Compare security by what the host prevents, what it detects, and what happens after an incident. Kinsta, WP Engine, and Cloudways provide security controls, but a managed hosting plan does not take ownership of every plugin, administrator account, or application vulnerability. The response process matters as much as the feature list.
Start with the division of responsibility
| Area | What to confirm with the host | What the site owner must arrange |
|---|---|---|
| Infrastructure | Patching and protection of the managed platform | Use supported configurations and access methods |
| WordPress software | Core and plugin update scope, exclusions, optional services | Maintain unsupported or custom components and test changes |
| Accounts | Available permissions and account protection | Remove former users, limit access, protect credentials |
| Detection | Scanning, alerts, and included coverage | Monitor messages and investigate application symptoms |
| Incident response | Cleanup scope, charges, escalation, limitations | Restore business operations and resolve the entry point |
| Recovery | Backup contents, retention, restore access | Test recovery and reconcile changed customer data |
Ask for these answers for the exact product and plan. "Security included" can refer to a platform firewall, an application add-on, or a service with a different cleanup scope. Those are not interchangeable promises.
Kinsta: check the scope of malware assistance
Kinsta documents malware-removal assistance and platform protections. Its malware policy also describes limitations. Treat this as an incident-response service to understand, not a guarantee that every infection can be prevented or every loss reversed.
Check plugin compatibility before moving, and identify who will maintain custom code and extensions. If an incident is caused by a vulnerable component, cleaning the site without resolving that component is not a complete operating plan. The Kinsta review separates the hosting service from application work.
WP Engine: distinguish standard protection from extensions
WP Engine documents its security environment and a separate Global Edge Security extension. Do not assume every feature described on the extension page is included in every hosting quote.
Ask which protection is included and whether the extension addresses a requirement you actually have. Also confirm the incident escalation route and the work expected from your developer. A restricted-plugin list can reduce certain platform risks but can also affect an existing site; check it before signup rather than discovering an incompatibility during migration.
Cloudways: identify the product and selected protection
Cloudways Flexible and Autonomous should not be treated as having identical security packages. Autonomous documents built-in malware protection. For Flexible, check the currently selected security services, their application coverage, and any extra charges in the quote.
If several client sites share a server, decide who receives alerts and who can approve recovery work. A feature activated for one application should not be assumed to cover an entire portfolio. The Cloudways review covers the wider responsibility and capacity decisions.
Ask what happens during a real incident
Give each candidate the same example: a site is redirecting visitors and the administrator cannot confidently identify the cause. Ask who investigates, whether cleanup is included, what access is required, how communication works, and what remains outside the service.
Then consider the business side. Who can pause sales, contact customers if necessary, rotate credentials, and approve a restore? Keep recovery access outside the affected hosting account. These decisions are useful before an emergency, even for a small site.
Security controls alone also do not establish regulatory or payment compliance. If your business has specific obligations, assess the complete application and operating process with the appropriate specialist rather than relying on a hosting badge.
Choose a service you can operate responsibly
Prefer the provider whose included controls and response scope match the work you can handle. Pay for an extra protection service when it closes an identified gap. Do not buy an overlapping feature simply because it sounds reassuring, and do not remove a useful control without understanding what replaces it.
Use backups compared to complete the recovery side of the decision, then add required security services to your total hosting cost. A clear division of work is more valuable than an unsupported promise that the site will never be compromised.