Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025 Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
SaaS AI Tools Cloudways

Cloudways expands AI agent access with 244 hosting tools

New permission tiers limit scope but security risks persist in MCP servers

Cloudways expands AI agent access with 244 hosting tools
Brett Sayles · Pexels

Cloud hosting provider Cloudways has significantly expanded the capabilities of its AI agent integration, allowing automated systems to perform nearly all hosting account functions without manual intervention. The change reflects a broader industry shift toward delegating infrastructure management to AI-driven tools, though security researchers warn the approach carries substantial risks if not properly constrained.

What changed

Cloudways released version 1.2.112 of its Model Context Protocol (MCP) server this week, nearly doubling the number of available tools to 244. The MCP server acts as an intermediary between AI agents—such as Claude, Cursor, or Windsurf—and hosting accounts, enabling direct execution of tasks like service restarts, code deployments, security scans, and billing operations. Previously, these actions required manual input through the Cloudways dashboard.

The update introduces three permission tiers for API tokens: read-only for monitoring, limited scope for specific tasks, and full access for comprehensive control. This replaces the previous single-key system, which granted blanket permissions. Cloudways stated the change was intended to reduce the risk of overprivileged access, though the company did not specify when the new version was deployed.

Security concerns

The expansion of AI agent access comes amid growing scrutiny of MCP server vulnerabilities. Security firm BlueRock recently scanned over 10,000 public MCP servers and found that 9.2% contained critical flaws, while 43% were susceptible to command injection attacks. Such vulnerabilities could allow external actors to execute arbitrary commands on the server, potentially compromising broader infrastructure.

In one documented case, BlueRock researchers exploited a separate flaw in Microsoft’s MarkItDown MCP server to extract AWS access keys from a cloud instance’s metadata. Depending on the permissions associated with those keys, the breach could have provided access to the entire AWS account. While Cloudways’ new permission tiers may mitigate some risks, the underlying architecture remains exposed to similar attack vectors if not properly secured.

Background

Background: Model Context Protocol (MCP) servers enable AI agents to interact with software systems by translating natural language instructions into executable commands. These tools are increasingly used in hosting and cloud environments to automate routine tasks, though their adoption has outpaced standardized security practices.

Industry context

Cloudways is not the first provider to implement AI-driven hosting management. Its parent company, DigitalOcean, introduced its own MCP server in August 2025, and community-developed versions exist for other control panels, including cPanel. The cPanel integration currently exposes 164 tools, demonstrating the rapid proliferation of this technology across the hosting ecosystem.

The primary concern for operators is not the number of tools available but the potential for unintended consequences when AI agents are granted broad access. A single compromised agent could become a single point of failure for multiple client sites, particularly for agencies managing numerous accounts. The shift toward scoped permissions reflects an industry-wide effort to balance automation with security, though the effectiveness of these measures remains unproven at scale.

What to watch

Hosting providers and agencies adopting AI agent integrations should prioritize the following:

  • Token scoping: Ensure API tokens are restricted to the minimum required permissions for each task.
  • Server hardening: MCP servers should be treated as high-risk components, with regular vulnerability scans and access controls.
  • Audit trails: Maintain detailed logs of AI agent actions to detect and investigate unauthorized activity.

The long-term impact of AI-driven hosting management will depend on whether security practices evolve as quickly as the technology itself. For now, operators must weigh the convenience of automation against the risks of exposing critical infrastructure to new attack surfaces.

Companies mentioned

Cloudways BlueRock DigitalOcean Microsoft

Discussion · coming soon

Be the first to join the thread when community discussion launches.