//Server Security

Imunify360 Explained: Features, Pricing and Setup Guide (2026)

What Imunify360 actually protects against, how its pricing compares with the free ImunifyAV tier, and a practical setup checklist for a live server.

3 min read
Imunify360 Explained: Features, Pricing and Setup Guide (2026)

Imunify360 has become close to a default choice for securing cPanel and Plesk servers, combining a web application firewall, malware scanning, and intrusion prevention into one product instead of stitching together ModSecurity, ClamAV and fail2ban by hand. This guide explains what it does, what it costs, and how to set it up correctly the first time.

What Imunify360 actually includes

Rather than a single feature, Imunify360 is a bundle of security layers that work together:

  • Web Application Firewall (WAF): filters malicious requests before they reach PHP, based on rules tuned to common CMS platforms like WordPress and Joomla.
  • Malware scanning and cleanup: scans hosted files for known malware signatures and can automatically quarantine or clean infected files.
  • Proactive Defense: watches PHP scripts in real time and blocks suspicious behaviour even from malware that has no known signature yet.
  • Intrusion prevention (fail2ban replacement): blocks IP addresses showing brute-force or scanning behaviour, with a shared reputation database across all Imunify360 servers.
  • KernelCare integration: optional add-on for patching the kernel without rebooting, sold separately in most plans.

Pricing and licensing in 2026

Imunify360 licences are sold per server and scale with the number of hosted domains or cPanel accounts, similar to CloudLinux's model since both come from the same company. There is no meaningfully useful free tier for production servers; a lighter option called ImunifyAV exists but only covers malware scanning, without the firewall or Proactive Defense.

FeatureImunifyAV (free/basic)Imunify360 (paid)
Malware scanningYesYes
Web Application FirewallNoYes
Proactive Defense (real-time)NoYes
Intrusion / brute-force protectionNoYes
Automatic malware cleanupLimitedYes

Setting up Imunify360 the right way

The default configuration is usable, but a few adjustments make it noticeably better on a live server:

  1. Start the WAF in detection mode for the first few days on a new install, so you can review what it would have blocked before switching to full blocking, avoiding false positives on unusual but legitimate site behaviour.
  2. Whitelist your own office or VPN IP in the firewall so administrative logins are never accidentally rate-limited during testing.
  3. Schedule full malware scans during low-traffic hours, since a full filesystem scan on a large server is I/O-intensive.
  4. Review the Proactive Defense log weekly at first, since some legitimate plugins (particularly page builders and caching plugins) occasionally trigger false alerts that need a one-time exception.

Imunify360 vs. building your own stack

Before Imunify360 existed, most admins combined ModSecurity with the OWASP Core Rule Set, ClamAV for scanning, and fail2ban for brute-force blocking. That combination is still free and viable, but it takes real ongoing maintenance: updating rule sets, tuning ModSecurity to avoid false positives, and keeping scan schedules from overlapping with backups. Imunify360's main value is not doing anything impossible to replicate — it is doing all of it in one interface, pre-tuned, with a shared threat-intelligence feed across every server running it.

Frequently asked questions

Does Imunify360 replace ModSecurity?

Yes, its Web Application Firewall is a replacement for a manually configured ModSecurity + OWASP CRS setup, and the two should not typically be run together on the same rules.

Will Imunify360 slow down my server?

There is a measurable but generally small CPU overhead from real-time scanning and the WAF; on an already resource-constrained server, scheduling full scans for off-peak hours keeps the impact minimal.

Does Imunify360 work outside cPanel?

Yes, it also supports Plesk and DirectAdmin, and there is a standalone installation path for servers without a control panel.

Conclusion

For any server hosting client websites, Imunify360 replaces several free tools with one maintained, pre-tuned product, and the malware cleanup and shared threat intelligence alone justify it for most hosting businesses. Run the WAF in detection mode first, whitelist your own access, and give the scan schedule some thought before switching everything to full blocking mode.

imunify360imunify360 pricingcpanel securityweb application firewallmalware scanningproactive defenseserver security

Try it on your own server

Follow along on a Cloud VPS with full root access, or read the step-by-step knowledge base guides.