High-risk tools in Hostinger
38 of the 284 tools in Hostinger are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
agency_deploy_node_staticExecuteDeploy a node-static Agency Plan website from an archive. Uploads archive, triggers build, deploys to public_html. Operation is synchronous — site is live when tool returns.
-
agency_deploy_phpExecuteDeploy a PHP application to an Agency Plan website from an archive. Extracts and serves as-is (no build step). Operation is synchronous.
-
agency_website_build_assetsExecuteBuild Node.js assets for an Agency Plan website.
-
batch_vps_restartExecuteRestart multiple VPS instances at once.
-
hosting_cache_clearExecuteClear cache for a hosted website.
-
hosting_db_repairExecuteRepair a corrupted database.
-
hosting_deploy_js_appExecuteDeploy a JavaScript application from an archive. The archive must contain source files only (no node_modules, no build output). Build runs automatically on server. Use hosting_d...
-
hosting_deploy_staticExecuteDeploy a static website from an archive (HTML/CSS/JS/images). Archive must contain pre-built files ready to serve. No build process. For JS apps with build step, use hosting_dep...
-
hosting_deploy_wp_importExecuteImport a WordPress website from an archive and database dump. Files are extracted and site deployed automatically.
-
hosting_deploy_wp_pluginExecuteDeploy a custom WordPress plugin from a directory/archive. Uploads plugin files and triggers deployment.
-
hosting_deploy_wp_themeExecuteDeploy a custom WordPress theme from a directory/archive. Uploads theme files and optionally activates.
-
hosting_nodejs_build_from_archiveExecuteCreate a Node.js build from an uploaded archive.
-
hosting_nodejs_patch_vulnerabilitiesExecuteAuto-patch known Node.js vulnerabilities.
-
hosting_nodejs_restartExecuteRestart a Node.js application.
-
hosting_php_update_extensionsExecuteEnable/disable PHP extensions.
-
mail_webhooks_testExecuteSend a test event to a webhook.
-
vps_docker_restartExecuteRestart a Docker project.
-
vps_docker_startExecuteStart a Docker project.
-
vps_docker_stopExecuteStop a Docker project.
-
vps_docker_updateExecuteUpdate a Docker project (re-deploy).
-
vps_firewall_activateExecuteActivate a firewall on a VPS.
-
vps_firewall_deactivateExecuteDeactivate a firewall from a VPS.
-
vps_firewall_syncExecuteSync firewall rules to a VPS.
-
vps_malware_installExecuteInstall Monarx malware scanner on a VPS.
-
vps_recovery_startExecuteBoot VPS into recovery mode.
-
vps_recovery_stopExecuteExit recovery mode and reboot normally.
-
vps_restartExecuteRestart a virtual machine.
-
vps_set_root_passwordExecuteSet root password for a virtual machine.
-
vps_setupExecuteSetup a purchased virtual machine with OS and credentials.
-
vps_startExecuteStart a virtual machine.
-
vps_stopExecuteStop a virtual machine.
-
wp_installExecuteInstall WordPress on a hosting account.
-
wp_litespeed_purgeExecutePurge the LiteSpeed Cache.
-
wp_maintenance_toggleExecuteToggle maintenance mode on/off.
-
wp_memcached_toggleExecuteToggle Memcached object cache on/off.
-
wp_plugins_activateExecuteActivate a WordPress plugin.
-
wp_plugins_installExecuteInstall plugins by slug.
-
wp_update_coreExecuteUpdate WordPress core to latest version.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.