In relation to blocking malware etc, I would look for a host with something like CageFS that scans everything that is uploaded to the server and instantly rejects it if there is any malware or viruses detected.
Aslong as you have the disable_functions on your IPB community then you should not have any issues with SQL attacks. I have been using IPB for around 4 years and never experienced a SQL attack even on nulled and cracking forums.