What is Imunify360? Malware Protection on Web Hosting Explained

Websites on shared hosting are more vulnerable than you might think — dozens of sites share the same server, so if one account is compromised, the attack can spread. Imunify360 is a comprehensive security platform installed at the server level to address exactly this risk.

This article explains what Imunify360 is, how it works, what features it provides, and what hosting users should know about it.

For AsiaGB Hosting customers: Imunify360 is already installed at the server level. You do not need to install or configure anything. Scan results are accessible directly from your DirectAdmin Panel.

What is Imunify360?

Imunify360 is a Linux server security platform developed by CloudLinux Inc., designed specifically for web hosting servers running cPanel, DirectAdmin, or Plesk. It combines malware detection, a Web Application Firewall (WAF), brute force protection, and network-level threat intelligence into a single integrated suite.

Key Features of Imunify360

🔍

Malware Scanner

Continuously scans all website files in the background, detecting PHP shells, backdoors, webshells, and infected scripts.

🧱

Web Application Firewall

Blocks SQL injection, XSS, LFI/RFI, and other web application attacks using automatically updated rule sets.

🔒

Brute Force Protection

Automatically bans IPs that repeatedly fail login attempts to cPanel, DirectAdmin, FTP, SSH, and WordPress.

🌐

Network Firewall

Blocks network-level attacks using real-time IP reputation data from a continuously updated threat intelligence database.

📊

Reputation Monitoring

Checks whether the server's IP has been blacklisted by Google Safe Browsing, Spamhaus, or other reputation services.

🔄

Proactive Defense

Monitors PHP script behavior and blocks scripts that attempt to send mass emails or connect to command-and-control servers.

How to View Imunify360 in DirectAdmin

As a hosting user on DirectAdmin, you can view scan results and manage threats:

  1. Log in to DirectAdmin.
  2. Go to Extra Features or click the Imunify360 link (location varies by DirectAdmin version).
  3. Under Files → Malicious, you can see any detected files.
  4. You can choose to Cleanup (remove malicious code) or Delete infected files.

If malware is found: Do not simply restore from a backup without verifying it is clean. Use Imunify360's Cleanup function first, then immediately change all passwords — DirectAdmin, FTP, and database passwords.

How Does Imunify360 Work?

Imunify360 operates in three protection layers:

Layer 1 — Real-time Prevention

The WAF intercepts HTTP requests before they reach PHP scripts. Requests that match SQL injection or XSS patterns are blocked immediately, before any server-side code executes.

Layer 2 — Background Malware Scanning

Imunify360 scans all files in the hosting account on a schedule, comparing them against a signature database of known malicious files. Detected files are quarantined immediately.

Layer 3 — Incident Response

When malware is detected, the system emails the admin and moves the malicious file out of the document root so it cannot execute. The file is preserved for admin review before permanent deletion.

Imunify360 Feature Comparison: What Each Layer Protects

Many users assume Imunify360 is simply an "antivirus scanner," but it is actually a multi-layer security suite where each component addresses a different attack vector. The table below summarizes the four main protection layers, what threats each one covers, and the practical benefit for your hosted website.

Protection Layer Threats Covered Benefit to Your Site
Web Application Firewall (WAF) SQL injection, XSS, LFI/RFI, malicious plugin exploit payloads Blocks attacks before they reach PHP — no patch needed first
Malware Scanner PHP shells, backdoors, webshells, JS files with hidden redirects or card skimmers Detects infected files early — before Google blacklists your domain
Proactive Defense PHP scripts trying to send spam, open outbound C&C connections, or execute dangerous code Stops malware with no known signature while it is executing (runtime blocking)
Brute Force Protection Password guessing on DirectAdmin, FTP, SSH, and WordPress login pages Automatically bans repeat offenders — reduces credential theft risk
Reputation Management Your IP or domain being listed on Spamhaus or Google Safe Browsing Alerts you before emails bounce or browsers display "This site may be harmful"

Because every layer operates at the server level, these protections apply to all websites in your hosting account simultaneously. You do not need to install a separate WordPress security plugin for each site you run.

How Imunify360 Works Behind the Scenes

Beyond the three-layer model visible in the DirectAdmin dashboard, Imunify360 uses several internal mechanisms that work continuously without user interaction. The most important is its connection to CloudLinux's Cloud Threat Intelligence network — a shared database that collects threat data from hundreds of thousands of servers worldwide. When a new attack pattern is observed on any participating server, CloudLinux analyzes it and pushes updated signatures and WAF rules to all servers in the network within minutes.

Key internal components include:

This defense-in-depth design means malware must bypass multiple independent layers. If the WAF does not catch a request, the file scanner may catch the resulting file. If the scanner lacks a signature for a novel variant, Proactive Defense can still block the script when it attempts to run. No single point of failure compromises all layers simultaneously.

Imunify360 vs. Manual Security: Server-Level vs. Plugin-Level

A common question is: "If I can install a WordPress security plugin myself, why is Imunify360 necessary?" The answer is that both approaches operate at different levels of the stack and complement each other. The comparison below shows the key differences.

Dimension Imunify360 (Server Level) WP Security Plugin (Application Level)
Scope Covers all sites in the account automatically Must be installed and configured on each WordPress site separately
If PHP is bypassed WAF still protects (sits in front of PHP) Plugin is bypassed too (it runs inside PHP)
Signature updates Automatic from the cloud at all times Depends on the user remembering to update the plugin
User effort Zero configuration — runs automatically Requires installation, configuration, and ongoing maintenance

Think of Imunify360 as the building's security system that the property owner (your hosting provider) installs for everyone, while WordPress security plugins are the lock on your own apartment door. You need both for complete protection.

Best practice combination: Let Imunify360 handle server-level threats automatically, while you focus on keeping your CMS, themes, and plugins updated, using strong unique passwords, and maintaining regular backups. These two layers working together provide far better coverage than either alone.

What to Do After Imunify360 Detects Malware

When the scanner flags a file, the recommended response follows a clear sequence. Acting on every step — not just the first — is important, because skipping steps leaves the same vulnerability open for reinfection.

  1. Use Cleanup or Quarantine in DirectAdmin — Let Imunify360 neutralize the threat first. Cleanup removes malicious code while preserving legitimate file content. Quarantine moves whole-file malware to an isolated area where it cannot execute.
  2. Change all passwords immediately — Reset DirectAdmin, FTP, and all database passwords. If WordPress was affected, change its admin password as well. Attackers often retain access through saved credentials even after the malware file is removed.
  3. Update everything — Upgrade WordPress core, all themes, and every plugin to their current versions. Most infections exploit known vulnerabilities in outdated software.
  4. Audit WordPress admin accounts — Check the Users section in WordPress for any administrator accounts you did not create. Attackers commonly add hidden admin accounts to maintain persistent access.
  5. Verify your backup is clean — If you restore from a backup, ensure the backup predates the infection. Restoring an infected backup re-introduces the malware.

Reinfection warning: If malware returns after cleanup, it means the entry point is still open. The most common causes are an unpatched plugin vulnerability, a compromised FTP password that has not been changed, or a backdoor in a theme file that was not caught in the initial scan. Contact your hosting support team if reinfection occurs repeatedly.

Does Imunify360 Provide 100% Protection?

No security system is 100% effective. Imunify360 significantly reduces the attack surface and detects known malware well, but gaps remain:

⚠️ Imunify360 is one layer, not a complete strategy. Keep WordPress, themes, and plugins updated. Use strong, unique passwords. Back up regularly. Imunify360 complements these practices; it does not replace them.

Summary: What Hosting Users Need to Know

Hosting with Imunify360 Security Built In

AsiaGB Hosting includes Imunify360 on every plan, plus DirectAdmin, SSD storage, and automatic backups. Starting at 500 THB/year.

View Hosting Plans