How to choose WordPress hosting: what to check
Published on 3 October 2026
Good WordPress hosting runs a current PHP version and a modern database, handles HTTPS without fuss and lets you make backups you can restore yourself. Those are the basics. After that, look at storage, protection against attacks, where the server is and how easy it is to leave. Here are the eight things to check, with the questions worth asking a host.
1. Which PHP version do you need?
WordPress is written in PHP, and the version matters for both speed and security. WordPress recommends PHP 8.3 or later, and the WordPress hosting handbook goes a step further, advising PHP 8.4 or later for production sites. Also check how long a version will keep getting security fixes:
| PHP version | Active support until | Security fixes until |
|---|---|---|
| 8.2 | 31 December 2024 (ended) | 31 December 2026 |
| 8.3 | 31 December 2025 (ended) | 31 December 2027 |
| 8.4 | 31 December 2026 | 31 December 2028 |
| 8.5 | 31 December 2027 | 31 December 2029 |
If a host still runs PHP 8.2 or older, you’ll soon be behind. Ask whether you can switch versions yourself, so you can test a new one when it suits you.
2. Which database should your host run?
WordPress keeps your posts, pages and settings in a database. Its requirements are MySQL 8.0 or later, or MariaDB 10.11 or later. The hosting handbook lists the long-term support versions: MySQL 8.4 or 8.0 and MariaDB 11.8 or 10.11. Count the databases in your plan too. A WordPress site usually needs one, but a staging copy or a second site needs another.
3. Does the host take care of HTTPS?
HTTPS isn’t an extra any more. Since Chrome 154, the browser asks for permission before opening a public site without HTTPS. Certificates are also getting shorter lifetimes. The CA/Browser Forum, where browsers and certificate authorities agree the rules, is cutting the maximum validity in steps from March 2026, down to 47 days in 2029. Let’s Encrypt goes from 90 to 64 days in February 2027 and to 45 days in February 2028. Renewing by hand quickly turns into a chore, so pick a host that requests and renews certificates automatically.
4. Can you make and restore backups yourself?
A backup has two parts: your files and your database. As WordPress puts it, you need both to restore your site. It recommends weekly backups for a small site and daily ones for a busy site, with three to five recent copies in different places. Ask your host whether it makes backups, how long it keeps them and whether you can download them. Then keep your own copy as well. A backup that only lives on the same server disappears with that server.
5. How much storage do you need?
WordPress itself takes up very little space. It’s your photos, videos and backups that fill the disk. A blog with a few photos per post fits in a small plan; a photography portfolio or a web shop grows faster. After a few months, check the size of your wp-content/uploads folder to see how quickly it’s growing. Keep an eye on monthly data traffic too, especially if you offer large downloads.
Web hosting at CakeHosting: SSD storage, databases for WordPress, mailboxes on your own domain and DDoS protection through RoyaleHosting, with more than 6 Tbps of capacity. View the plans.
6. How does the host protect you against attacks?
WordPress sites get two kinds of uninvited guests. A DDoS attack floods your site with traffic until it stops responding. What helps there is protection on your host’s network that filters out attack traffic before it reaches your server. In a brute-force attack, a bot tries thousands of passwords on your login page. According to WordPress, even unsuccessful attacks can overwhelm a site, and blocking them at the edge, before they reach your server, works best. So ask your host what it does about both. At CakeHosting, every website gets DDoS protection through RoyaleHosting, with more than 6 Tbps of capacity.
7. Where is the server?
The further your visitors are from the server, the longer the first byte takes to arrive. Google’s web.dev calls a Time to First Byte of 0.8 seconds or less good. If most of your visitors are in Europe, a server in Europe makes sense. If they come from all over the world, a CDN helps by serving your files from servers close to each visitor.
8. Can you leave easily?
The best host is one you’re not stuck with. Check whether you can cancel monthly, whether the domain name is registered to you and whether you have access to your own files and database. Then you can always move if it doesn’t work out; How to move your website to a new host shows you how. You can register a domain in your own name under domain names, for example.
Shared hosting, VPS or managed WordPress?
With shared hosting you share a server with other sites. It’s affordable and plenty for most blogs, portfolios and club websites. According to web.dev, shared hosting is generally slower than having your own server, which makes caching all the more important (see How to speed up a slow WordPress site). A VPS gives you your own virtual server, with more freedom but also more maintenance. With managed WordPress hosting the host handles updates for you, usually at a higher price. Building sites for clients? Then have a look at reseller hosting too. If you’re just starting out, shared hosting is almost always the sensible first step.
Which questions should you ask a host?
- Which PHP versions can I choose, and how long will they stay available?
- Which database do you run, and which version?
- Do I automatically get an SSL certificate that renews itself?
- Do you make backups, how long do you keep them and can I download them?
- How much storage, how many databases and how much data traffic do I get?
- What do you do about DDoS and brute-force attacks?
- Can I cancel monthly, and how do I take my site with me if I leave?
If you get a straight answer to every question, you’re in good hands. A host that dodges them is like a cake without an ingredients list: it may look tasty, but you have no idea what you’re getting.