50% off your first month on monthly billing, for new customers, with code See the plans
HostCrafter
Get started

Everything included, on every plan

There is no add-on list. This is the whole platform, and the smallest plan gets all of it — the panel, four caching layers, three kinds of backup, the security settings, and a person on live chat.

The panel

What you do every day

We wrote our own panel rather than shipping cPanel. It does the things a WordPress site needs and it does not have two hundred icons you will never press.

Install WordPress in a minute

Domain, admin username, email, password. It is installed, the database is made, SSL is queued and the page cache is configured before you see the login screen.

One click WP dashboard login

Sign into any of your sites from the panel. No shared admin account and no password to keep in a spreadsheet.

Staging, with a way back

Copy the live site, break it safely, publish it over the real one. If the publish is wrong, one click restores what was there before.

Clone a site

Duplicate a finished site onto a new domain instead of building the same stack of plugins again.

File manager

Upload, download, zip, unzip, rename, create and chmod. Enough to fix a theme file at midnight without opening an SFTP client.

phpMyAdmin, signed in for you

One click from the panel into the right database. No separate credentials to store.

PHP version per site

8.3 by default, and any single site can be moved to 8.1, 8.2, 8.4 or 8.5 when a plugin needs it.

Updates, with auto-update

See what is out of date across your sites, apply it, or leave it to run on its own.

Mailboxes and webmail

Real IMAP mailboxes on your own domain, created from the panel, with webmail included.

Logs, per website

The access log and the error log for one site, in the panel, without an SFTP client. Enough to see whether the 500 you are chasing is yours or ours.

Quick Migrate, done by you

Point it at your old host and it pulls the site across while you watch. For when you would rather not wait for us to do it.

A temporary address

Every site gets a HostCrafter address it answers on before your domain points here, so you can build and check it without touching DNS.

Speed

Where the milliseconds come from

Nothing here is a plugin you have to configure. It is how the server is set up before your site exists.

Multi-level caching

A cached page is served in milliseconds and never starts PHP. A caching plugin has to boot WordPress first, which costs 20–40 ms before it does anything at all.

Object cache

For pages that cannot be cached — anything logged in, and every WooCommerce checkout — the repeated database queries are answered from memory instead.

OPcache, tuned for the node

192 MB of compiled PHP held in memory and not revalidated on every request, because your files are not changing between one visitor and the next.

NVMe storage

Every node. WordPress reads a lot of small files, and that is the workload where NVMe pulls furthest ahead.

One PHP pool per website

Your site's workers are yours. They idle at close to nothing and start when a visitor arrives, so an idle site costs nobody anything.

Uncrowded on purpose

There is a hard cap on sites per node and we stop selling it there. This is the one that makes the other five worth having.

Security

Two layers, and you control the inner one

The server defends every site on it whether or not you ever open this part of the panel. What you get on top of that is a rule of your own, per website, that can be stricter than ours.

Attack blocking you set yourself

Per website: how many failed requests one address may make in a minute — anywhere from 4 to 25 — and how long it is blocked for, from fifteen minutes to a day. Turn it off for one site without touching the others.

A backstop you cannot switch off

Underneath your rule, the node blocks any address making more than 30 failed PHP requests in a minute. That one is not a setting. It is what catches the scanner that arrives while you are asleep.

XML-RPC shut, usernames hidden

Both on from the day a site goes up. xmlrpc.php carries hundreds of password attempts in a single request, and /wp-json/wp/v2/users hands out every author's login name — which is half of a password guess, given away. Signed-in users and your own plugins still read it.

Malware scanning, every night

Every account, at an hour you pick. Anything found is quarantined rather than deleted, so a false positive costs you a message to support and never a file.

Every site walled off from every other

Its own system user, its own database and user, its own PHP workers, and its own CPU and memory limits. One busy neighbour cannot take you with it.

SSL free, and SFTP on keys

Let's Encrypt on every domain and subdomain, issued the day DNS points here and renewed without you being told about it. SFTP is per site and takes a key rather than a password.

Backups

What happens when something goes wrong

Not if. The plan is what happens when.

Nightly backups you restore yourself

Every site, every night, kept 14 or 30 days. Restore from the panel without opening a ticket and waiting for a reply.

A backup before anything destructive

The platform takes one automatically before it does something it cannot undo, whether or not you remembered to.

Free migration, done by us

We rebuild the site here, you check it on a temporary address, and DNS only moves when you say so. Most are done inside 24 hours.

And the small things

  • Undo an update that broke something, from the panel
  • Object cache on Growth and up, on the phpredis extension
  • Change a site's domain without reinstalling anything
  • WP-Cron left to WordPress by default, or run by the server if you would rather
  • Unlimited subdomains on every plan
  • Databases you create yourself, on top of the one each WordPress install gets
  • Bandwidth counted only on your own domains — our temporary and staging addresses are never billed
  • The theme and plugin file editors, switchable off if you would rather they were not there
  • 7-day money back, and a renewal price that matches the one you signed up on
  • A hard cap on sites per node, and we stop selling it when it is reached
Questions

Frequently asked questions

Is anything on this page an extra charge?

No. Everything listed here is on every plan including the smallest. What differs between plans is the size of the resources — sites, storage, memory, workers — and the backup retention.

Do you use cPanel?

No. We built our own panel for WordPress. If your reason for wanting cPanel is a specific thing it does, ask us on chat — most of the time the answer is that our panel does it too, and occasionally the honest answer is that we are not the right host for you.

Is the security on by default, or do I have to set it up?

On by default. A new website arrives with attack blocking running, XML-RPC closed and its usernames hidden from the REST API, and the server's own backstop is on underneath regardless. The settings in the panel are there to make your rule stricter than the default, or to switch a piece of it off if something you use needs it open.

Managed WordPress, without the guesswork

Pick a plan, or ask us first — we would rather talk you into the right one than sell you the big one.

7-day money back · Free migration inside 24 hours · Renews at the price you signed up on