
Websites on shared hosting are more vulnerable than you might think — dozens of sites share the same server, so if one account is compromised, the attack can spread. Imunify360 is a comprehensive security platform installed at the server level to address exactly this risk.
This article explains what Imunify360 is, how it works, what features it provides, and what hosting users should know about it.
For AsiaGB Hosting customers: Imunify360 is already installed at the server level. You do not need to install or configure anything. Scan results are accessible directly from your DirectAdmin Panel.
What is Imunify360?
Imunify360 is a Linux server security platform developed by CloudLinux Inc., designed specifically for web hosting servers running cPanel, DirectAdmin, or Plesk. It combines malware detection, a Web Application Firewall (WAF), brute force protection, and network-level threat intelligence into a single integrated suite.
Key Features of Imunify360
Malware Scanner
Continuously scans all website files in the background, detecting PHP shells, backdoors, webshells, and infected scripts.
Web Application Firewall
Blocks SQL injection, XSS, LFI/RFI, and other web application attacks using automatically updated rule sets.
Brute Force Protection
Automatically bans IPs that repeatedly fail login attempts to cPanel, DirectAdmin, FTP, SSH, and WordPress.
Network Firewall
Blocks network-level attacks using real-time IP reputation data from a continuously updated threat intelligence database.
Reputation Monitoring
Checks whether the server's IP has been blacklisted by Google Safe Browsing, Spamhaus, or other reputation services.
Proactive Defense
Monitors PHP script behavior and blocks scripts that attempt to send mass emails or connect to command-and-control servers.
How to View Imunify360 in DirectAdmin
As a hosting user on DirectAdmin, you can view scan results and manage threats:
- Log in to DirectAdmin.
- Go to Extra Features or click the Imunify360 link (location varies by DirectAdmin version).
- Under Files → Malicious, you can see any detected files.
- You can choose to Cleanup (remove malicious code) or Delete infected files.
If malware is found: Do not simply restore from a backup without verifying it is clean. Use Imunify360's Cleanup function first, then immediately change all passwords — DirectAdmin, FTP, and database passwords.
How Does Imunify360 Work?
Imunify360 operates in three protection layers:
Layer 1 — Real-time Prevention
The WAF intercepts HTTP requests before they reach PHP scripts. Requests that match SQL injection or XSS patterns are blocked immediately, before any server-side code executes.
Layer 2 — Background Malware Scanning
Imunify360 scans all files in the hosting account on a schedule, comparing them against a signature database of known malicious files. Detected files are quarantined immediately.
Layer 3 — Incident Response
When malware is detected, the system emails the admin and moves the malicious file out of the document root so it cannot execute. The file is preserved for admin review before permanent deletion.
Imunify360 Feature Comparison: What Each Layer Protects
Many users assume Imunify360 is simply an "antivirus scanner," but it is actually a multi-layer security suite where each component addresses a different attack vector. The table below summarizes the four main protection layers, what threats each one covers, and the practical benefit for your hosted website.
| Protection Layer | Threats Covered | Benefit to Your Site |
|---|---|---|
| Web Application Firewall (WAF) | SQL injection, XSS, LFI/RFI, malicious plugin exploit payloads | Blocks attacks before they reach PHP — no patch needed first |
| Malware Scanner | PHP shells, backdoors, webshells, JS files with hidden redirects or card skimmers | Detects infected files early — before Google blacklists your domain |
| Proactive Defense | PHP scripts trying to send spam, open outbound C&C connections, or execute dangerous code | Stops malware with no known signature while it is executing (runtime blocking) |
| Brute Force Protection | Password guessing on DirectAdmin, FTP, SSH, and WordPress login pages | Automatically bans repeat offenders — reduces credential theft risk |
| Reputation Management | Your IP or domain being listed on Spamhaus or Google Safe Browsing | Alerts you before emails bounce or browsers display "This site may be harmful" |
Because every layer operates at the server level, these protections apply to all websites in your hosting account simultaneously. You do not need to install a separate WordPress security plugin for each site you run.
How Imunify360 Works Behind the Scenes
Beyond the three-layer model visible in the DirectAdmin dashboard, Imunify360 uses several internal mechanisms that work continuously without user interaction. The most important is its connection to CloudLinux's Cloud Threat Intelligence network — a shared database that collects threat data from hundreds of thousands of servers worldwide. When a new attack pattern is observed on any participating server, CloudLinux analyzes it and pushes updated signatures and WAF rules to all servers in the network within minutes.
Key internal components include:
- ModSecurity-based WAF — intercepts HTTP requests at the web server level (Apache, Nginx, or LiteSpeed) and inspects payloads for attack patterns before forwarding requests to PHP.
- Real-time File System Watcher — monitors file changes in real time. Any new file written to the document root is scanned on-access immediately, without waiting for the next scheduled scan.
- PHP Immunity / Proactive Defense — runs as a PHP extension and monitors script behavior at runtime. If a script attempts something dangerous — such as executing code decoded from Base64 via
eval()— the action is blocked instantly. - Network Layer Firewall — manages IP reputation at the network level and blocks IPs that have previously attacked other servers in the CloudLinux network.
- Heuristic Engine — combines signature-based detection (known threats) with behavioral analysis (suspicious patterns) to catch malware variants that have been obfuscated to evade signature matching.
This defense-in-depth design means malware must bypass multiple independent layers. If the WAF does not catch a request, the file scanner may catch the resulting file. If the scanner lacks a signature for a novel variant, Proactive Defense can still block the script when it attempts to run. No single point of failure compromises all layers simultaneously.
Imunify360 vs. Manual Security: Server-Level vs. Plugin-Level
A common question is: "If I can install a WordPress security plugin myself, why is Imunify360 necessary?" The answer is that both approaches operate at different levels of the stack and complement each other. The comparison below shows the key differences.
| Dimension | Imunify360 (Server Level) | WP Security Plugin (Application Level) |
|---|---|---|
| Scope | Covers all sites in the account automatically | Must be installed and configured on each WordPress site separately |
| If PHP is bypassed | WAF still protects (sits in front of PHP) | Plugin is bypassed too (it runs inside PHP) |
| Signature updates | Automatic from the cloud at all times | Depends on the user remembering to update the plugin |
| User effort | Zero configuration — runs automatically | Requires installation, configuration, and ongoing maintenance |
Think of Imunify360 as the building's security system that the property owner (your hosting provider) installs for everyone, while WordPress security plugins are the lock on your own apartment door. You need both for complete protection.
Best practice combination: Let Imunify360 handle server-level threats automatically, while you focus on keeping your CMS, themes, and plugins updated, using strong unique passwords, and maintaining regular backups. These two layers working together provide far better coverage than either alone.
What to Do After Imunify360 Detects Malware
When the scanner flags a file, the recommended response follows a clear sequence. Acting on every step — not just the first — is important, because skipping steps leaves the same vulnerability open for reinfection.
- Use Cleanup or Quarantine in DirectAdmin — Let Imunify360 neutralize the threat first. Cleanup removes malicious code while preserving legitimate file content. Quarantine moves whole-file malware to an isolated area where it cannot execute.
- Change all passwords immediately — Reset DirectAdmin, FTP, and all database passwords. If WordPress was affected, change its admin password as well. Attackers often retain access through saved credentials even after the malware file is removed.
- Update everything — Upgrade WordPress core, all themes, and every plugin to their current versions. Most infections exploit known vulnerabilities in outdated software.
- Audit WordPress admin accounts — Check the Users section in WordPress for any administrator accounts you did not create. Attackers commonly add hidden admin accounts to maintain persistent access.
- Verify your backup is clean — If you restore from a backup, ensure the backup predates the infection. Restoring an infected backup re-introduces the malware.
Reinfection warning: If malware returns after cleanup, it means the entry point is still open. The most common causes are an unpatched plugin vulnerability, a compromised FTP password that has not been changed, or a backdoor in a theme file that was not caught in the initial scan. Contact your hosting support team if reinfection occurs repeatedly.
Does Imunify360 Provide 100% Protection?
No security system is 100% effective. Imunify360 significantly reduces the attack surface and detects known malware well, but gaps remain:
- Zero-day exploits — newly discovered malware without existing signatures may slip through.
- Password compromise — if FTP or panel credentials are stolen, an attacker can upload files directly.
- Outdated CMS — unpatched WordPress or plugin vulnerabilities may be exploited before Imunify360 detects them.
⚠️ Imunify360 is one layer, not a complete strategy. Keep WordPress, themes, and plugins updated. Use strong, unique passwords. Back up regularly. Imunify360 complements these practices; it does not replace them.
Summary: What Hosting Users Need to Know
- Imunify360 operates automatically at the server level — no setup needed.
- View scan results and manage threats from the DirectAdmin Panel.
- Act immediately if you receive a malware detection email — do not ignore it.
- Change all passwords after any confirmed breach.
- Imunify360 does not replace CMS updates, strong passwords, or regular backups.
Hosting with Imunify360 Security Built In
AsiaGB Hosting includes Imunify360 on every plan, plus DirectAdmin, SSD storage, and automatic backups. Starting at 500 THB/year.
View Hosting Plans