Real-time malware scanning
Files are scanned continuously rather than on a nightly cron, so a compromise is flagged when it lands instead of hours later. Scanning is included on every plan, on every product line.
Malware scanning
Every site runs under Imunify360: real-time malware scanning, a proactive WAF that blocks exploits before a patch exists, a network firewall, brute-force protection and IP reputation filtering. Scanning, the WAF and kernel-level isolation are included on every plan — because an infected site is a threat to its neighbours, not just to its owner. When something does get through, one-click cleanup and staff-run hack repair are there to buy.
Imunify360 is installed on every worker in the fleet as one integrated security layer. It is not a plugin you remember to install, and not a scan you have to schedule — it is part of the platform your site is deployed onto.
Files are scanned continuously rather than on a nightly cron, so a compromise is flagged when it lands instead of hours later. Scanning is included on every plan, on every product line.
The proactive firewall blocks known exploit techniques before a patch for the underlying vulnerability is even available — the gap that catches out sites running an unpatched plugin or theme.
A network-level firewall, brute-force protection on login endpoints and IP reputation filtering sit in front of the site, cutting off the credential-stuffing and probing traffic that precedes most WordPress compromises.
When an infection is confirmed, remediation is a single action rather than a manual file-by-file hunt. Cleanup is sold as an add-on — per incident or as a subscription — while the scanning that finds the infection is always included.
A scanner on its own misses the compromises that only show up in behaviour. We correlate several independent signals so a hacked site is caught by whichever one fires first.
Detection matters less than what happens in the minutes after. Each site sits inside its own kernel-level cage, so a compromise is boxed in while it is dealt with.
Each tenant gets an isolated filesystem view and cannot see other tenants, other sites, or sensitive system files. CloudLinux describes this as containing breaches — the blast radius of a compromise is held inside the cage rather than spreading across the server.
CPU, RAM, IO, IOPS, processes and entry-processes are capped per site. A miner, a mail flood or an attacked site is throttled inside its own cage instead of starving its neighbours.
Quarantine locks files and stops execution while preserving the site as it was found, so forensics and any later dispute have something real to work from.
Per-site backups are immutable, offsite and air-gapped, with restores that are tested rather than assumed. Footprint-Free plans hold daily backups for 30 days with one-click restore.
Enforcement is graduated, reversible and reason-tracked — a documented state machine, not a blunt on/off switch. Every transition is logged with its reason and evidence, notified to you with how to resolve it, and appealable.
The site stays visible but is degraded — outbound mail off, cron off, POST blocked — and cleanup is offered. Restricted status lifts automatically once the site is remediated.
The site goes offline with files locked and no execution, isolated for forensics. Quarantine is reversed after cleanup and review — there is no automatic release on the next scan.
Confirmed phishing carries legal risk for everyone on the platform, so it skips the graduated path and is quarantined straight away.
Outbound mail is throttled first, then disabled under restricted status, and only escalates to suspension if the sending continues. A suspended site serves a branded, reason-specific holding page rather than a broken one.
We draw the line where the fleet's safety draws it. Anything that protects your neighbours is included; anything that is work done on your site specifically is priced.
Most of our customers do not run one site. Scanning and enforcement are designed for operators managing hundreds of them, on the same infrastructure that hosts 100,000+ PBN sites across every niche.
Because scanning runs on every worker rather than inside each site, adding sites does not add scanners to configure or licences to buy. A network of five sites and a network of two thousand get the same real-time coverage, the same proactive WAF and the same isolation model.
Enforcement policies are configurable per product line and per trigger, because a billing issue, an abuse signal and a legal takedown do not deserve the same escalation timing. Whichever path a site takes, the transition is logged, the reason is stated, and you are told how to resolve it.
Footprint-Free plans carry free SSL, unlimited bandwidth and disk, daily backups held for 30 days, free migrations and a 30-day no-quibble money-back guarantee — the security baseline is part of that, not a line item on top of it.
Real-time scanning is included on every plan, along with the proactive WAF and LVE/CageFS isolation. We include them because an infected site threatens its neighbours, the server's reputation and our IP ranges — so protection cannot be optional. What is priced separately is the remediation: one-click malware cleanup, per incident or as a subscription, plus advanced tiers such as enhanced WAF rules, priority scanning, bot management and dedicated firewall rules.
It is contained rather than shared. Each site runs in its own CloudLinux LVE resource cage and its own CageFS filesystem view, so a compromised tenant cannot see your files, your database credentials or sensitive system files, and cannot drain the resources your site needs. Confirmed malware or phishing is taken offline and isolated for forensics on top of that. No host can promise a hosting neighbour will never matter at all, but the isolation model is specifically designed so a breach stops at the cage wall.
The default policy moves the site to restricted: it stays visible, but outbound mail, cron and POST requests are turned off so the compromise cannot do further harm, and cleanup is offered. You are notified with the reason and the evidence, and the state lifts once the site is remediated. Severe or unresolved cases escalate to quarantine — offline, files locked, no execution — which is reversed after cleanup and review rather than automatically on a re-scan.
Yes. One-click malware cleanup handles remediation directly, and staff-run hack repair is available as a first-party Extra bought from the dashboard, routed to the right department with status updates as it progresses. If a clean restore is the better route, per-site backups are immutable, offsite and air-gapped, with tested restores — Footprint-Free plans keep daily backups for 30 days with one-click restore.
Scanning runs at the host level rather than inside your PHP requests, and per-site resource limits are enforced by LVE with database load throttled by MySQL Governor, so security work is not competing with your visitors for the site's own allocation. We do not publish benchmark figures for the scanner's overhead, so we will not claim a number we cannot show you.
A signature-based firewall reacts to attacks it has already seen. Imunify360's proactive WAF blocks known exploit techniques before a patch exists for the underlying vulnerability, which is what protects a site running a plugin with an unfixed flaw. It sits alongside the network firewall, brute-force protection and IP reputation filtering, all included on every plan.
Real-time scanning, the proactive WAF and kernel-level isolation are running the moment your first site goes live. Try Footprint-Free Hosting on a card-free 7-day trial with up to 5 sites — no payment details, and a 30-day no-quibble money-back guarantee behind every plan.
Start free