Everything included, on every plan
There is no add-on list. This is the whole platform, and the smallest plan gets all of it — the panel, four caching layers, three kinds of backup, the security settings, and a person on live chat.
What you do every day
We wrote our own panel rather than shipping cPanel. It does the things a WordPress site needs and it does not have two hundred icons you will never press.
Install WordPress in a minute
Domain, admin username, email, password. It is installed, the database is made, SSL is queued and the page cache is configured before you see the login screen.
One click WP dashboard login
Sign into any of your sites from the panel. No shared admin account and no password to keep in a spreadsheet.
Staging, with a way back
Copy the live site, break it safely, publish it over the real one. If the publish is wrong, one click restores what was there before.
Clone a site
Duplicate a finished site onto a new domain instead of building the same stack of plugins again.
File manager
Upload, download, zip, unzip, rename, create and chmod. Enough to fix a theme file at midnight without opening an SFTP client.
phpMyAdmin, signed in for you
One click from the panel into the right database. No separate credentials to store.
PHP version per site
8.3 by default, and any single site can be moved to 8.1, 8.2, 8.4 or 8.5 when a plugin needs it.
Updates, with auto-update
See what is out of date across your sites, apply it, or leave it to run on its own.
Mailboxes and webmail
Real IMAP mailboxes on your own domain, created from the panel, with webmail included.
Logs, per website
The access log and the error log for one site, in the panel, without an SFTP client. Enough to see whether the 500 you are chasing is yours or ours.
Quick Migrate, done by you
Point it at your old host and it pulls the site across while you watch. For when you would rather not wait for us to do it.
A temporary address
Every site gets a HostCrafter address it answers on before your domain points here, so you can build and check it without touching DNS.
Where the milliseconds come from
Nothing here is a plugin you have to configure. It is how the server is set up before your site exists.
Multi-level caching
A cached page is served in milliseconds and never starts PHP. A caching plugin has to boot WordPress first, which costs 20–40 ms before it does anything at all.
Object cache
For pages that cannot be cached — anything logged in, and every WooCommerce checkout — the repeated database queries are answered from memory instead.
OPcache, tuned for the node
192 MB of compiled PHP held in memory and not revalidated on every request, because your files are not changing between one visitor and the next.
NVMe storage
Every node. WordPress reads a lot of small files, and that is the workload where NVMe pulls furthest ahead.
One PHP pool per website
Your site's workers are yours. They idle at close to nothing and start when a visitor arrives, so an idle site costs nobody anything.
Uncrowded on purpose
There is a hard cap on sites per node and we stop selling it there. This is the one that makes the other five worth having.
Two layers, and you control the inner one
The server defends every site on it whether or not you ever open this part of the panel. What you get on top of that is a rule of your own, per website, that can be stricter than ours.
Attack blocking you set yourself
Per website: how many failed requests one address may make in a minute — anywhere from 4 to 25 — and how long it is blocked for, from fifteen minutes to a day. Turn it off for one site without touching the others.
A backstop you cannot switch off
Underneath your rule, the node blocks any address making more than 30 failed PHP requests in a minute. That one is not a setting. It is what catches the scanner that arrives while you are asleep.
XML-RPC shut, usernames hidden
Both on from the day a site goes up. xmlrpc.php carries hundreds of password attempts in a single request, and /wp-json/wp/v2/users hands out every author's login name — which is half of a password guess, given away. Signed-in users and your own plugins still read it.
Malware scanning, every night
Every account, at an hour you pick. Anything found is quarantined rather than deleted, so a false positive costs you a message to support and never a file.
Every site walled off from every other
Its own system user, its own database and user, its own PHP workers, and its own CPU and memory limits. One busy neighbour cannot take you with it.
SSL free, and SFTP on keys
Let's Encrypt on every domain and subdomain, issued the day DNS points here and renewed without you being told about it. SFTP is per site and takes a key rather than a password.
What happens when something goes wrong
Not if. The plan is what happens when.
Nightly backups you restore yourself
Every site, every night, kept 14 or 30 days. Restore from the panel without opening a ticket and waiting for a reply.
A backup before anything destructive
The platform takes one automatically before it does something it cannot undo, whether or not you remembered to.
Free migration, done by us
We rebuild the site here, you check it on a temporary address, and DNS only moves when you say so. Most are done inside 24 hours.
And the small things
- Undo an update that broke something, from the panel
- Object cache on Growth and up, on the phpredis extension
- Change a site's domain without reinstalling anything
- WP-Cron left to WordPress by default, or run by the server if you would rather
- Unlimited subdomains on every plan
- Databases you create yourself, on top of the one each WordPress install gets
- Bandwidth counted only on your own domains — our temporary and staging addresses are never billed
- The theme and plugin file editors, switchable off if you would rather they were not there
- 7-day money back, and a renewal price that matches the one you signed up on
- A hard cap on sites per node, and we stop selling it when it is reached
Frequently asked questions
Is anything on this page an extra charge?
No. Everything listed here is on every plan including the smallest. What differs between plans is the size of the resources — sites, storage, memory, workers — and the backup retention.
Do you use cPanel?
No. We built our own panel for WordPress. If your reason for wanting cPanel is a specific thing it does, ask us on chat — most of the time the answer is that our panel does it too, and occasionally the honest answer is that we are not the right host for you.
Is the security on by default, or do I have to set it up?
On by default. A new website arrives with attack blocking running, XML-RPC closed and its usernames hidden from the REST API, and the server's own backstop is on underneath regardless. The settings in the panel are there to make your rule stricter than the default, or to switch a piece of it off if something you use needs it open.
Managed WordPress, without the guesswork
Pick a plan, or ask us first — we would rather talk you into the right one than sell you the big one.
7-day money back · Free migration inside 24 hours · Renews at the price you signed up on