Critical-risk tools in Hostinger Api
60 of the 382 tools in Hostinger Api are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
agency-hosting_clearWebsiteCacheV1DestructiveClears cache for all domains associated with an Agency Plan website, including its preview domain. This operation clears all cache types for the website.
-
agency-hosting_deleteWebsiteCronJobV1DestructivePermanently deletes the cron job identified by its uuid from an Agency Plan website. The operation is idempotent: deleting a cron job that does not exist succeeds without error.
-
agency-hosting_deleteWebsiteDatabaseUserV1DestructivePermanently deletes a database user from an Agency Plan website database, revoking all access it had. The operation is idempotent: deleting a user that does not exist succeeds ...
-
agency-hosting_deleteWebsiteDatabaseV1DestructivePermanently deletes a MySQL database and all its data from an Agency Plan website, including its users. The operation is idempotent: deleting a database that does not exist suc...
-
agency-hosting_deleteWebsiteV1DestructivePermanently deletes an Agency Plan website. Deletion is processed asynchronously: the website is immediately transitioned to a deleting state and the underlying server resources...
-
agency-hosting_deployNodeStaticWebsiteDestructiveDeploy a node-static Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone — always confirm with the user...
-
agency-hosting_deployPhpApplicationDestructiveDeploy a PHP (or other non-build) Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone — always confirm ...
-
billing_deletePaymentMethodV1DestructiveDelete a payment method from your account. Use this endpoint to remove unused payment methods from user accounts.
-
DNS_deleteDNSRecordsV1DestructiveDelete DNS records for the selected domain. To filter which records to delete, add the `name` of the record and `type` to the filter. Multiple filters can be provided with sin...
-
DNS_resetDNSRecordsV1DestructiveReset DNS zone to the default records. Use this endpoint to restore domain DNS to original configuration.
-
domains_cancelPendingIRTPVerificationV1DestructiveCancel a pending IRTP verification. Use this endpoint to back out of a WHOIS change that is stuck waiting on registrant confirmation, for example when the confirmation email ca...
-
domains_deleteDomainForwardingV1DestructiveDelete domain forwarding data. Use this endpoint to remove redirect configuration from domains.
-
domains_deleteWHOISProfileV1DestructiveDelete WHOIS contact profile. Use this endpoint to remove unused contact profiles from account.
-
ecommerce_cancelAnOrderV1DestructiveCancel the order and optionally email the customer. Returns the updated order summary.
-
ecommerce_deleteAProductV1DestructiveDelete a product and its variants from the store. A subscription product with active subscribers is archived instead of deleted so its data stays available.
-
ecommerce_deleteAProductVariantV1DestructiveDelete a single variant from the product.
-
ecommerce_deleteStoreV1DestructiveSoft-delete a store owned by your account. The underlying store data is preserved; only the store is marked as deleted.
-
hosting_clearNode_jsRuntimeLogsV1DestructiveEmpties the Node.js application's runtime log file. This cannot be undone, so confirm with the user before calling it. Returns success even when no log file exists yet. Use it ...
-
hosting_clearWebsiteCacheV1DestructivePermanently clears all server-side cache for the website at once. Use it when content was updated and needs to be visible immediately, or after making major changes. Also purge...
-
hosting_deleteAccountCronJobV1DestructivePermanently deletes the cron job identified by its uid. The uid is returned by the list cron jobs endpoint.
-
hosting_deleteAccountDatabaseV1DestructivePermanently deletes a database and its remote connections. The database name must be the full name returned by the list databases endpoint.
-
hosting_deleteDatabaseRemoteConnectionV1DestructivePermanently removes a remote-access rule, revoking the given host's remote access to the database. Identify the rule with the required ip query parameter (the IPv4/IPv6 address...
-
hosting_deleteWebsiteParkedDomainV1DestructiveDelete an existing parked or alias domain from the selected website. Use this endpoint to remove parked domains that are no longer needed.
-
hosting_deleteWebsiteRedirectV1DestructivePermanently deletes the redirect identified by its source URL. Pass the `from` value exactly as returned by the list redirects endpoint.
-
hosting_deleteWebsiteSubdomainV1DestructiveDelete an existing subdomain from the selected website. Use this endpoint to remove subdomains that are no longer needed.
-
hosting_deleteWebsiteV1DestructiveThis endpoint permanently removes a website and all of its data. This action cannot be undone. Before calling it, make sure the user understands the consequences and explicitly ...
-
hosting_deleteWordPressInstallationV1DestructiveDelete the specified WordPress installation, with optional file and database removal. This removes all associated components including plugins, themes, staging websites and any ...
-
hosting_deployStaticSiteArchiveV1DestructiveDeploy a static application from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone — verify this is intended before calling this en...
-
hosting_importWordPressWebsiteV1DestructiveImport WordPress website to the specified domain. WARNING: this overwrites the website's existing contents and cannot be undone — verify this is intended before calling this en...
-
hosting_startNode_jsBuildV1DestructiveStart a Node.js build process using files already present on the website's file storage. WARNING: on success this overwrites the website's existing contents and cannot be undon...
-
hosting_uninstallWordPressPluginsV1DestructiveUninstall one or more plugins from a WordPress installation. Provide the WordPress installation (software) identifier in the path. It can be obtained from GET /api/hosting/v1/w...
-
hosting_uninstallWordPressThemesV1DestructiveUninstall one or more themes from a WordPress installation. Provide the WordPress installation (software) identifier in the path. It can be obtained from GET /api/hosting/v1/wo...
-
mail_deleteAliasV1DestructiveDelete an alias. Messages sent to the alias address are no longer delivered to the mailbox.
-
mail_deleteAutoreplyV1DestructiveDelete the autoreply of a mailbox. The mailbox stops sending automatic replies immediately.
-
mail_deleteCatchAllV1DestructiveDelete a catch-all. Messages sent to unknown addresses of the domain are no longer routed to the mailbox.
-
mail_deleteForwarderV1DestructiveDelete a forwarder. The mailbox stops forwarding messages to the destination address immediately.
-
mail_deleteMailboxV1DestructiveDelete a mailbox. The mailbox is soft-deleted and stays restorable for a limited period before it is permanently removed.
-
mail_deleteWebhookV1DestructivePermanently delete a webhook. This action cannot be undone. After deletion the URL no longer receives event notifications.
-
mail_revokeAPITokenV1DestructiveRevoke an API token. The token immediately loses access to the [Hostinger Email API](https://api.mail.hostinger.com/). This action cannot be undone.
-
reach_deleteAContactFieldV1DestructiveDelete a custom contact field. Every value contacts hold for the field is deleted with it, and for the choice types so are its options. The contacts themselves are not affected.
-
reach_deleteAContactV1DestructiveDelete a contact with the specified UUID. This endpoint permanently removes a contact from the email marketing system. **Deprecated.** This endpoint cannot target a profile, s...
-
reach_deleteAProfileContactV1DestructivePermanently delete a contact from a profile. The contact is removed together with its custom field values and tag assignments.
-
reach_deleteAProfileSegmentV1DestructiveDelete a segment. Only the segment definition is removed. The contacts that matched it are left untouched.
-
reach_deleteATagV1DestructiveDelete a tag and remove it from every contact carrying it. The contacts themselves are not deleted. This is idempotent: deleting a tag that does not exist in the profile still ...
-
reach_deleteFormV1DestructivePermanently delete a form together with its template. A form that has already captured submissions cannot be deleted, so that the contacts it collected are never silently disca...
-
VPS_deleteFirewallRuleV1DestructiveDelete a specific firewall rule from a specified firewall. Any virtual machine that has this firewall activated will lose sync with the firewall and will have to be synced agai...
-
VPS_deleteFirewallV1DestructiveDelete a specified firewall. Any virtual machine that has this firewall activated will automatically have it deactivated. Use this endpoint to remove unused firewall configura...
-
VPS_deletePostInstallScriptV1DestructiveDelete a post-install script from your account. Use this endpoint to remove unused automation scripts.
-
VPS_deleteProjectV1DestructiveCompletely removes a Docker Compose project from the virtual machine, stopping all containers and cleaning up associated resources including networks, volumes, and images. Th...
-
VPS_deletePTRRecordV1DestructiveDelete a PTR (Pointer) record for a specified virtual machine. Once deleted, reverse DNS lookups to the virtual machine's IP address will no longer return the previously config...
-
VPS_deletePublicKeyV1DestructiveDelete a public key from your account. **Deleting public key from account does not remove it from virtual machine** Use this endpoint to remove unused SSH keys from a...
-
VPS_deleteSnapshotV1DestructiveDelete a snapshot of a specified virtual machine. Use this endpoint to remove VPS snapshots.
-
VPS_recreateVirtualMachineV1DestructiveRecreate a virtual machine from scratch. The recreation process involves reinstalling the operating system and resetting the virtual machine to its initial state. Snapshots, if...
-
VPS_restoreBackupV1DestructiveRestore a backup for a specified virtual machine. The system will then initiate the restore process, which may take some time depending on the size of the backup. **All data o...
-
VPS_uninstallMonarxV1DestructiveUninstall the Monarx malware scanner on a specified virtual machine. If Monarx is not installed, the request will still be processed without any effect. Use this endpoint to r...
-
billing_createPurchaseOrderV1FinancialCreate a purchase order for any Hostinger product. This unified endpoint places an order for one or more catalog items and works across all Hostinger products, leveraging the e...
-
billing_renewSubscriptionV1FinancialCreate a renewal order for an existing Hostinger subscription. This endpoint places a renewal order for a single subscription, leveraging the existing billing infrastructure. U...
-
billing_setDefaultPaymentMethodV1FinancialSet the default payment method for your account. Use this endpoint to configure the primary payment method for future orders.
-
domains_purchaseNewDomainV1FinancialPurchase and register a new domain name. If registration fails, login to [hPanel](https://hpanel.hostinger.com/) and check domain registration status. If no payment method is ...
-
VPS_purchaseNewVirtualMachineV1FinancialPurchase and setup a new virtual machine. If virtual machine setup fails for any reason, login to [hPanel](https://hpanel.hostinger.com/) and complete the setup manually. If n...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.