AsiaGB Security 2026: cpGuard, Free SSL & Backup — Complete Protection
Website security is not optional — it is the baseline. For Thai businesses and individuals hosting websites, a single malware infection or data breach can mean days of downtime, lost revenue, and damaged reputation. The question is: does your hosting provider help you stay secure, or leave you to figure it out alone?
AsiaGB, a Thai hosting provider with 19 years of experience, bundles a meaningful suite of security tools into every shared hosting plan at no extra charge. This guide walks through each layer of AsiaGB's security stack so you know exactly what protection you get — and where you may want to add your own measures.
AsiaGB Security Overview
AsiaGB takes a layered approach to website security. Rather than offering a single security product, they stack multiple protection mechanisms that work together: an active malware scanner at the application layer, free SSL encryption at the transport layer, scheduled backups at the data layer, and DirectAdmin's built-in account isolation at the operating system layer.
Here is a summary of every security feature included with all AsiaGB hosting plans:
| Security Feature | Included | Details |
|---|---|---|
| cpGuard Malware Scanner | Yes — all plans | Auto-scan for malware, backdoors, web shells |
| Free SSL Certificate | Yes — all plans | Let's Encrypt, auto-renewal |
| Automated Backups | Yes — all plans | 2× per month, kept for 1 year |
| Anti-Spam Email Filtering | Yes — all plans | Built-in spam and virus filtering for email |
| DirectAdmin Account Isolation | Yes — all plans | Each account sandboxed from others |
| Firewall Protection | Yes — server level | Network-level protection managed by AsiaGB |
All of these features come standard — there is no security add-on tier or premium upsell. Whether you are on the entry-level 5 GB plan at 500 THB/year or the 35 GB plan at 3,500 THB/year, you receive the same security capabilities.
cpGuard Malware Protection
cpGuard is a specialized web hosting security tool that sits at the heart of AsiaGB's malware defense. It operates as an active scanning engine that continuously monitors your hosting account's files for signs of compromise.
What cpGuard Scans For
cpGuard's detection engine targets three primary threat categories that are especially common in shared web hosting environments:
- Malware and malicious scripts: PHP files injected with malicious code, often inserted by attackers after compromising a weak password or outdated plugin
- Backdoors: Hidden files that give attackers persistent remote access to your hosting account even after initial infection is cleaned
- Web shells: Scripts that allow attackers to run operating system commands on the server from their browser — one of the most dangerous classes of malware in shared hosting
How cpGuard Alerts Work
When cpGuard detects a threat, it sends an immediate alert. This early-warning system is critical because the longer malware sits undetected, the more damage it can do: sending spam, stealing visitor data, defacing your site, or getting your domain blacklisted by Google.
The alert tells you which file is infected and what type of threat was found. You can then decide whether to delete the file, restore from backup, or investigate further. For non-technical users, cpGuard's alerts effectively act as a security professional watching your account around the clock.
cpGuard vs. Manual Security
Without an active scanner like cpGuard, website owners would need to manually review their files, use third-party scanning services, or hope they notice unusual server behavior before significant damage occurs. cpGuard automates this vigilance and is included in every AsiaGB plan, which is a significant advantage compared to hosting providers who charge separately for malware scanning.
cpGuard on Every AsiaGB Plan
Malware scanning, backdoor detection, and web shell alerts are bundled into all AsiaGB shared hosting plans — from 500 THB/year. No security add-on required.
View AsiaGB PlansFree SSL on Every Plan
SSL (Secure Sockets Layer) certificates are the technology behind the padlock icon in your browser's address bar and the "https://" prefix in URLs. An SSL certificate encrypts data traveling between your visitor's browser and your server, protecting sensitive information like passwords, form submissions, and payment data.
Why SSL Is Non-Negotiable in 2026
Google has used HTTPS as a ranking signal since 2014, and modern browsers actively warn users when they visit non-HTTPS sites with "Not Secure" labels. If your website does not have SSL, you will see lower search rankings and higher visitor drop-off rates. For e-commerce and lead generation sites, this directly impacts revenue.
How SSL Works on AsiaGB
AsiaGB provides free Let's Encrypt SSL certificates with every hosting plan. Let's Encrypt is a trusted certificate authority used by millions of websites worldwide. The SSL certificate is managed through DirectAdmin's SSL Manager, and renewal is automatic — you do not need to manually renew or pay for certificate renewals.
The process for activating SSL on a new domain with AsiaGB is straightforward:
- Log into DirectAdmin
- Navigate to SSL Manager under the Domain section
- Select your domain and choose "Let's Encrypt"
- Click to issue the certificate — it activates within minutes
Once SSL is active, you should configure your site to redirect all HTTP traffic to HTTPS so that visitors always use the secure connection. This can be done via a simple redirect rule in your .htaccess file or through DirectAdmin's redirect tools.
SSL for Multiple Domains
If your hosting plan includes multiple addon domains or subdomains, each can have its own free SSL certificate. You can also request a wildcard-style coverage for subdomains in some configurations. This means a growing website with multiple sub-sites does not need to purchase separate SSL certificates for each one.
Automated Backups
No security strategy is complete without backups. Even with excellent malware protection and SSL, unexpected events can destroy data: accidental file deletion, botched updates, corrupted databases, or catastrophic server hardware failure. Backups are your last line of defense.
AsiaGB Backup Schedule
AsiaGB runs automated backups twice per month on all hosting accounts. These backups are retained for one full year, giving you access to historical snapshots of your website going back 12 months. This is an unusually generous retention policy — many shared hosting providers keep backups for only 7 to 30 days.
What the Backup Includes
AsiaGB's backups cover the complete contents of your hosting account:
- All website files (HTML, PHP, images, CSS, JavaScript, and other assets)
- All MySQL databases (includes WordPress data, e-commerce orders, user registrations, etc.)
- Email accounts and their stored messages
- DNS zone configurations
- DirectAdmin account settings and configurations
Restoring from Backup
Backups are accessible via DirectAdmin's Backup Manager. You can browse available restore points, select the backup date you want to recover from, and restore either the entire account or specific files and databases. This self-service restore capability means you do not need to wait for support to intervene in most recovery scenarios.
For best results, complement AsiaGB's server-side backups with your own periodic manual downloads of your website files and database exports. This gives you an additional off-site copy independent of the hosting provider.
DirectAdmin Security Features
DirectAdmin, the control panel used exclusively by AsiaGB, includes several built-in security tools that give you direct control over your account's security posture.
Account Isolation
On shared hosting servers, multiple customer accounts share the same physical server. DirectAdmin enforces strict account isolation so that one customer's files cannot be read or modified by another customer. This prevents a common shared hosting risk where a compromised account on the same server could potentially affect neighbors.
Password Management
DirectAdmin provides a secure interface for managing all account passwords, including the main DirectAdmin login password, FTP passwords, email account passwords, and MySQL database user passwords. You can enforce strong passwords and update them regularly through a single, organized interface rather than managing credentials across multiple systems.
IP Blocking and Hotlink Protection
DirectAdmin includes IP blocking tools that allow you to deny access to your website from specific IP addresses or IP ranges. This is useful for blocking known malicious bots or unwanted scrapers. Hotlink protection prevents other websites from directly embedding your images or files, saving your bandwidth and protecting your content.
Error Logs and Access Logs
Access to raw server logs through DirectAdmin is a valuable security tool. Error logs help you spot unusual activity — such as repeated 404 errors on non-existent file paths (often indicating automated vulnerability scanning) or PHP errors that might reveal a compromised script. Access logs show every request made to your server, helping you identify suspicious IP addresses or attack patterns.
Firewall and DDoS Protection
Below the application layer, AsiaGB manages server-level firewall protection for all accounts on their infrastructure. This includes protection against common network-level attacks and contributes to the provider's 99% uptime commitment.
Network-Level Firewall
AsiaGB's servers are protected by network-level firewalls that filter malicious traffic before it reaches your website. This includes blocking known malicious IP ranges, filtering port scanning attempts, and applying rate limiting to protect against brute-force attacks on login pages and admin interfaces.
DDoS Mitigation
Distributed Denial of Service (DDoS) attacks attempt to overwhelm a server with traffic until it becomes unavailable. AsiaGB's data centers in Thailand and Singapore include upstream DDoS mitigation services that can absorb and filter attack traffic. For the majority of small and medium business websites, this server-level protection is sufficient. For websites that are high-value targets and face sustained, sophisticated DDoS attacks, a dedicated DDoS protection service or CDN with DDoS mitigation (such as Cloudflare) would provide an additional layer of protection.
HTTPS and Redirect Setup
Installing an SSL certificate is only the first step. To ensure all your visitors and search engine crawlers consistently use the secure HTTPS version of your site, you need to configure proper redirects.
Setting Up HTTP to HTTPS Redirect
The most reliable way to enforce HTTPS on an Apache-based shared hosting environment (which AsiaGB uses) is via the .htaccess file in your website's root directory. Add the following rules:
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
This tells the server to permanently redirect (301) any HTTP request to the HTTPS equivalent. The 301 status code passes link equity for SEO purposes, so search engines will index the HTTPS version of your pages.
Forcing www or non-www
Alongside HTTPS enforcement, choose a canonical domain format — either www.yourdomain.com or yourdomain.com — and redirect all traffic to that format. Running both versions without a redirect creates duplicate content issues for SEO. DirectAdmin allows you to set this up through its domain redirect settings, or you can add the redirect rules to .htaccess.
Checking Your HTTPS Configuration
After setting up SSL and redirects, verify your configuration using tools like SSL Labs' SSL Test (ssllabs.com/ssltest) to check your certificate and cipher configuration, and check that your entire site loads over HTTPS without mixed content warnings (where some resources like images or scripts are still loaded over HTTP).
Best Practices for Website Owners
AsiaGB's built-in security tools provide a strong foundation, but website security is a shared responsibility. Here is what you should do as a website owner to maximize your security on any hosting platform.
For WordPress Sites
- Keep WordPress core updated to the latest version
- Update all plugins and themes regularly
- Delete unused plugins and themes
- Use strong, unique passwords for admin accounts
- Enable two-factor authentication for WP admin
- Limit login attempts with a security plugin
- Change the default /wp-admin login URL
For All Websites
- Use strong passwords for all accounts (DirectAdmin, FTP, MySQL, email)
- Never reuse passwords across services
- Keep your FTP client and local computer malware-free
- Review cpGuard alerts promptly and act on them
- Download manual backups before major site changes
- Verify your SSL certificate is active and auto-renewing
- Monitor your site with a free uptime checker
Password Hygiene Is Your First Line of Defense
The majority of shared hosting compromises happen not through server vulnerabilities but through weak or reused passwords. An attacker with your DirectAdmin, FTP, or database password can bypass every other security measure instantly. Use a password manager to generate and store unique, complex passwords for every hosting-related credential.
Regular Plugin Audits for CMS Users
If you run WordPress, Joomla, or another CMS, outdated plugins are the single most common entry point for malware. cpGuard will detect infections after the fact, but preventing infection requires keeping all software up to date. Set a monthly reminder to review and update all your CMS components.
Conclusion
AsiaGB provides a comprehensive, multi-layer security stack that addresses the most common risks faced by small and medium websites: malware infection, man-in-the-middle attacks via unencrypted connections, and data loss from unexpected events. The combination of cpGuard's active malware scanning, free Let's Encrypt SSL, twice-monthly automated backups retained for a full year, and DirectAdmin's built-in security controls gives website owners meaningful protection without additional cost.
For a Thai hosting provider offering plans starting at 500 THB per year, the security package is substantial. The key areas where website owners need to contribute their own effort are keeping their CMS and plugins updated, using strong passwords, and reviewing cpGuard alerts when they arrive.
If you are looking for Thai hosting that treats security as a standard feature rather than an upsell, AsiaGB's approach is worth considering.
Start with Secure Hosting from 500 THB/Year
cpGuard malware protection, free SSL, and automated backups included in every AsiaGB plan. 19 years of hosting experience in Thailand and Singapore.
View AsiaGB PlansFrequently Asked Questions
Does cpGuard automatically remove malware, or does it just alert me?
cpGuard detects and alerts you to malware, backdoors, and web shells found in your account. The alert includes details about the affected file. You then decide whether to delete the file, quarantine it, or restore a clean version from backup. This approach ensures you are in control — automatic deletion can sometimes remove files that trigger false positives.
Is the free SSL certificate trusted by all browsers?
Yes. AsiaGB provides Let's Encrypt SSL certificates, which are trusted by all major browsers including Chrome, Firefox, Safari, and Edge, as well as mobile browsers on Android and iOS. Let's Encrypt is a widely recognized certificate authority used by over 300 million websites globally.
What happens if I need to restore from a backup? Do I need to contact support?
You can initiate most restorations yourself through DirectAdmin's Backup Manager without needing to contact support. You select the backup date and choose what to restore — full account, specific files, or specific databases. For complex recovery scenarios, AsiaGB's support team can assist.
Can I get daily backups instead of twice monthly?
The standard included backup schedule runs twice per month with one-year retention. If you need daily backups, you can create your own supplemental backup routine — for example, scheduling daily database exports via a cron job in DirectAdmin and downloading them to off-site storage, or using a WordPress backup plugin like UpdraftPlus that sends daily backups to cloud storage.
Does AsiaGB offer two-factor authentication (2FA) for the control panel?
DirectAdmin supports two-factor authentication (2FA) via TOTP apps such as Google Authenticator. Enabling 2FA on your DirectAdmin account adds a critical layer of protection: even if someone obtains your password, they cannot log in without also having access to your authentication app. It is strongly recommended to enable this.
My cpGuard alert says a file is infected. What should I do first?
First, do not panic. Note the exact file path mentioned in the alert. If it is a file you do not recognize, delete it. If it is a core CMS file (like a WordPress core file), restore it from a known clean version. Next, change all passwords associated with your hosting account — DirectAdmin, FTP, database, and email passwords. Then update all CMS software and plugins to close whatever vulnerability was exploited. Finally, check your site from a visitor's perspective to confirm it loads normally without any suspicious content or redirects.