⚙
Hosting

Website security monitoring is one of the most important responsibilities when running a live site, yet accessing security reports shouldn't require advanced technical knowledge or special server permissions. cPGuard, a comprehensive security suite pre-installed on all AsiaGB hosting accounts, provides security monitoring and malware detection at the server level. The key advantage is that website owners can view their security status directly through their familiar DirectAdmin control panel without needing to contact hosting support or obtain root access to the server.

This article is a complete guide to understanding and using the cPGuard DirectAdmin Plugin — the user-facing interface that brings professional-grade security monitoring to individual website owners. We'll explore what information is available, how to access reports, what different scan statuses mean, and what actions to take when security issues are detected.

AsiaGB includes cPGuard on every hosting plan at no extra cost — website owners have immediate access to security reports through DirectAdmin from the moment their account is created, with no setup fees or additional purchases required.

Understanding cPGuard and Its Architecture

cPGuard is a multi-layered security system that operates at the server level and provides several integrated functions. It combines several key technologies: the Malware Scanner (detects compromised or suspicious files), the Web Application Firewall or WAF (blocks common web attacks before they reach your site), Domain Reputation monitoring (tracks whether your domain is listed on blacklists), and Brute Force Protection (monitors and blocks password guessing attempts).

The system works in two-tier architecture: the backend processes that run continuously on the server, and the user-facing interfaces that display results. Most website owners interact with cPGuard through the DirectAdmin Plugin, which is integrated directly into the control panel. Server administrators and hosting providers use the cPGuard App Portal, a separate admin-only interface that manages server-wide settings.

The DirectAdmin Plugin sits between these two worlds — it allows website owners to see results specific to their accounts without exposing server-wide controls or security settings. This separation of concerns is important from a security standpoint: your neighbor's domain can be compromised without affecting your own security monitoring and controls.

DirectAdmin Plugin vs App Portal — Understanding the Difference

The most common point of confusion is the relationship between the cPGuard DirectAdmin Plugin (what you see) and the cPGuard App Portal (what the server admin uses). These are two completely separate interfaces serving different purposes.

FeatureDirectAdmin Plugin (User)App Portal (Admin)
UsersIndividual website ownersServer admins
Data scopeOwn sites and domains onlyAll sites and all servers
View malware scan✓ Own sites only✓ All sites
View WAF log✓ Own domains✓ All domains
Request manual scan✓ Yes (own sites)✓ Yes (any site)
Manage WAF rules✗ No✓ Yes
Manage IP blacklist (IPDB)✗ No✓ Yes
Email security management✗ No✓ Yes
Firewall policies✗ No✓ Yes

The DirectAdmin Plugin provides read-only access to security reports and the ability to request scans. You cannot modify firewall rules, whitelist IPs, or change detection thresholds from the user interface — those administrative functions remain exclusively available to the hosting provider's staff through the App Portal. This is by design, as it prevents accidental security configuration changes by non-technical account owners.

What You Can See Through the DirectAdmin Plugin

Malware Scan Report

The malware scan report displays the results of cPGuard's file scanner applied to all files under your hosting account. It shows flagged files with their complete paths, the reason they were flagged, and the current status of each file.

The report includes the following information for each scan: the list of files that triggered a detection signature (these might be known malware, suspicious web shells, injected code, or other security risk patterns), the full server path to each flagged file, a brief description of what was detected and why, the current status of the file (which might be clean from a previous scan, quarantined, already cleaned, or awaiting cleanup), and the exact date and time of the most recent scan run.

You can click on individual results to see more detail, including which scanner signature matched, file size, and in some cases a snippet of the suspicious code if it's safe to display. If cPGuard's automatic cleanup ran, you'll see detailed information about what was removed or modified.

WAF Log (Web Application Firewall)

The WAF log shows HTTP requests that were blocked by the Web Application Firewall before they reached your website application. This log is crucial for understanding attack patterns and ensuring that legitimate traffic isn't being accidentally blocked.

Each log entry includes the source IP address and approximate geographic location of the request origin, the target URL path that was being attacked, the WAF rule ID that detected the threat, the attack category (SQL injection, cross-site scripting or XSS, path traversal, command injection, etc.), the payload or parameter that triggered the detection, request timestamp, and whether the request was blocked or flagged for logging.

The log can be filtered by date range (past 24 hours, past 7 days, past 30 days) and displayed as a timeline graph showing attack frequency or as individual request records. This helps you understand whether attacks are concentrated during certain hours or spread throughout the day.

Brute Force Report

The Brute Force Report lists IP addresses that have attempted repeated password guessing attacks against your account or the email accounts on your domain. cPGuard automatically detects patterns of repeated failed login attempts and takes protective action.

This report shows the attacking IP address and the country it originated from, the service that was targeted (FTP, SMTP email, DirectAdmin control panel itself, WordPress admin panel, etc.), the number of failed login attempts detected, the time period during which attacks occurred, and the current status (whether the IP has been temporarily or permanently banned).

Brute force protection is automatic — you don't need to manually block IPs. cPGuard uses intelligent thresholds: a few failed attempts might just be a user entering the wrong password, but dozens of attempts from the same IP within a short time period clearly indicates an automated attack and triggers protection mechanisms.

Understanding Scan Status Meanings

When cPGuard flags a file, the file goes through several possible states. Understanding what each status means helps you know what action, if any, is required from you.

Clean: File was scanned and no threats were found. This is the desired status for all files on your account. If a previously-flagged file now shows "Clean", it either means the file was manually corrected, the issue was automatically remediated by cPGuard, or it was a false positive that passed additional verification.

Quarantined: A threat was detected and cPGuard moved the file to a quarantine location where it cannot be executed. The website cannot access the quarantined file, so if it's a legitimate file that was incorrectly flagged, you'll likely notice your site stops working correctly. This status usually requires action — either to restore the file from backup (if it's legitimate) or to proceed with cleanup (if it's confirmed malware).

Cleaned: cPGuard detected a threat, removed the dangerous parts, and restored the file to a working state. For example, it might have detected injected code at the top of a PHP file, removed just the injected part, and left your legitimate code intact. This is the best-case scenario: the threat was neutralized automatically and your site continues working. No further action is usually needed, though you should still investigate how the injection happened to prevent future attacks.

Pending: cPGuard detected a threat and has not yet completed cleanup or quarantine action. This might be because cleanup is in progress, or the system is awaiting additional authorization before performing dangerous operations. A "pending" status usually resolves within 24-48 hours, but if it remains pending longer, you should contact support.

How to Request a Manual Scan

While cPGuard runs automatic scans on a regular schedule, you can request an immediate scan of your account at any time. This is useful if you suspect your site might be compromised or if you've just made significant changes and want to verify everything is clean.

  1. Log in to your DirectAdmin control panel using your username and password
  2. Look for the cPGuard Security menu option, typically found under Extra Features or in a Security section of the main menu
  3. Click on cPGuard Security to open the plugin interface
  4. You'll see a list of domains/subdomains associated with your account — select the one you want to scan
  5. Click the Scan Now button or Request Scan button (exact wording may vary by server version)
  6. Confirm the action if a confirmation dialog appears
  7. The scan will begin immediately — wait for results (typically 2-15 minutes depending on the size of your website and server load)

During the scan, your website remains fully operational. Malware scanning doesn't block user access or put your site offline. Once the scan completes, you'll see updated results displayed immediately in the DirectAdmin Plugin without needing to refresh the page.

Pro Tip: If you receive an automated email alert from cPGuard about detected malware, check the DirectAdmin Plugin report first before panicking. In the majority of cases, cPGuard has already cleaned the threat automatically. By checking the status, you can confirm the issue is resolved without unnecessary support tickets.

Signs You Should Request a Manual Scan Immediately

While the regular automatic scan schedule is usually sufficient, certain situations warrant requesting an immediate manual scan:

Responding to Scan Results

When cPGuard detects threats, the appropriate response depends on the nature and status of the threat detected.

If status is "Cleaned": The threat has been automatically remediated. Your site should be working normally. However, you should still investigate the root cause: how did the file get infected? Did you upload a compromised plugin? Are your passwords weak? Once the immediate threat is cleaned, address the underlying vulnerability to prevent re-infection.

If status is "Quarantined": The file is no longer accessible to your website. If this is a legitimate file you need (check with your application developer), you'll need to restore it from a backup and then investigate why it was flagged. If it's confirmed malware, you can safely delete it.

If status is "Pending": Automatic cleanup is in progress or waiting. Wait 24 hours before taking further action. If the status remains "Pending" after 48 hours, contact hosting support.

If you see a false positive: Occasionally cPGuard's signature database flags legitimate code. If you're absolutely certain a flagged file is legitimate (for example, a file that came with your open-source CMS), you can request a whitelist exception through support. Never ignore all alerts just because one was a false positive.

Integration with DirectAdmin User Management

The DirectAdmin Plugin respects DirectAdmin's user account model. If you have a multi-account DirectAdmin setup or you've assigned domain management to resellers, each user sees only the security reports for domains under their account. A domain owner account sees only their own domains. A reseller account sees only the domains they manage.

This means you don't need to worry about security reports from other accounts becoming visible to your users — DirectAdmin's access controls are enforced throughout the cPGuard integration.

How cPGuard Signatures Are Updated

cPGuard uses malware signature databases (patterns that match known threats) similar to antivirus software on your personal computer. These signatures are updated regularly by the security team behind cPGuard.

You don't need to manually update signatures — it's automatic. Your hosting account always uses the latest detection rules. If a new widespread malware threat emerges on the internet, the signature database is updated within hours or days, and all servers begin detecting the new threat automatically on the next scheduled scan.

Frequently Asked Questions

What is the cPGuard DirectAdmin Plugin?

The cPGuard DirectAdmin Plugin is an integrated security monitoring interface built directly into your DirectAdmin control panel. It allows website owners to view security scan results, WAF logs, and brute force attempts without needing special server admin access or to log into a separate system. It's a user-friendly way to monitor your site's security status.

What can I see through the DirectAdmin Plugin?

You can view malware scan results (which files were detected, current status, cleanup action), WAF log data (which attacks were blocked and when), brute force reports (which IPs tried to compromise your account), and domain reputation status (whether your domain is flagged on blacklists).

Can website owners request a manual scan?

Yes — through the DirectAdmin Plugin you can request a manual scan for your own domain without waiting for the next scheduled scan. This is useful if you suspect a compromise or want to verify something after making changes.

How is the App Portal different from the DirectAdmin Plugin?

The App Portal is the admin/server-wide interface used by hosting providers to manage cPGuard across the entire server, configure global WAF rules, manage IP whitelists/blacklists, and handle email security. The DirectAdmin Plugin is the user interface showing only one account's data and allowing only user-level actions like requesting scans.

If I find malware in the report, what should I do?

First, check the status of the detected file. If it shows "Cleaned," the threat has been automatically remediated — no action needed beyond investigating the root cause. If it shows "Pending," wait for automatic cleanup to complete. If it shows "Quarantined," contact support to have the file restored from backup (if legitimate) or deleted (if confirmed malware).

How often does cPGuard scan my website?

cPGuard runs automatic scans on a regular schedule — typically daily or every few days depending on server load and your account size. You can always request an immediate manual scan through the DirectAdmin Plugin without waiting for the next scheduled scan.

Best Practices for Website Security Monitoring

While cPGuard provides excellent automated protection, following best practices helps prevent security issues in the first place. Keep your applications updated (WordPress, plugins, themes, etc.). Use strong, unique passwords for all accounts. Enable two-factor authentication if your hosting provider offers it. Limit access to your site's backend — give people only the permissions they actually need.

Check your security reports regularly, even when nothing seems wrong. Monthly review of WAF logs helps you understand attack patterns targeting your site. Most importantly, don't ignore security alerts when you receive them. cPGuard's warnings are generated by real threat detection, not false alarms.

AsiaGB Hosting — cPGuard Security Ready Through DirectAdmin

AsiaGB includes cPGuard on every hosting plan at no additional cost. Website owners can view complete security reports directly through DirectAdmin immediately upon account activation. We host on SSD storage with 99% uptime from just 500 THB/year.

See Hosting Plans

View all cheap Thailand web hosting plans →