Protecting Your Account: Passwords and Two-Factor Authentication Print

  • 0

Most account compromises start with a reused or weak password. These steps take a few minutes and prevent almost all of them.

Use a password manager

Generate a unique password of at least 16 characters for every account and store them in a password manager. Never reuse the same password across your client area, cPanel, WordPress and email.

Enable two-factor authentication

  • Client area: open your profile and enable two-factor authentication with an authenticator app.
  • cPanel: open Security → Two-Factor Authentication and scan the QR code.
  • WordPress: use a 2FA plugin on all administrator accounts.

Store the backup codes somewhere safe and offline.

Keep your contact email current

Password resets and security notices go to your registered email. If that address stops working, recovery becomes much harder. Update it under Account → Edit Account Details.

Watch out for phishing

We will never ask for your password by email or chat. Treat any message urging you to "verify your account" or warning of immediate suspension with suspicion — type the URL yourself rather than clicking a link, and check the sender domain carefully.

Limit who has access

  • Use sub-accounts in the client area instead of sharing your main login
  • Create restricted FTP accounts for developers and remove them when the job ends
  • Give WordPress users the lowest role that suits their work
  • Review who has access every few months

If you suspect a compromise

Change every related password immediately, review recent activity, and open a ticket so we can check the server-side logs with you.


Was this answer helpful?

« Back