How to Use cPGuard Security in DirectAdmin

Website security is not optional — compromised hosting accounts can be used to send spam, host phishing pages, or attack other servers, resulting in your site being blacklisted or your hosting account suspended. cPGuard is a comprehensive security suite available in DirectAdmin that actively scans your hosting files for malware, detects PHP web shells, blocks brute force login attempts, and generates security reports. This guide shows you how to use it effectively.

What Is cPGuard?

cPGuard is a commercial security plugin for web hosting control panels including DirectAdmin. It integrates directly into your hosting account and provides multiple layers of protection for your website files and login systems. Unlike traditional antivirus software that runs on a desktop, cPGuard runs on the server side — scanning all files in your hosting account for malicious code, unauthorized scripts, and known malware signatures.

cPGuard is developed by OwlH and is widely deployed across hosting providers as a proactive security layer, complementing existing firewall and intrusion detection systems.

Key Features of cPGuard

cPGuard provides several core security capabilities:

Enabling cPGuard in DirectAdmin

To access cPGuard, log in to DirectAdmin and navigate to the Extra Features section. Click on cPGuard. The cPGuard dashboard will open showing your current security status, recent scan results, and any active threats detected. If this is your first time opening cPGuard, you may need to accept the terms and enable the service for your account.

How to Run a Malware Scan

To manually initiate a malware scan of your hosting files:

  1. Open the cPGuard dashboard from DirectAdmin.
  2. Navigate to the Malware Scanner section.
  3. Click Start Scan to begin scanning all files in your account.
  4. The scan will run in the background. Depending on how many files you have, it may take a few minutes to complete.
  5. Once the scan finishes, a results summary will show the number of clean files and any infected files detected.
cPGuard Security page in DirectAdmin
cPGuard Security page in DirectAdmin

Reading Security Reports

The cPGuard Reports section shows a history of all scans, detected threats, and blocked brute force attempts. Each report entry includes:

Handling Detected Malware

When cPGuard detects a malicious file, you have several options:

After handling detected malware, always change your CMS admin password and FTP password, and update all plugins and themes to eliminate the vulnerability that allowed the infection.

Managing Quarantined Files

When cPGuard moves a file to quarantine, the file is isolated in a secure directory where it cannot be executed by the web server. This prevents the malicious code from doing further damage while you decide how to handle it. You have three options for each quarantined file:

After cleaning up detected malware, take these follow-up steps to close the security gap that allowed the infection in the first place:

Setting Up Auto-Scan and Email Alerts

Relying on manual scans means you only find malware when you remember to look. Configuring cPGuard to scan automatically on a schedule and send email alerts ensures you are notified as soon as a threat is detected, even if you have not logged into DirectAdmin for days.

To configure scheduled scanning:

  1. Open the cPGuard dashboard from DirectAdmin Extra Features.
  2. Navigate to the Settings or Scheduled Scan section.
  3. Set the scan frequency. Weekly is sufficient for most websites. Choose Daily if your site allows user-uploaded content, runs an online store with frequent uploads, or has a history of being targeted.
  4. Select the scan scope — in most cases, scan your entire public_html directory including all subdirectories.
  5. Enter the notification email address where you want alert reports sent.
  6. Save the settings.

cPGuard will send an email report after each scheduled scan summarising the number of files scanned, threats detected, and actions taken. If no threats are found, you may receive a clean report or no email at all depending on your notification settings. Either way, the scan has run in the background keeping your files monitored.

Security Best Practice: Run a malware scan at least once every week, especially after installing new plugins, themes, or third-party scripts. Many infections occur through vulnerable plugins, and catching them early prevents your domain from being blacklisted by Google or your hosting account from being suspended.

Best Practices for Getting the Most Out of cPGuard

Enabling cPGuard is just the first step. Configuring it thoughtfully and maintaining it over time is what makes the difference between surface-level protection and genuinely secure hosting. The following practices help you get the most effective results while avoiding false positives and alert fatigue.

Choose the Right Scan Schedule

The scan frequency you choose should reflect how often files change in your hosting account. For most websites that only update content occasionally, a weekly scan provides a good balance between security coverage and server resource use. For sites that accept user-generated content — such as community forums, marketplaces, or any site where customers can upload files directly — you should configure a daily scan, since the risk of a malicious file being uploaded is substantially higher. Schedule scans during off-peak hours, typically between 1am and 4am local time, to minimise any performance impact on your live site.

Set Alert Thresholds Appropriately

cPGuard can notify you when it detects threats at various severity levels. If you set the alert threshold too low, you will receive frequent notifications for minor issues and false positives — and you may start ignoring alerts altogether, which defeats the purpose. If you set it too high, cPGuard may detect genuine medium-severity threats without notifying you. A practical starting point is to alert on medium severity and above for general websites, and lower it to include low-severity findings if your site handles sensitive data or has previously been compromised.

Manage File Exclusions Carefully

The Whitelist or File Exclusions feature tells cPGuard to skip specific files or directories during scans. Use it sparingly and only when you have verified that the flagged file is genuinely a false positive. Common legitimate candidates for whitelisting include heavily minified third-party JavaScript files or custom PHP scripts that use patterns that superficially resemble obfuscation techniques. Avoid whitelisting entire directories such as wp-content/uploads, as that would leave all newly uploaded files completely unscanned. Always whitelist specific files by full path, and review your exclusion list every few months to remove entries that are no longer needed.

Keep Malware Signatures Up to Date

cPGuard's detection capability depends on the quality and freshness of its signature database. An outdated database will miss newly discovered malware strains. In most configurations, cPGuard updates its signatures automatically in the background. However, if you notice that the signature database version shown in the dashboard has not changed for several weeks, contact AsiaGB Support to verify that updates are running correctly on your server. Keeping signatures current is especially important after major security incidents in the WordPress plugin ecosystem, which can introduce new malware variants rapidly.

Alongside these cPGuard-specific practices, maintain good general security habits in parallel: update WordPress core, plugins, and themes whenever new versions are released; use strong, unique passwords for both WordPress admin and DirectAdmin; and run scheduled backups at least weekly. cPGuard is an excellent detection layer, but layered security — detection combined with prevention and recovery planning — gives your hosting account the most robust protection available.

Hosting with cPGuard Security Included

AsiaGB hosting includes cPGuard security on all plans — proactive malware protection and brute force blocking built right in.

View Hosting Plans