Documentation

Visit Our xCloud Knowledge Base

Here is your one-stop source for in-depth articles, FAQs, and tutorials for you to excel at hosting & managing your websites.


Enhancing Server and Website Security with xCloud

xCloud ensures robust security for your websites by default, locking down servers during the provisioning process. However, it’s important to maintain good security practices and assist clients in doing so to further enhance security.

This documentation details the security measures xCloud implements by default, allowing you to create a comprehensive security checklist for setting up new websites on xCloud.

xCloudโ€™s Network and Server Security #

1. SSH Lockdown #

The root user is restricted to secure SSH access only to minimize the risk of unauthorized access.

SSH Key Authentication is more secure than password-based authentication, supporting public and private key authentication.

3. System User Isolation #

System users created via our platform are completely isolated and secure from one another, each with only the essential permissions assigned.

4. Managing Server Access: Sudo Users vs. Site Users #

In xCloud Sudo users have full server-wide access, allowing them to control all aspects of the server. In contrast, site users are restricted to managing a single site on the server, ensuring they cannot access or modify other sites’ files or server configurations.

5. Firewall Control – Linux UFW Configuration #

At xCloud, the Linux Uncomplicated Firewall is configured during the server provisioning process.

6. Strict Port Control #

By default, only essential ports are open (22/TCP for SSH, 80/TCP for HTTP, 443/TCP for HTTPS, and 34210/TCP for xCloud communication), reducing attack risks. Users can also change the default port if needed.

7. Fail2Ban Preconfigured #

Fail2Ban, an intrusion prevention software, is enabled on xCloud by default to protect against brute-force attacks on the SSH port.

8. Vulnerability Scanner #

With xCloudโ€™s Vulnerability Scanner, you can scan and identify the security issues of core, plugin, and theme versions that are installed on your WordPress site. Also, can configure auto updates to handle them automatically.

xCloudโ€™s WordPress Security #

1. Secure PHP Version #

By default, new WordPress websites are provisioned with the most current version of PHP, ensuring compatibility and security.  

2. Latest WordPress Version #

New websites created by any user employ the latest WordPress version to avoid unpatched vulnerabilities.

3. Disable Directory Browsing/System File Protection #

xCloud prevents access to critical WordPress files and directories.

5. Disable PHP Execution in Uploads and Themes Directories #

xCloud blocks maliciously uploaded PHP files in WordPress directories.

7. SFTP and SSH Access Only

xCloud enforces the use of secure server connections exclusively via SFTP and SSH. 

Additional WordPress Security Options #

1. Security Headers #

Customize security headers to prevent cross-site scripting and clickjacking. Beyond default measures, xCloud offers customizable security options to meet specific needs:

2. Web Application Firewall (WAF) Options #

Integrates with 7G and 8G firewalls to protect against malicious requests, bad bots, and spam referrers.

3. Website Isolation Through System Users #

Assign unique system users to websites to keep them isolated and prevent cross-infection in case of a compromise.

4. Disable XML-RPC #

Disabling the outdated and insecure XML-RPC method if not in use. It can be customized from PHP settings.

5. 1 Click SSL Certificates #

Users are encouraged to use SSL certificates for enhanced security. With just one click, SSL certificates can be implemented in xCloud.

Product Security #

1. Two-Factor Authentication (2FA) on account #

It is highly recommended for password-based authentication, requiring a second form of identification.

2. Permission Levels #

Different permissions can be assigned to users or teams within the xCloud dashboard including server/site access, billing, user data, and message permissions.

3. Password and Credential Storage #

xCloud enforces a complex password standard, storing credentials in hash form to reduce the risk of password theft and unauthorized access.

4. Credit Card Information #

Payments are handled by the payment gateway (Stripe), ensuring no access to your credit card information.

5. Best Practices #

Automated server configuration follows industry best practices for securing your server or web applications.

Still, facing any security issues? Contact our support team for any of your queries.

What are your feelings
Updated on September 8, 2024

Server Name

RAM

SSD

xCloud Provider Price/m
(For LTD users)

VULTR Price/m

DO Price/m

Newcomer

1GB

25GB

$4.50

$5.00

$6.00

Basic

2GB

55GB

$9.00

$10

$12.00

Standard

4GB

80GB

$18.00

$20

$24.00

Professional

8GB

160GB

$36.00

$40

$48.00

Business

16GB

320GB

$72.00

$80

$96.00

Server Name

RAM

SSD/NVMe

xCloud Provider Price/m
(For LTD users)

VULTR Price/m

DO Price/m

Lite

1GB

32GB

$5.40

$6.00

$8.00

Personal

2GB

88GB

$16.20

$18.00

$24.00

Growing

4GB

128GB

$21.60

$24.00

$32.00

Elite

8GB

256GB

$43.20

$48.00

$64.00

Titanium

8GB

384GB

$86.40

$96.00

$96.00

Ultimate

32GB

512GB

$172.80

$192.00

$192.00