Get a free website with any plan

See how
HOSTING

Hiding your site while you build it

Last updated

IN SHORT

To hide an in-progress site on Flashcloud, use cPanel Directory Privacy to password-protect your site folder. Combine this with a noindex tag or WordPress maintenance mode. Directory Privacy gives you the strongest lock by requiring an HTTP login at the server level before your site application loads.

To keep a site private while you build it, don't rely on secrecy alone. Use cPanel → Directory Privacy to password-protect the folder, put a noindex tag on the pages so search engines skip them, and if it's WordPress, turn on maintenance mode so visitors see a holding page instead of a half-built layout. Combine at least two of these. A URL nobody links to still gets found eventually.

Password-protect the folder

The most reliable way to block visitors outright is directory-level password protection. In cPanel, open Directory Privacy (Files section) and select the folder your site lives in, usually public_html or an addon domain's subfolder if you're building a second site on the same account (see addon domains, aliases, and subdomains). Enable protection, set a name for the protected area, then create a username and password. Anyone hitting the site gets an HTTP authentication prompt before they see anything.

This works for any site type, static HTML or a full CMS, because it happens at the web server level before your application even loads. The tradeoff: anyone testing the site (a client, a teammate) needs those credentials too, and some browser-based tools or embeds that can't handle HTTP auth will fail against the protected URL.

Keep search engines out

Password protection stops visitors, but you also don't want a half-finished site getting crawled and indexed. Add this to every page's <head> while you build:

<meta name="robots" content="noindex, nofollow">

If you're running WordPress, there's a simpler switch: Settings → Reading → Discourage search engines from indexing this site. It writes the same directive site-wide. Remember to turn it off before launch, it takes a while to reappear in search results.

You can also block crawling entirely with a robots.txt disallow rule, but that's a request, not an enforcement mechanism. Well-behaved crawlers respect it; it does nothing to stop a human with the link. Use it alongside the meta tag and password protection, not instead of them.

WordPress: maintenance mode instead of a broken layout

If your domain already has live traffic (an existing site you're redesigning), taking it fully offline with a password prompt breaks the experience for current visitors. Maintenance mode is the middle ground: it shows a "we'll be right back" page to everyone except logged-in admins, while you work behind the scenes.

Most page builders and popular plugins (SeedProd, WP Maintenance Mode, and similar) add this with a toggle and a simple holding page you can brand. If you'd rather not add a plugin, WordPress core has a built-in maintenance mode that only needs a file:

<?php
$upgrading = time();
?>

Save that as .maintenance in your site's root folder (via File Manager or FTP) and WordPress shows its default maintenance page to logged-out visitors until you delete the file. It's blunt but reliable, and it doesn't touch your theme or plugins.

Building on a subdomain instead

Another common approach: build the new version on a staging.yourdomain.com subdomain while the live site stays untouched at the root domain. Set one up from your service's Subdomains tile, pointed at its own folder. Combine it with directory privacy and a noindex tag on the subdomain specifically, since subdomains are indexed independently from the main domain. When the rebuild is ready, you migrate the content over rather than flipping a switch on the same URL. More detail on how subdomains, aliases, and addon domains differ is in addon domains, aliases, and subdomains.

What this doesn't protect against

None of the above hides the fact that a domain exists, or that a server is answering on it. DNS lookups, certificate transparency logs, and old cached copies can all surface a "hidden" site's existence even when the content itself is locked down.

When to contact support

If Directory Privacy isn't prompting for a password after you've set it up, or a .maintenance file isn't taking effect, open a ticket from Support → New ticket in the portal. It's worth including the exact folder path and domain so the team can check the server-side config directly rather than guessing at what's misconfigured.

Common questions

Can I put WordPress into maintenance mode without installing a plugin?

Yes. Save a file named .maintenance in your root directory via File Manager or FTP. WordPress will show a default maintenance page to logged-out visitors until you delete the file.

Does a robots.txt file stop people from viewing my pages?

No, robots.txt does not block human visitors. It is only a crawler request that search bots choose to follow. Use directory password protection to actually block access.

Is my site completely invisible if I use password protection?

No. While page content is locked, DNS records, certificate transparency logs, and old cached copies can still show that your domain and server exist.

What should I do if my password protection is not working?

Open a ticket under Support, then New ticket in the portal. Provide your exact domain and folder path so the team can verify your server configuration.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.