A note on what this article does and does not claim: SSL bundling details below are drawn from multiple independent hosting comparison sources and cross-checked for consistency. The security incident history section includes only breaches that are publicly documented through SEC filings, direct company disclosures, or major news reporting. Where no comparable documented incident was found for a provider, this article says so explicitly rather than implying a clean record, since absence of a found incident in this research is not the same as a verified clean history. No uptime percentage in this article is independently audited data; where a host advertises a specific uptime figure, it is identified as the host’s own marketing claim.
SSL Bundling by Provider: What’s Actually Included
Free SSL via Let’s Encrypt has become close to universal among mainstream shared hosting providers, but the specifics (unlimited versus capped, standard versus wildcard, automatic versus manual activation) still vary in ways that matter.
| Provider | SSL offering | Notable detail |
| Bluehost | Free, unlimited SSL via Let’s Encrypt on shared hosting plans | Included as standard across plans; free domain for first year also bundled |
| SiteGround | Free, unlimited Let’s Encrypt WILDCARD SSL on every plan | Wildcard specifically, meaning subdomains are covered under one certificate, a step beyond standard single-domain free SSL |
| DreamHost | Free, unlimited Let’s Encrypt SSL, automatic activation and renewal | Advertises a 100 percent uptime guarantee; this is DreamHost’s own stated marketing claim, not independently audited uptime data |
| Namecheap | 50 free PositiveSSL certificates included (capped, not unlimited) | An exception to the unlimited-SSL norm among the providers reviewed; the cap matters for accounts managing many domains |
| Liquid Web | Free, unlimited SSL | Positioned primarily for VPS and managed hosting customers rather than entry-level shared hosting |
| GreenGeeks | Free SSL bundled with a free CDN | SSL and CDN bundled together as a single included feature rather than separate add-ons |
| Hostwinds | Does not offer free Let’s Encrypt SSL on shared hosting specifically | A notable exception; Let’s Encrypt is available on VPS and dedicated plans via manual WHM configuration rather than automatic shared-hosting bundling |
Free, unlimited Let’s Encrypt SSL is now the default expectation across mainstream shared hosting, to the point that a host without it (like Hostwinds on its shared tier) stands out as an exception rather than the norm. The more useful comparison point in 2026 is no longer ‘does this host include free SSL’ but specifics like wildcard coverage, certificate count caps, and whether activation and renewal are fully automatic or require manual cPanel/WHM configuration.
Security Incident History: GoDaddy’s Well-Documented Pattern
Among major hosting providers, GoDaddy has the most extensively documented public breach history, established through multiple SEC filings and confirmed by major outlets including BleepingComputer, TechRadar, and direct company disclosures. This is presented as a detailed case study precisely because the documentation trail is unusually thorough and verifiable.
| Date | Incident | What happened |
| October 2019 | Unauthorized access to hosting account credentials | GoDaddy identified suspicious activity on a server and disclosed unauthorized access affecting hosting account login information. The company stated the intruders did not access the main customer account or modify files stored in hosting accounts. |
| November 2021 (disclosed) | Managed WordPress breach, 1.2 million customers | An attacker used a compromised password to access GoDaddy’s Managed WordPress hosting environment code base. GoDaddy reset SFTP and database passwords and began reissuing SSL certificates for affected customers, since the exposure created risk around stolen SSL private keys specifically, not just login credentials. |
| March 2020 (occurred) / February-March 2023 (disclosed) | Multi-year sophisticated intrusion campaign | GoDaddy’s 2023 SEC filing revealed that a security incident which actually began in March 2020 was not detected until late 2022, nearly three years later. The company stated this incident, along with the November 2021 breach, were both part of the same multi-year campaign by one threat actor, who installed malware and obtained source code related to some GoDaddy services. |
Independent cyber risk analysis from CyberCube, cited in coverage of the 2023 disclosure, states that GoDaddy has been targeted in at least 14 separate data breaches involving personally identifiable information since 2011, a pattern analysts have specifically flagged as evidence of recurring rather than isolated security weaknesses given GoDaddy’s scale (an estimated 20 million customers and over 84 million domains under management at the time of the 2023 disclosure).
The 2021 GoDaddy breach is specifically relevant to SSL certificate security, not just general data exposure: the incident created a scenario where SSL private keys for affected Managed WordPress customers were potentially exposed, requiring GoDaddy to reissue certificates rather than simply reset passwords. A compromised hosting provider’s breach can directly affect the SSL certificates installed on customer sites, which is a distinct and more severe category of impact than a typical credential-only breach.
What This Research Did Not Find for Other Major Providers
This article’s research did not surface a publicly documented, SEC-filed or major-outlet-confirmed security breach for Bluehost, SiteGround, Hostinger, DreamHost, Namecheap, or GreenGeeks specifically as hosting companies, comparable in scale and documentation quality to GoDaddy’s history.
This is stated explicitly because it would be easy, and inaccurate, to read that absence as proof these companies have a perfect security record. It is not proof of that. It means only that no comparable, well-documented breach disclosure was identified in this specific research effort. Several of these companies are privately held (DreamHost) or operate under broader corporate ownership structures (Bluehost is part of Newfold Digital, which also owns several other hosting brands) where breach disclosure practices, regulatory reporting obligations, and public visibility may differ meaningfully from a publicly traded company like GoDaddy, which faces SEC disclosure requirements that create a more complete public paper trail almost by structural necessity.
A more accurate framing of the available evidence: GoDaddy’s breach history is unusually well documented because of its scale, its public company status, and its position as what cyber risk analysts describe as a single point of failure (SPoF) target given how much of the internet’s infrastructure depends on it. The absence of comparably documented incidents at other major hosts in this research should be read as a data gap, not a verified clean bill of health.
Why This Article Does Not Publish a Comparative Uptime Table
Several hosts advertise specific uptime commitments. DreamHost states a 100 percent uptime guarantee on its own marketing materials. Other providers commonly cite figures in the 99.9 percent range. These are the hosts’ own stated guarantees or marketing claims, not independently audited, third-party-verified uptime measurements across a common methodology and time period.
Producing a genuinely comparative, evidence-based uptime table would require either each provider’s own internal monitoring data (which is not independently verifiable from outside the company) or a third-party uptime monitoring service that has continuously tracked multiple major hosts over an identical measurement window with a transparent methodology. This article did not have access to that kind of dataset and is therefore not presenting an uptime comparison, to avoid implying a level of precision and independent verification that does not exist behind the numbers.
If uptime reliability is a primary concern in choosing a host, independent third-party uptime monitoring services (such as those that track and publish ongoing uptime statistics across multiple hosting providers using a consistent measurement methodology) are a more reliable source than any single provider’s self-reported guarantee. A hosting provider’s own advertised uptime percentage is a marketing claim and a service-level commitment, which is useful as a contractual benchmark, but it is not equivalent to independently measured historical performance.
Frequently Asked Questions
Does a host’s free SSL certificate offer the same security as a paid certificate?
For encryption strength, yes: a free Let’s Encrypt DV certificate provides cryptographically identical encryption to a paid DV certificate from any commercial CA. What a paid OV or EV certificate adds is CA-verified organizational identity in the certificate, which free DV certificates do not include. For most informational websites and blogs, free hosting-bundled SSL is fully adequate. For sites collecting payment information, sensitive personal data, or operating in regulated industries, an OV certificate’s verified business identity may be a meaningful additional consideration, independent of the hosting provider’s own security track record.
If my hosting provider has a documented breach history, should I switch hosts?
A documented breach history is one input into that decision, not an automatic disqualifier. What matters more than the existence of a past incident is the provider’s disclosed response: did they notify affected customers promptly, did they take concrete remediation steps (password resets, certificate reissuance, infrastructure hardening), and is there evidence of a pattern of recurring, unaddressed weaknesses versus a single isolated incident followed by genuine security investment. GoDaddy’s documented multi-year detection gap (a 2020 intrusion not detected until 2022) is a more serious signal than a single, quickly detected and disclosed incident would be, since it points to a sustained monitoring and detection gap rather than just one successful attack.
Why does this article only cover one provider’s breach history in detail?
Because that is what the available, verifiable public record supports. Building a comparative breach history table across multiple providers requires that comparably documented incidents actually exist and be publicly verifiable for each provider being compared. Inventing or implying parallel incident histories for providers where no such documentation was found would not be an honest comparison; it would be fabricated content. This article presents what is genuinely documented for the one provider with an extensive public record and states clearly where the research found no comparable documentation for the others.
