All articles

VPS vs Shared Hosting: Which One Does Your Application Need?

The real differences between shared hosting and a VPS: resources, access, what you can run, who handles security and backups, signs you have outgrown shared hosting, a basic VPS hardening checklist, and how to migrate without downtime.

Cloud Infrastructure|Published |9 min read
A Linux terminal showing a sudo command

Shared hosting is where most company websites start: cheap, easy, with a control panel and email included. It works well for a company profile or a small WordPress site. Problems begin when the website turns into an application with logins, transactions, background jobs, and integrations. Pages slow down at busy hours, the host suspends the account for using too many resources, or the stack you need simply cannot be installed. A VPS removes those limits, but it also hands you responsibilities that the hosting company used to carry.

The Main Differences

AspectShared hostingVPS
ResourcesCPU, RAM, and disk shared with hundreds of other sites, with per-account limitsA fixed allocation of vCPU, RAM, and disk reserved for you
AccessA control panel such as cPanel, FTP, and sometimes limited SSHFull root access to the operating system
What you can runMostly PHP and MySQL, with the versions and extensions the host providesAnything that runs on Linux: Node.js, Go, Python, Docker, Redis, queue workers, WebSockets
Maintenance and securityHandled by the hosting companyYour responsibility on an unmanaged VPS, or the provider's on a managed VPS
NeighboursA busy or compromised site on the same server can slow yours or affect the shared IP reputationIsolated from other customers at the virtual machine level
Typical fitCompany profiles, blogs, small WordPress sites, email for a small teamBusiness applications, APIs, online stores with real traffic, and custom stacks

When Shared Hosting Is Enough

Shared hosting is a sensible choice when the site is mostly content, traffic is modest, and nobody on the team wants to manage a server. A company profile, a landing page, or a blog with a few thousand visitors a month runs comfortably on a good shared plan. The host handles updates to the server, the control panel makes domains, SSL, and email simple, and the cost is low. Moving such a site to a VPS adds work without a visible benefit.

Signs You Have Outgrown Shared Hosting

  • Errors such as "508 Resource Limit Is Reached" or the site going down at busy hours, because the account hits its CPU, memory, or process limits.
  • You need queue workers, scheduled jobs that run longer than the host allows, or WebSockets for real-time features.
  • The application needs a PHP version or extension the host does not offer, or a different runtime such as Node.js or Go.
  • You want Redis for caching and sessions, or Docker to keep environments consistent.
  • Response time is unpredictable even though your own traffic has not changed, which often points to a busy neighbour.
  • Client contracts or regulations require control over where data is stored, who has access, and how it is backed up.

Managed or Unmanaged VPS

An unmanaged VPS gives you a clean server and nothing else. Installing the web server, applying security patches, setting up the firewall, configuring backups, and fixing problems at night are all your job. A managed VPS, or a VPS looked after by an operations partner, costs more per month but includes that work. If your team does not include someone comfortable with Linux administration, the managed option is usually cheaper once you count the hours and the risk of a misconfigured server.

A Basic Checklist for a New VPS

  1. 1Create a normal user with sudo, log in with SSH keys only, and disable password and direct root login.
  2. 2Turn on a firewall that only allows SSH, HTTP, and HTTPS, and keep the database port closed to the internet.
  3. 3Enable automatic security updates, and install fail2ban or a similar tool to block repeated login attempts.
  4. 4Set up HTTPS with Let's Encrypt and make sure certificates renew automatically.
  5. 5Schedule daily backups of the database and uploaded files to storage outside the server, and test a restore at least once.
  6. 6Add monitoring for uptime, disk space, memory, and CPU, with alerts sent to someone who will act on them.

Most VPS break-ins we see come from skipped basics: password login left open, an old CMS plugin, or a database exposed to the internet. None of these need advanced tools to fix, only discipline in the first hour of setting up the server.

Keep Email Separate

On shared hosting, email usually comes bundled. On a VPS, running your own mail server is possible but rarely worth the effort, because a new server IP has no sending reputation and messages often land in spam. Keep company mailboxes on a dedicated email service, and send application email such as password resets and invoices through a transactional email provider, with SPF, DKIM, and DMARC records set up for your domain.

Choosing the Size

Start with what the application actually needs and grow from there. A typical Laravel, Django, or WordPress application with a database on the same server often starts comfortably on 2 vCPU and 4 GB of RAM. Watch memory, CPU, and response time for a few weeks of real traffic, then resize. Most cloud providers let you move to a larger plan in minutes. Choose a data centre close to your users. For an audience in Indonesia, a Jakarta or Singapore location keeps latency low, and a Jakarta location also helps when data needs to stay in the country.

Moving from Shared Hosting to a VPS Without Downtime

  1. 1List everything the current hosting provides: domains, subdomains, databases, cron jobs, email accounts, and SSL certificates.
  2. 2Lower the DNS TTL to a few minutes a day before the move, so the switch spreads quickly.
  3. 3Set up and harden the VPS, then copy the application files and import a fresh database dump.
  4. 4Test the site on the new server by pointing your own computer to the new IP through the hosts file.
  5. 5Put the old site in maintenance mode briefly, copy the latest database changes, and switch the DNS records.
  6. 6Keep the old hosting account for a week or two as a fallback, then cancel it once everything is confirmed.

Other Options Worth Knowing

A VPS is not the only step up. Managed application platforms let you deploy code without managing a server at all, at a higher price per resource. Managed databases remove the hardest part of running a VPS: backups, updates, and failover for the data. For larger systems, several servers behind a load balancer, or containers on a managed service, bring more reliability than one bigger VPS. The right choice depends on traffic, the team's skills, and how costly downtime is for the business.

Before deciding, write down how long the business can tolerate the application being down and how much data it can afford to lose. Those two numbers usually settle the choice faster than comparing hosting plans.

Key takeaways

  • Shared hosting fits content websites with modest traffic and no one available to manage a server.
  • Move to a VPS when you hit resource limits, need queue workers or other runtimes, or need control over data and access.
  • An unmanaged VPS makes security, updates, backups, and monitoring your job, so budget for that work or choose a managed option.
  • Harden a new VPS in the first hour: SSH keys, firewall, automatic updates, HTTPS, off-server backups, and monitoring.
  • Migrate with a lowered DNS TTL, a test through the hosts file, and the old hosting kept as a fallback.

Related articles

More articles on software development, AI, cloud, and infrastructure.

A desktop screen showing landing page designs next to a tablet and a phone
Web Development|

How to Build a Company Profile Website That Brings in Leads

What a company profile website needs to bring in enquiries: clear service pages, proof such as case studies and client logos, easy contact options, fast loading on mobile, SEO basics, the right platform, and tracking that shows which pages produce leads.

A customer paying with a phone at a shop counter
Software Development|

Integrating a Payment Gateway Like Midtrans or Xendit Safely

How to integrate an Indonesian payment gateway such as Midtrans or Xendit: choosing payment methods, hosted checkout versus direct API, verifying webhooks, handling duplicate notifications, order status design, expiry, refunds, testing in sandbox, and daily reconciliation.

Looking for a software development partner?

Tell us about your project, what you need to build, and the challenges you are facing. We can discuss the technical approach, scope, timeline, and estimated cost.

Start a conversation