Critical-risk tools in Hostinger Api
40 of the 258 tools in Hostinger Api are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
agency-hosting_clearAgencyPlanWebsiteCacheV1DestructiveClears cache for all domains associated with an Agency Plan website, including its preview domain. This operation clears all cache types for the website.
-
agency-hosting_deleteAgencyPlanWebsiteCronJobV1DestructivePermanently deletes the cron job identified by its uuid from an Agency Plan website. The operation is idempotent: deleting a cron job that does not exist succeeds without error.
-
agency-hosting_deleteAgencyPlanWebsiteDatabaseUserV1DestructivePermanently deletes a database user from an Agency Plan website database, revoking all access it had. The operation is idempotent: deleting a user that does not exist succeeds ...
-
agency-hosting_deleteAgencyPlanWebsiteDatabaseV1DestructivePermanently deletes a MySQL database and all its data from an Agency Plan website, including its users. The operation is idempotent: deleting a database that does not exist suc...
-
agency-hosting_deleteAgencyPlanWebsiteV1DestructiveDeletes an Agency Plan website and schedules cleanup of its resources. This action is irreversible. Website files, databases, and linked domains are removed.
-
agencyHosting_deployNodeStaticWebsiteDestructiveDeploy a node-static Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone — always confirm with the user...
-
agencyHosting_deployPhpApplicationDestructiveDeploy a PHP (or other non-build) Agency Plan (h5g) website from an archive file. WARNING: this overwrites the website's existing contents and cannot be undone — always confirm ...
-
billing_deletePaymentMethodV1DestructiveDelete a payment method from your account. Use this endpoint to remove unused payment methods from user accounts.
-
DNS_deleteDNSRecordsV1DestructiveDelete DNS records for the selected domain. To filter which records to delete, add the `name` of the record and `type` to the filter. Multiple filters can be provided with sin...
-
DNS_resetDNSRecordsV1DestructiveReset DNS zone to the default records. Use this endpoint to restore domain DNS to original configuration.
-
domains_deleteDomainForwardingV1DestructiveDelete domain forwarding data. Use this endpoint to remove redirect configuration from domains.
-
domains_deleteWHOISProfileV1DestructiveDelete WHOIS contact profile. Use this endpoint to remove unused contact profiles from account.
-
ecommerce_deleteStoreV1DestructiveSoft-delete a store owned by your account. The underlying store data is preserved; only the store is marked as deleted.
-
hosting_clearWebsiteCacheV1DestructivePermanently clears all server-side cache for the website at once. Use it when content was updated and needs to be visible immediately, or after making major changes. Also purge...
-
hosting_deleteAccountCronJobV1DestructivePermanently deletes the cron job identified by its uid. The uid is returned by the list cron jobs endpoint.
-
hosting_deleteAccountDatabaseRemoteConnectionV1DestructivePermanently removes a remote-access rule, revoking the given host's remote access to the database. Identify the rule with the required ip query parameter (the IPv4/IPv6 address...
-
hosting_deleteAccountDatabaseV1DestructivePermanently deletes a database and its remote connections. The database name must be the full name returned by the list databases endpoint.
-
hosting_deleteWebsiteParkedDomainV1DestructiveDelete an existing parked or alias domain from the selected website. Use this endpoint to remove parked domains that are no longer needed.
-
hosting_deleteWebsiteSubdomainV1DestructiveDelete an existing subdomain from the selected website. Use this endpoint to remove subdomains that are no longer needed.
-
hosting_deleteWebsiteV1DestructivePermanently deletes a website and all of its data. This action is destructive and cannot be undone. Always ask the user for explicit confirmation before calling this endpoint. ...
-
hosting_deleteWordPressInstallationV1DestructiveDelete the specified WordPress installation, with optional file and database removal. This removes all associated components including plugins, themes, staging websites and any ...
-
hosting_uninstallWordPressPluginsV1DestructiveUninstall one or more plugins from a WordPress installation. Provide the WordPress installation (software) identifier in the path. It can be obtained from GET /api/hosting/v1/w...
-
hosting_uninstallWordPressThemesV1DestructiveUninstall one or more themes from a WordPress installation. Provide the WordPress installation (software) identifier in the path. It can be obtained from GET /api/hosting/v1/wo...
-
mail_deleteMailboxV1DestructiveDelete a mailbox. The mailbox is soft-deleted and stays restorable for a limited period before it is permanently removed.
-
mail_deleteWebhookV1DestructivePermanently delete a webhook. This action cannot be undone. After deletion the URL no longer receives event notifications.
-
mail_revokeAPITokenV1DestructiveRevoke an API token. The token immediately loses access to the [Hostinger Email API](https://api.mail.hostinger.com/). This action cannot be undone.
-
reach_deleteAContactV1DestructiveDelete a contact with the specified UUID. This endpoint permanently removes a contact from the email marketing system.
-
VPS_deleteFirewallRuleV1DestructiveDelete a specific firewall rule from a specified firewall. Any virtual machine that has this firewall activated will lose sync with the firewall and will have to be synced agai...
-
VPS_deleteFirewallV1DestructiveDelete a specified firewall. Any virtual machine that has this firewall activated will automatically have it deactivated. Use this endpoint to remove unused firewall configura...
-
VPS_deletePostInstallScriptV1DestructiveDelete a post-install script from your account. Use this endpoint to remove unused automation scripts.
-
VPS_deleteProjectV1DestructiveCompletely removes a Docker Compose project from the virtual machine, stopping all containers and cleaning up associated resources including networks, volumes, and images. Th...
-
VPS_deletePTRRecordV1DestructiveDelete a PTR (Pointer) record for a specified virtual machine. Once deleted, reverse DNS lookups to the virtual machine's IP address will no longer return the previously config...
-
VPS_deletePublicKeyV1DestructiveDelete a public key from your account. **Deleting public key from account does not remove it from virtual machine** Use this endpoint to remove unused SSH keys from a...
-
VPS_deleteSnapshotV1DestructiveDelete a snapshot of a specified virtual machine. Use this endpoint to remove VPS snapshots.
-
VPS_recreateVirtualMachineV1DestructiveRecreate a virtual machine from scratch. The recreation process involves reinstalling the operating system and resetting the virtual machine to its initial state. Snapshots, if...
-
VPS_restoreBackupV1DestructiveRestore a backup for a specified virtual machine. The system will then initiate the restore process, which may take some time depending on the size of the backup. **All data o...
-
VPS_uninstallMonarxV1DestructiveUninstall the Monarx malware scanner on a specified virtual machine. If Monarx is not installed, the request will still be processed without any effect. Use this endpoint to r...
-
billing_setDefaultPaymentMethodV1FinancialSet the default payment method for your account. Use this endpoint to configure the primary payment method for future orders.
-
domains_purchaseNewDomainV1FinancialPurchase and register a new domain name. If registration fails, login to [hPanel](https://hpanel.hostinger.com/) and check domain registration status. If no payment method is ...
-
VPS_purchaseNewVirtualMachineV1FinancialPurchase and setup a new virtual machine. If virtual machine setup fails for any reason, login to [hPanel](https://hpanel.hostinger.com/) and complete the setup manually. If n...
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.