How to Safely Give a Specialist Access to Your Hosting
Giving Someone Hosting Access — What Could Go Wrong?
When you commission virus removal from a website, the specialist needs access to the server. This is necessary — analysis over FTP or SSH is essential for effective cleanup. However, sharing access without thinking it through carries its own security risks. This article shows you how to do it properly.
What Does the Specialist Actually Need?
Effective malware removal requires one of the following types of access (the higher on the list, the better):
- SSH access — the most effective option. It allows for quick analysis of the entire server, searching for malware patterns, and bulk file operations. Without SSH, the work takes several times longer.
- FTP/SFTP access — sufficient for basic file cleanup. Slower than SSH, and does not provide access to system logs.
- Hosting control panel access (cPanel/Plesk/DirectAdmin) — provides access to File Manager, phpMyAdmin, and configuration. Sufficient for most cases.
- phpMyAdmin access or a database export — needed to clean the database. This can be provided separately from file access.
How to Share Access Safely
Never Send Passwords by Email or Messenger
Email is not end-to-end encrypted. A message containing a password in your inbox can be read by a third party — or by hackers if the mailbox is compromised (which happens during break-ins).
Secure ways to share a password:
- A one-time password link — services such as Privnote.com or OneTimeSecret.com — the link expires after one view
- A password manager with sharing — Bitwarden or 1Password allow you to share a password without sending it in readable form
- SMS separate from the username — send the username by email and the password by SMS to the specialist’s number
Create a Temporary FTP/SSH Account for the Work Only
Most hosting panels allow you to create additional FTP accounts with limited access to a selected directory. Instead of giving out your main FTP password, create a temporary account:
- Username: e.g.
service_cleanup
- Password: randomly generated
- Directory:
/public_html/ (and nothing beyond it)
- After the work is complete: delete this account
Document What You Share
Make a note of what you shared and with whom: the type of access, date, and scope. This will make it easier to revoke access later and check whether anything unauthorized happened.
What to Do AFTER the Work Is Complete
This is the step site owners most often overlook:
- Change the password for the main FTP/SSH account
- Delete the temporary FTP/SSH account if you created one
- Remove the specialist from the WordPress user list if they had an account there
- Change the hosting panel password if the specialist had access to it
- Check the access logs in the hosting panel — make sure there were no logins outside the expected time window
What NOT to Share
- Access to email associated with the domain or hosting (it is unnecessary and risky)
- Access to the domain registrar (it is not needed to work on the server)
- Payment card details in the hosting panel (block them before granting panel access)
- Login details for external services (Google Analytics, Ads, Search Console) if they are not essential
Trusted vs. Untrusted Specialists — How to Tell the Difference
A few questions worth asking before granting access:
- Can I see references or examples of previous work (anonymized)?
- How will you protect my login details after the work is complete?
- Do you provide a guarantee for the service performed?
- Can I receive a report detailing what you found and changed?
A reputable company will answer these questions without any problem. No answer or evasiveness is a warning sign.