Malware scanning

Real-time malware scanning on every site we host

Every site runs under Imunify360: real-time malware scanning, a proactive WAF that blocks exploits before a patch exists, a network firewall, brute-force protection and IP reputation filtering. Scanning, the WAF and kernel-level isolation are included on every plan — because an infected site is a threat to its neighbours, not just to its owner. When something does get through, one-click cleanup and staff-run hack repair are there to buy.

  • 100,000+PBN sites hosted across every niche
  • Real-timemalware scanning, on every plan
  • Includedscanning, proactive WAF and isolation
  • 30 daysdaily backup retention, one-click restore

What runs on every site, from the first deploy

Imunify360 is installed on every worker in the fleet as one integrated security layer. It is not a plugin you remember to install, and not a scan you have to schedule — it is part of the platform your site is deployed onto.

Real-time malware scanning

Files are scanned continuously rather than on a nightly cron, so a compromise is flagged when it lands instead of hours later. Scanning is included on every plan, on every product line.

Proactive WAF

The proactive firewall blocks known exploit techniques before a patch for the underlying vulnerability is even available — the gap that catches out sites running an unpatched plugin or theme.

Network firewall and brute-force protection

A network-level firewall, brute-force protection on login endpoints and IP reputation filtering sit in front of the site, cutting off the credential-stuffing and probing traffic that precedes most WordPress compromises.

One-click cleanup

When an infection is confirmed, remediation is a single action rather than a manual file-by-file hunt. Cleanup is sold as an add-on — per incident or as a subscription — while the scanning that finds the infection is always included.

Detection is layered, because malware rarely announces itself

A scanner on its own misses the compromises that only show up in behaviour. We correlate several independent signals so a hacked site is caught by whichever one fires first.

  • Malware and phishing kits are caught by the real-time Imunify360 scan and proactive defence, then cross-checked against Google Safe Browsing, PhishTank and SURBL/APWG blocklists.
  • Outbound mail is watched for the signature of a compromised site: volume spikes, high bounce rates, RBL and spam-trap hits, and feedback-loop complaints, with per-site outbound rate limits enforced.
  • A spam signal plus a malware signal together is treated as high-confidence compromise — which is how a hacked site gets actioned in minutes rather than after a blocklisting.
  • Crypto-miners and other resource abuse surface through CloudLinux LVE, which logs CPU and IO faults per site and throttles automatically.
  • Every signal — scan hits, mail anomalies, LVE faults, inbound abuse reports to our abuse mailbox — lands in one Abuse Desk, aggregated, deduplicated and prioritised.

Containment first, so an infection stays one site's problem

Detection matters less than what happens in the minutes after. Each site sits inside its own kernel-level cage, so a compromise is boxed in while it is dealt with.

CageFS filesystem isolation

Each tenant gets an isolated filesystem view and cannot see other tenants, other sites, or sensitive system files. CloudLinux describes this as containing breaches — the blast radius of a compromise is held inside the cage rather than spreading across the server.

LVE resource caps

CPU, RAM, IO, IOPS, processes and entry-processes are capped per site. A miner, a mail flood or an attacked site is throttled inside its own cage instead of starving its neighbours.

Evidence preserved before cleanup

Quarantine locks files and stops execution while preserving the site as it was found, so forensics and any later dispute have something real to work from.

Immutable backups as the fallback

Per-site backups are immutable, offsite and air-gapped, with restores that are tested rather than assumed. Footprint-Free plans hold daily backups for 30 days with one-click restore.

What happens when a site is flagged

Enforcement is graduated, reversible and reason-tracked — a documented state machine, not a blunt on/off switch. Every transition is logged with its reason and evidence, notified to you with how to resolve it, and appealable.

Malware detected → restricted

The site stays visible but is degraded — outbound mail off, cron off, POST blocked — and cleanup is offered. Restricted status lifts automatically once the site is remediated.

Severe or unresolved → quarantined

The site goes offline with files locked and no execution, isolated for forensics. Quarantine is reversed after cleanup and review — there is no automatic release on the next scan.

Phishing confirmed → quarantined immediately

Confirmed phishing carries legal risk for everyone on the platform, so it skips the graduated path and is quarantined straight away.

Outbound spam → throttle, then restrict

Outbound mail is throttled first, then disabled under restricted status, and only escalates to suspension if the sending continues. A suspended site serves a branded, reason-specific holding page rather than a broken one.

Included, upsold, and repaired

We draw the line where the fleet's safety draws it. Anything that protects your neighbours is included; anything that is work done on your site specifically is priced.

  • Included on every plan: real-time malware scanning, the proactive WAF, and LVE plus CageFS isolation.
  • Sold as add-ons: one-click malware cleanup and remediation, per incident or as a subscription.
  • Also sold as add-ons: advanced protection tiers — enhanced WAF rules, priority scanning, bot management and DDoS tiers, and dedicated firewall rules.
  • Hack repair is a first-party Extra, bought from the dashboard alongside DB maintenance, speed optimisation and managed migration. Extras are staff-fulfilled or automated; either way you are charged, the work is fulfilled, and you are notified when it is complete.
  • Cleanup is offered contextually — on a site the platform has already flagged — so you are not hunting for the right service while a site is compromised.

Built for networks, not just single sites

Most of our customers do not run one site. Scanning and enforcement are designed for operators managing hundreds of them, on the same infrastructure that hosts 100,000+ PBN sites across every niche.

Because scanning runs on every worker rather than inside each site, adding sites does not add scanners to configure or licences to buy. A network of five sites and a network of two thousand get the same real-time coverage, the same proactive WAF and the same isolation model.

Enforcement policies are configurable per product line and per trigger, because a billing issue, an abuse signal and a legal takedown do not deserve the same escalation timing. Whichever path a site takes, the transition is logged, the reason is stated, and you are told how to resolve it.

Footprint-Free plans carry free SSL, unlimited bandwidth and disk, daily backups held for 30 days, free migrations and a 30-day no-quibble money-back guarantee — the security baseline is part of that, not a line item on top of it.

FAQ

Is malware scanning included, or do I pay extra for it?

Real-time scanning is included on every plan, along with the proactive WAF and LVE/CageFS isolation. We include them because an infected site threatens its neighbours, the server's reputation and our IP ranges — so protection cannot be optional. What is priced separately is the remediation: one-click malware cleanup, per incident or as a subscription, plus advanced tiers such as enhanced WAF rules, priority scanning, bot management and dedicated firewall rules.

If a site on the same server is hacked, is mine safe?

It is contained rather than shared. Each site runs in its own CloudLinux LVE resource cage and its own CageFS filesystem view, so a compromised tenant cannot see your files, your database credentials or sensitive system files, and cannot drain the resources your site needs. Confirmed malware or phishing is taken offline and isolated for forensics on top of that. No host can promise a hosting neighbour will never matter at all, but the isolation model is specifically designed so a breach stops at the cage wall.

What happens the moment my site is flagged as infected?

The default policy moves the site to restricted: it stays visible, but outbound mail, cron and POST requests are turned off so the compromise cannot do further harm, and cleanup is offered. You are notified with the reason and the evidence, and the state lifts once the site is remediated. Severe or unresolved cases escalate to quarantine — offline, files locked, no execution — which is reversed after cleanup and review rather than automatically on a re-scan.

Can you clean an already-hacked site for me?

Yes. One-click malware cleanup handles remediation directly, and staff-run hack repair is available as a first-party Extra bought from the dashboard, routed to the right department with status updates as it progresses. If a clean restore is the better route, per-site backups are immutable, offsite and air-gapped, with tested restores — Footprint-Free plans keep daily backups for 30 days with one-click restore.

Will scanning slow my site down?

Scanning runs at the host level rather than inside your PHP requests, and per-site resource limits are enforced by LVE with database load throttled by MySQL Governor, so security work is not competing with your visitors for the site's own allocation. We do not publish benchmark figures for the scanner's overhead, so we will not claim a number we cannot show you.

What is a proactive WAF, and how is it different from a normal firewall?

A signature-based firewall reacts to attacks it has already seen. Imunify360's proactive WAF blocks known exploit techniques before a patch exists for the underlying vulnerability, which is what protects a site running a plugin with an unfixed flaw. It sits alongside the network firewall, brute-force protection and IP reputation filtering, all included on every plan.

Protection that is on before you deploy

Real-time scanning, the proactive WAF and kernel-level isolation are running the moment your first site goes live. Try Footprint-Free Hosting on a card-free 7-day trial with up to 5 sites — no payment details, and a 30-day no-quibble money-back guarantee behind every plan.

Start free