Creating and managing secure passwords
Use strong, unique passwords for your hosting accounts. This guide explains what makes a password strong, how to use a password manager,
On this page
Weak or reused passwords are the leading cause of website hacks and account compromises. A strong password is your first and most important layer of security. This guide explains how to choose good passwords and manage them without memorizing dozens of random strings.
What makes a strong password?
| Characteristic | Recommendation |
|---|---|
| Length | Minimum 14 characters-longer is always better |
| Complexity | Mix uppercase, lowercase, numbers, and symbols |
| Uniqueness | Never reuse a password across different sites |
| Randomness | Avoid real words, names, dates, or keyboard patterns |
| No personal info | Don't use your name, domain, phone number, or birthday |
Avoid: password123, admin, mywebsite2024, qwerty!, P@ssw0rd. These are in every brute-force wordlist and will be guessed quickly.
Using a password manager
A password manager generates and stores strong, unique passwords for every account. You only need to remember one master password. Recommended options:
- Bitwarden-Free, open-source, works on all devices
- 1Password-Premium, excellent for teams and families
- KeePassXC-Local-only, no cloud sync, free
These tools autofill passwords in your browser so you never have to type or remember them. Your passwords are stored encrypted and protected by your master password.
Which accounts need strong passwords?
All of the following should have unique, strong passwords:
- CustomerPanel-billing and account management
- cPanel-controls your entire hosting account
- Email accounts-compromised email is used to reset other passwords
- WordPress admin-the most targeted CMS login
- FTP / SFTP accounts-file access to your server
- Database users-direct database access
- Domain registrar-controls your domain nameservers
Two-factor authentication (2FA)
Two-factor authentication adds a second layer of security. Even if your password is stolen, the attacker can't log in without your phone.
- CustomerPanel-Enable in Account > Security Settings
- WordPress-Use a plugin like Wordfence or Two Factor Authentication
Use an authenticator app (Google Authenticator, Authy, or the built-in option in Bitwarden/1Password) rather than SMS-based 2FA when possible.
Related: How to access your CustomerPanel account | Start with UnderHost: your first 15 minutes | How to find your hosting service details | How to contact UnderHost support
Ready to start with UnderHost?
Compare UnderHost hosting, VPS, dedicated, offshore, and managed services to choose the right starting point.





















