond the padlock

Getting a certificate is the easy part: this Security Monday covers redirects, HSTS in plain terms, mixed content and keeping renewals boring.

security mondaysslhttps

May 4, 2026
3 min

Backups that actually restore

A backup only counts if it restores, so this Security Monday covers restore testing, retention, offsite copies and what your host does and does not do.

security mondaybackupsrecovery

Apr 6, 2026
3 min

Nothing is broken: why you still need updates

Most hacked sites we clean up were running software with a known, already-patched hole, so here is how to update without fear of breaking things.

security mondayupdateswordpress

Mar 2, 2026
3 min

Passkeys, 2FA and your hosting account

Your hosting account controls email, DNS and every file on your site, so here is how we lock ours down and who should still have access to yours.

security mondayaccounts2fa

Feb 2, 2026
3 min

The five WordPress security habits that stop most hacks

The five habits we see separating clean WordPress sites from hacked ones on our servers, and how to make each one part of your routine.

security mondaywordpressbasics

No sales team. No scripts.

Tell us what you're running.
We'll tell you what it needs.

Migrations are free, quotes are written, and the engineer who replies is on the team that will run your server.