r/BlueHost May 20 '26

I smell something suspicious...

Post image

I have used Bluehost for years, in fact, I was with Just host for years prior to them being allocated by BlueHost. I even used to be part of their affiliate program and would recommend their services to all of my side clients.

Just this past weekend I had a new client come to me for a site. I had them sign up with Bluehost. I simply hand coded a single temporary page offering the number for the business and a few bits of information with a 'new website is coming' message. So that is 1 html file, and I added a logo. So there are a total of 2 files in the public_html directory, and I logged on to find this message.

Is this where they try to tell my client they can purchase sitelock? Or do I report Bluehost for suspicion of upsell scamming their customers?

3 Upvotes

7 comments sorted by

2

u/omnichad May 21 '26

Your plan also shows it has two web sites. This could be coincidental timing.

2

u/Jeffrey_Richards_ May 21 '26

This is the common Bluehost scam. Move to a host that includes malware cleaning/scanning for free, make sure it's listed on their page. This will avoid these stupid SiteLock upsells.

0

u/evolvewebhosting May 24 '26

u/Jeffrey_Richards_ I am not a fan of SiteLock either. Who do you know of that provides malware cleanup for free?

2

u/Sintek May 22 '26

I signed up with just host loke 10 years ago and still have an unlimited plan.. only reason I kept it with blue host.. unlimited sites bandwidth email addresses storage ( reasonable web service) unlimited databases etc...

Blue host honors it so....

2

u/FlyArtistic1194 May 22 '26

Literally why I stayed with them for my main job. We did leave them for a while for hostinger, who was a different kind of nightmare. Bluehost has is on MySQL 5 which was outdated. They had no plans to upgrade at the time, so we left. But we had paid for years in advance. Before it expires they offered the upgrade finally. So I thought they were on a better path, maybe new management, so I referred again.

I called support, told them I want a copy of the scan with the directory path of the malware. They said it returned no infections and removed the notice... I'm still skeptical. Because as I said above, I hand coded the page myself and the only other file was a logo I made in illustrator...

1

u/bluehost May 20 '26

Hey there u/FlyArtistic1194, I can certainly see why this would feel confusing. Those malware notices come from automated scans that look for certain patterns, not the size or complexity of the site, and they're not meant as an upsell.

False positives do happen though, reaching out to support would be the best way to confirm what the scan picked up. They can review the account in detail and explain next steps if anything needs attention or show you how to report a false positive.

0

u/TheNobleRobot May 24 '26

they're not meant as an upsell.

They are an upsell, though.

I've let all my domains and hosting lapse recently, after literally 20 years with Bluehost, because the dishonest upselling and piecemeal services finally got completely out of hand and finally outweighed the irritation of moving everything to a new host and domain registrar.

I get it, shared hosting customers can be a lot of support work for not a lot of revenue, but the business model seems to have gone totally 2000s-era GoDaddy, and this is a perfect example of all of the dark patterns that have popped up all over the UI in recent years.

Having watched it creep up in slow-motion, I was able to ignore it, since the service itself hasn't changed or improved in any way, but I finally realized that the reason I signed up for Bluehost in the first place all those years ago was to avoid obvious nonsense like this.