WAFPlanet
Imunify360 server security platform logo

Imunify360

by CloudLinux Inc.

3.8
WAFPlanet Rating

A multi-layered server security platform by CloudLinux that bundles a managed ModSecurity WAF, proactive PHP defense, malware scanning, and network firewall into a single automated package for Linux hosting servers.

Company: CloudLinux Inc.
Pricing: Per-server subscription, tiered by number of hosting accounts
Founded: 2017

Overview

Imunify360 is a comprehensive security platform for Linux web servers, built by CloudLinux. Rather than being a standalone WAF, it integrates six layers of protection: a network firewall backed by global threat intelligence, WebShield for bot detection and DDoS mitigation, a ModSecurity-based WAF with proprietary managed rules, real-time malware scanning, a proactive PHP defense engine, and intrusion detection/prevention.

The WAF component uses ModSecurity under the hood but with Imunify's own curated ruleset, maintained and updated by their security team. This means hosting providers and site owners get WAF protection without needing to manage ModSecurity rules themselves. The WAF provides virtual patching for known vulnerabilities in WordPress plugins, themes, and other popular CMS software, blocking exploit attempts before official patches are available.

What sets Imunify360 apart from standalone WAFs is the Proactive Defense engine. It analyzes PHP script behavior at runtime, catching zero-day attacks that signature-based detection would miss. Combined with automated malware cleanup and compromised password resets, it handles the full lifecycle from prevention through remediation.

Imunify360 integrates with cPanel, Plesk, and DirectAdmin, and also runs standalone on Linux servers. A WordPress plugin provides site-level visibility into security status. The platform feeds a global threat intelligence network spanning 57 million+ domains, where an attack blocked on one server protects all others in the network.

Ratings Breakdown

Ease of Use 4.2/5
Value for Money 4.0/5
Customer Support 4.0/5
Features 4.2/5

Key Features

Managed WAF Rules

ModSecurity-based WAF with proprietary rules maintained by Imunify's security team. Automatically updated to cover new WordPress plugin vulnerabilities, CMS exploits, and emerging attack patterns.

Proactive Defense

Real-time PHP script behavior analysis that detects and blocks malicious activity during execution. Catches zero-day attacks that signature-based WAFs miss entirely.

Virtual Patching

Blocks exploit attempts against known vulnerabilities in WordPress plugins, themes, and CMS software before official patches are released or applied.

WebShield

Reverse proxy layer that filters bot traffic and mitigates DDoS attacks using invisible JavaScript challenges instead of traditional CAPTCHAs.

Automated Malware Cleanup

Detects and removes malicious code from files automatically, preserving the original file integrity. Includes database scanning for CMS infections.

Global Threat Intelligence

Feeds from 57M+ protected domains. An attack blocked on one server instantly protects all other Imunify-protected servers worldwide.

WordPress Plugin

Dedicated WordPress plugin providing site-level security dashboard, scan results, proactive defense status, and malware details directly in wp-admin.

Compromised Password Reset

Automatically forces password resets when it detects that cPanel or WordPress credentials were used in an attack, breaking reinfection cycles.

Pros & Cons

Pros

  • Fully managed WAF rules

    No rule writing or tuning needed. Imunify's security team handles WAF rule updates based on current threat intelligence.

  • Goes beyond WAF

    Six integrated security layers mean you get firewall, WAF, malware scanning, PHP runtime defense, and IDS/IPS in one package.

  • WordPress-aware protection

    Virtual patching for WordPress plugin vulnerabilities, WordPress-specific malware scanning, and a dedicated WordPress admin plugin.

  • Low operational overhead

    Automated malware cleanup, password resets, and rule updates reduce support tickets and manual security work significantly.

  • Affordable for hosting providers

    At $12-45/mo per server regardless of traffic volume, it is significantly cheaper than per-request cloud WAFs for high-traffic servers.

Cons

  • Linux-only

    No Windows, no macOS. Requires a Linux server with a supported distribution and optionally a control panel (cPanel, Plesk, DirectAdmin).

  • Not a standalone WAF

    You cannot buy just the WAF component. You get the full security suite or nothing. Overkill if you only need request filtering.

  • Hosting ecosystem lock-in

    Designed for shared hosting environments. Not suited for Kubernetes, serverless, or cloud-native architectures.

  • No cloud proxy mode

    Does not sit in front of your server like Cloudflare or Sucuri. Traffic must reach your server before Imunify can inspect it.

  • Closed source

    Proprietary software with no visibility into rule logic or detection internals. You trust their team to get it right.

Pricing

Pricing model: Per-server subscription, tiered by number of hosting accounts

Single User

$12/mo

Full security suite for a server with 1 hosting account

  • All 6 security layers
  • Managed WAF rules
  • Proactive Defense
  • Automated malware cleanup
  • 24/7 support

Up to 30 Users

$20/mo

For shared hosting servers with up to 30 accounts

  • All Single User features
  • Multi-account support
  • CloudAV for reduced CPU usage
  • WordPress plugin

Up to 250 Users

$35/mo

For larger shared hosting environments

  • All features included
  • Scales to 250 hosting accounts
  • Fleet management CLI

Unlimited

$45/mo

Unlimited hosting accounts per server

  • All features included
  • Unlimited accounts
  • Priority support
  • Centralized monitoring dashboard

Our Verdict

Imunify360 is not a traditional WAF. It is a full server security platform that happens to include a very capable managed WAF. For hosting providers running cPanel or Plesk on Linux, it is one of the most practical security investments available. The WAF rules are maintained for you, the proactive PHP defense catches zero-days, and the automated malware cleanup reduces support tickets. The trade-off is that you are locked into the Linux hosting ecosystem and cannot use it as a standalone WAF for non-PHP workloads or cloud-native architectures.

CVE Coverage

Imunify360 can detect and block attacks matching 82K+ known CVEs based on its supported rule sets.

13K+
Critical
17K+
High
33K+
Medium
420
Low

Coverage by Attack Type

14K+ CVEs
8.4K+ CVEs
6.6K+ CVEs
5.2K+ CVEs
3.9K+ CVEs
3.9K+ CVEs
3.1K+ CVEs
Open Redirect Medium
1.4K+ CVEs
1.2K+ CVEs

Latest Blockable CVEs

CVE Severity
CVE-2026-2072 UNKNOWN
CVE-2026-1166 UNKNOWN
CVE-2026-4784 HIGH
CVE-2026-4766 MEDIUM
CVE-2026-4783 MEDIUM
CVE-2026-4781 MEDIUM
CVE-2026-4780 MEDIUM
CVE-2026-4779 MEDIUM
CVE-2026-4778 MEDIUM
CVE-2026-4777 MEDIUM

Frequently Asked Questions

Is Imunify360 a WAF?
Imunify360 includes a WAF as one of six security layers. The WAF component uses ModSecurity with Imunify's own managed ruleset. You cannot purchase the WAF separately from the full security suite.
Does Imunify360 work with WordPress?
Yes. It provides WordPress-specific virtual patching, malware scanning, and a dedicated WordPress plugin that shows security status in the wp-admin dashboard. It protects against WordPress plugin and theme vulnerabilities automatically.
How does Imunify360 compare to Wordfence?
Wordfence is a WordPress plugin that runs inside WordPress. Imunify360 is a server-level platform that protects all sites on the server, not just WordPress. Imunify360 includes additional layers like network firewall, PHP runtime defense, and automated malware cleanup that Wordfence does not offer.
Can I use Imunify360 with Cloudflare?
Yes. Imunify360 supports CDN passthrough configurations and works alongside Cloudflare. The two complement each other, with Cloudflare handling edge caching and DDoS at the network level while Imunify360 provides server-level application security.

Ready to try Imunify360?

Visit the website to learn more or request a demo.