Use a separate database identity for each application and keep its credential out of public files and repositories.
Before you start
Use the access and features actually assigned to your account. Keep a rollback or recovery route before changing existing service settings.
Steps
- Record the application database and approved connection details without exposing its password.
- Create or request the least-privileged application user required by the software.
- Back up before schema changes or imports. Test a restore in a separate target.
- Run application acceptance after the change; a successful import is only one part of verification.
Verify the result
The application can perform its required operations and an unrelated account cannot access the database.
Help and related information
Contact support, service status, and Customer Access. Never send passwords or recovery codes.
Official cPanel documentation. Account features vary by hosting package.