Skip to content

WordPress on VMs: Security & Support

Overview

Key Point

We're partners in security, not WordPress administrators. We provide secure infrastructure and VM hosting - you maintain your WordPress installation.

Is Your VM & Data Safe?

Infrastructure Security

What We Provide

  • DDoS Protection - Network-level mitigation included
  • Hardware Firewalls - Protecting our infrastructure
  • Isolated VMs - Complete separation between clients
  • Hypervisor Security - Enterprise-grade virtualization
  • Network Monitoring - 24/7 infrastructure surveillance

Your VM Security

Your Root Access = Your Responsibility

  • Full root access to configure as needed
  • Install any software, including WordPress
  • Configure your own firewall (iptables/ufw)
  • Manage all services and applications
  • Complete control over security settings

WordPress on VMs: The Reality

The Truth About Self-Hosted WordPress

  • Running WordPress on your own VM gives you complete control, but also complete responsibility. You're not just managing WordPress - you're managing an entire server.

Common Attack Vectors on VMs

Attack Type VM-Specific Risk Prevention
SSH Brute Force Root access attempts Key-only auth, fail2ban
Open Ports Unnecessary services Firewall, minimal services
Outdated OS System vulnerabilities Regular apt/yum updates
WordPress Exploits Application layer Plugin updates, WAF
Resource Exhaustion DoS attacks Rate limiting, monitoring

Our Approach to VM Security Issues

Collaborative Problem Solving

When security issues arise, we work together. We understand that managing a VM is complex and even experienced admins face challenges.

What Happens If Your VM Gets Compromised?

  1. Detection - Unusual traffic or resource usage alerts us
  2. Analysis - We identify the type and scope of issue. If it threatens our infrastructure or other customers, a read-only security bot may analyze the VM through the QEMU Guest Agent (never a human)
  3. Notification - Immediate contact with details, including the bot's findings and any action taken
  4. Temporary Measures - May limit network if actively attacking others
  5. Collaboration - Work together on resolution timeline
  6. Resolution - You clean the VM, we help with network-level blocks

We DON'T:

  • ❌ Log into your VM as humans
  • ❌ Modify anything inside your VM
  • ❌ Fix your WordPress installation
  • ❌ Update your OS or applications
  • ❌ Remove malware from your VM
  • ❌ Manage your firewall rules

What We DO:

  • ✅ Alert you to security issues
  • ✅ Provide network traffic logs
  • ✅ Implement upstream firewall rules if needed
  • ✅ Give reasonable time to fix issues
  • ✅ Offer guidance on best practices
  • ✅ Help identify attack sources

When We May Access Your VM

Security Exception: Protecting Our Nodes and Other Customers

We do not log into your VM for routine support, and we do not touch your WordPress, applications, or data in the ordinary course of business. In certain cases, however, we will access your VM to protect our nodes, our infrastructure, and other customers. If we detect a compromise, a critical fault, or malicious behavior, our automated security system dispatches AI agents that connect through the QEMU Guest Agent and run read-only shell commands to analyze the system and any vulnerabilities. The agents compile a report and send it to you.

This is never human access. No member of our staff logs into your VM. The access is always an automated, read-only bot that cannot modify your system, and it is used only to analyze and report. For full transparency, every action we take and the findings that prompted it are always sent to you by email, exactly as described in our Privacy Policy.

You can opt out by removing or disabling the QEMU Guest Agent (sudo systemctl disable --now qemu-guest-agent on Linux). If the agent is removed and we detect a threat, we cannot analyze the VM, so we will simply power off or suspend it instead. For repeat offenders, a VM that keeps threatening our infrastructure or other customers after this may be deleted outright.

Abuse Reports & VM Hosting

Understanding Our Position

VMs with root access can run anything - including compromised WordPress sites. We handle abuse reports reasonably, understanding that security breaches happen.

Scenario: WordPress Malware Sending Spam

  • We receive: Spam abuse report
  • We do: Notify you, provide mail logs
  • Timeline: 24 hours to stop spam
  • You do: Clean WordPress, secure mail server

Scenario: DDoS from Compromised Plugin

  • We receive: Attack complaints
  • We do: Rate-limit your VM, notify you
  • Timeline: Immediate action needed
  • You do: Identify and remove malicious code

Scenario: Phishing Page Injected

  • We receive: Phishing report
  • We do: Urgent notification
  • Timeline: 2-4 hours to remove
  • You do: Clean files, patch vulnerability

VM Management vs WordPress Support

Clear Boundaries

We Support You Handle
VM availability OS updates
Network connectivity Security patches
Hardware issues Firewall configuration
Hypervisor problems Service management
Network DDoS protection Application security
Abuse notifications WordPress maintenance
Resource upgrades Backup management

Securing WordPress on Your VM

Essential VM Security

Before Installing WordPress

  1. Update OS - apt update && apt upgrade
  2. Configure Firewall - Only ports 22, 80, 443
  3. Disable Root SSH - Use sudo user instead
  4. Install Fail2ban - Prevent brute force
  5. Set Up Monitoring - Track resource usage

WordPress-Specific Hardening

After Installing WordPress

  1. Hide WordPress Version - Security through obscurity
  2. Secure wp-config.php - Move above web root
  3. Disable File Editing - In WordPress admin
  4. Install Security Plugin - Wordfence or Sucuri
  5. Regular Backups - Before any updates
  6. CDN/WAF - CloudFlare for extra protection

FAQ

Will you suspend my VM if WordPress gets hacked?

No immediate suspension. We'll work with you if you're responsive. Suspension only happens for non-response or repeated issues affecting others.

Can you help clean my hacked WordPress?

We won't clean or modify your WordPress for you, and no human logs into your VM. If the compromise threatens our infrastructure or other customers, an automated read-only bot may analyze the VM through the QEMU Guest Agent and email you a report of the findings, but cleaning the site stays with you. We also provide logs and network-level assistance to identify the attack vector. See When We May Access Your VM.

What if my VM is attacking others?

We'll rate-limit your network and notify you immediately. You'll need to fix it quickly, but we won't instantly terminate your service.

Do you monitor what I install on my VM?

No. Your VM is private and no human looks inside it. We only monitor network behavior and resource usage that might affect other clients. The single exception is automated: if we detect a compromise or a threat to other customers, a read-only security bot may analyze the VM and email you the findings, as described in When We May Access Your VM.

Can I run multiple WordPress sites?

Yes. It's your VM - run as many sites as your resources allow. Just maintain them all properly.

Getting Help

Security Incident Response

  1. Check Notification - Read our alert carefully
  2. Access Your VM - SSH in to investigate
  3. Review Logs - Check access, error, mail logs
  4. Isolate Problem - Disable compromised services
  5. Clean Infection - Remove malware, patch holes
  6. Harden Security - Implement better protections
  7. Confirm Fixed - Reply to our ticket

Summary

Remember

We're partners in security, not WordPress administrators.

Your VM is your kingdom - you have root access and full control. We keep the infrastructure secure and notify you of issues. When problems arise, we work together: we provide the infrastructure support, you handle the application layer.