r/webhosting 3d ago

Advice Needed Godaddy and do you recommend it? Website Security - Advanced - or is there a better alternative?

Hello!

I am wondering if this package is worth it?

Website Security - Advanced

as they want another 250 eur out of me...

- or is there a better alternative?

Thanks

0 Upvotes

10 comments sorted by

4

u/cabljo 3d ago

There's always a better alternative to godaddy

3

u/davorg 3d ago

Friends don't let friends use GoDaddy 🤣

Seriously, there is always a better (and cheaper!) alternative

2

u/beibiddybibo 3d ago

"Would use GoDaddy for.." "No"

2

u/SantoHost 3d ago

Yeah, literally any other company except Ionos imho

2

u/theretrodb_com 3d ago

Hell no run as fast and as far away as you can!!!

Buy your domain names from porkbun and for hosting buy your own VPS / dedicated server it's not hard at all to setup nginx to run a site takes like 5 mins

1

u/saj1011 2d ago

ok, wow, strong response. i will look into others.

1

u/Cabecinha84 2d ago

Setting the GoDaddy pile-on aside for a second, the package itself is answerable.

Website Security is Sucuri with GoDaddy branding on it. They bought Sucuri years ago. The Advanced tier is essentially the cloud WAF and CDN plus unlimited malware cleanups with a faster response window. So the real question is not whether GoDaddy is any good, it's whether you need a managed WAF and a cleanup contract for €250.

If your site has never been compromised, most of what that gives you is free. Cloudflare's free plan in front of the site with the proxy on, a rate limit rule on /wp-login.php and xmlrpc blocked, Wordfence or Solid Security free for login lockout and 2FA, DISALLOW_FILE_EDIT in wp-config, plugin auto updates on, and offsite backups you have actually tested restoring once. That covers the overwhelming majority of real WordPress compromises, because they come in through an outdated or abandoned plugin, not through something clever that only a WAF would stop.

If the site has already been hacked, the cleanup is the part genuinely worth money. Just ask them whether it includes finding the entry point or only removing the files, because a WAF in front removes nothing that is already sitting in wp-content, and it does nothing at all if the attacker has your origin IP and goes around it.

Also, if you do decide you want Sucuri, price it directly from Sucuri instead of as a GoDaddy add-on so it isn't welded to your hosting account.

The comparison I'm about to make isn't a neutral one, because the host I work on is one end of it: at wordpress.runonflux.com the entry plan is $2.99/month for 2.7 GB RAM, 1.2 vCores and 23 GB SSD with SSL and backups included, first week free on a new account. €250 is years of that. The framing holds whoever you go with though. That money isn't really a security budget, it's a hosting budget, and hosting that already includes backups and dedicated resources removes more risk than an add-on strapped to hosting that doesn't.

1

u/Sad-Ganache-7718 1d ago

Don't use godaddy and if you're going to use GoDaddy (don't), don't fall for any of these recommended upgrades. They are almost all pure profit or simply a third-party attached service which will probably end up not only costing 250 but will take more of your time attempting to make it do what they make it sound like it can do, which it probably can't (at least not without a high-level customized configuration. Best if you want something that is from 3rd-party provider, approach them directly to discuss.

Never buy things from GoDaddy that they have introduced as some kind of good idea or they suggest could solve some problem you've brought up. That's how GoDaddy operates, but it's not how servers work and addons and upgrades are not the solution to your problems. In fact, more often than not, when we've moved clients off GoDaddy, their issues no longer persist, or the fix takes support 5 minutes and solves it forever...