UnderHost
Knowledgebase Docs

Creating and managing secure passwords

Use strong, unique passwords for your hosting accounts. This guide explains what makes a password strong, how to use a password manager,

On this page

Weak or reused passwords are the leading cause of website hacks and account compromises. A strong password is your first and most important layer of security. This guide explains how to choose good passwords and manage them without memorizing dozens of random strings.

What makes a strong password?

CharacteristicRecommendation
LengthMinimum 14 characters-longer is always better
ComplexityMix uppercase, lowercase, numbers, and symbols
UniquenessNever reuse a password across different sites
RandomnessAvoid real words, names, dates, or keyboard patterns
No personal infoDon't use your name, domain, phone number, or birthday
Bad password examples

Avoid: password123, admin, mywebsite2024, qwerty!, P@ssw0rd. These are in every brute-force wordlist and will be guessed quickly.

Using a password manager

A password manager generates and stores strong, unique passwords for every account. You only need to remember one master password. Recommended options:

  • Bitwarden-Free, open-source, works on all devices
  • 1Password-Premium, excellent for teams and families
  • KeePassXC-Local-only, no cloud sync, free

These tools autofill passwords in your browser so you never have to type or remember them. Your passwords are stored encrypted and protected by your master password.

Which accounts need strong passwords?

All of the following should have unique, strong passwords:

  • CustomerPanel-billing and account management
  • cPanel-controls your entire hosting account
  • Email accounts-compromised email is used to reset other passwords
  • WordPress admin-the most targeted CMS login
  • FTP / SFTP accounts-file access to your server
  • Database users-direct database access
  • Domain registrar-controls your domain nameservers

Two-factor authentication (2FA)

Two-factor authentication adds a second layer of security. Even if your password is stolen, the attacker can't log in without your phone.

  • CustomerPanel-Enable in Account > Security Settings
  • WordPress-Use a plugin like Wordfence or Two Factor Authentication

Use an authenticator app (Google Authenticator, Authy, or the built-in option in Bitwarden/1Password) rather than SMS-based 2FA when possible.

Related: How to access your CustomerPanel account | Start with UnderHost: your first 15 minutes | How to find your hosting service details | How to contact UnderHost support

Was this article helpful?

Ready to start with UnderHost?

Compare UnderHost hosting, VPS, dedicated, offshore, and managed services to choose the right starting point.

Related articles

Back to Getting Started