CloudLinux and EasyApache 4 are the two layers that decide how safe and how fast a cPanel server is: CloudLinux isolates accounts and limits their resources, and EasyApache 4 controls Apache and PHP. This guide is a hardening and tuning checklist for administrators of their own cPanel & WHM server, with root access and their own licences. If you have a shared hosting account, section 2 explains what is already done for you.
Everything from section 3 onwards needs root and WHM access. It does not apply to Domain India shared hosting, where we manage the server, and Domain India VPS plans don't include cPanel. For EasyApache 4 profiles and PHP handlers in depth, see EasyApache 4 in cPanel with CloudLinux.
On your own cPanel server: keep cPanel, the OS and EasyApache packages updated; keep every account inside CageFS with LVE limits set per package; run Apache with the event MPM, PHP-FPM and OPcache; protect logins with cPHulk and two-factor authentication; add ModSecurity with a maintained ruleset; and back up off the server. ConfigServer stopped developing CSF in 2025, so on a new server use firewalld or a maintained security suite instead.
1. Who this guide is for
| You have | Can you do this? | What to use instead |
|---|---|---|
| Domain India shared cPanel hosting | No, these are root tasks | cPanel's MultiPHP Manager, MultiPHP INI Editor and a support ticket |
| Your own cPanel & WHM server | Yes, as root | This guide |
| A Domain India VPS | cPanel isn't offered on VPS | Your own licence on a VPS you manage, or one of the panels offered at checkout |
2. On Domain India shared hosting: already done
Our shared cPanel servers run CloudLinux 8 with CageFS, so every account has its own resource limits and a private view of the file system. Imunify360 runs server-wide with a web application firewall and ModSecurity, and it removes known malicious code from infected files automatically. A server firewall is in place, and JetBackup 5 takes weekly account backups (measured on our servers, September 2026).
What you control is your own site: the PHP version in MultiPHP Manager (our cPanel servers offer PHP 5.1 to 8.5, with 8.3 for new accounts), PHP settings in the MultiPHP INI Editor, and .htaccess rules. If you hit your limits, see check your hosting resource usage.
3. Keep everything updated
Unpatched software is the most common way into a server.
- cPanel updates.In WHM, Server Configuration › Update Preferences, choose a release tier and leave automatic daily updates on.
/usr/local/cpanel/scripts/upcpruns an update by hand. - OS updates.On AlmaLinux, Rocky Linux or CloudLinux 8 and 9, run
dnf upgrade. EasyApache 4 packages (ea-apache24-,ea-php) update with the rest of the system; don't exclude them from updates. - Kernel.A new kernel needs a reboot. If KernelCare is licensed, it patches the running kernel live; check with
kcarectl --info. - Save a profile before big changes.Export the current EasyApache setup with
/usr/local/bin/ea_current_to_profile --output=/root/ea4-before.json, so you can reinstall it if a change goes wrong.
4. Isolate accounts with CloudLinux
cagefsctl --display-user-mode, and run cagefsctl --force-update after installing software users need.lveinfo.Set limits per package, not per user, so new accounts get sensible limits automatically. A limit that is too low shows up as 508 "Resource Limit Is Reached" pages; the CloudLinux and cPanel troubleshooting guide covers LVE and CageFS faults.
5. Tune Apache and PHP
- Event MPM with PHP-FPM. In Software › EasyApache 4, use the event MPM and enable PHP-FPM per domain in MultiPHP Manager. Each site's PHP then runs as its own user, with its own pool. Prefork is only for old setups that run PHP inside Apache.
- OPcache. Install the OPcache extension for every PHP version and leave
opcache.enable=1. Sizeopcache.memory_consumptionto fit your sites' code; see the PHP OPcache guide. - HTTP/2. Add
mod_http2in EasyApache 4. It needs the event or worker MPM, and browsers use it only over HTTPS. - A caching proxy. cPanel's NGINX reverse proxy (
ea-nginx) can sit in front of Apache to serve and cache static files while.htaccesskeeps working. - KeepAlive. Keep it on with a short timeout of a few seconds, in Service Configuration › Apache Configuration › Global Configuration.
6. Protect logins and web applications
- Brute-force protection.Turn on cPHulk in Security Center › cPHulk Brute Force Protection, and whitelist your own IP address so you don't lock yourself out.
- Two-factor authentication.Enable it for WHM and cPanel under Security Center › Two-Factor Authentication, and require it for root and resellers.
- ModSecurity.Install
ea-apache24-mod_security2through EasyApache 4, then add a maintained ruleset such as the OWASP Core Rule Set from Security Center › ModSecurity Vendors. Watch the audit log for false positives in the first week. - TLS.Enable AutoSSL for free certificates, and allow only TLS 1.2 and 1.3 in the Apache SSL settings.
- SSH.Use key-only login and disable root password login; see the SSH hardening checklist.
ConfigServer stopped developing CSF in 2025, so it gets no further security fixes. On a new cPanel server, use firewalld, which cPanel supports, together with cPHulk, or a maintained commercial security suite. If an existing server still runs CSF, plan the move rather than tuning it further.
7. Old PHP versions and hardened PHP
Some applications still need PHP 7 or even 5. CloudLinux publishes its own alt-php builds of old versions with security patches, selectable per account in the CloudLinux PHP Selector (enable them in CloudLinux Manager, then run cagefsctl --force-update). Treat these as a bridge, not a home: make PHP 8.3 or later the server default, enable old versions only for the accounts that need them, and give those customers a date to upgrade. The PHP Selector and MultiPHP can conflict; pick one approach, as explained in the EasyApache 4 guide.
8. Backups and monitoring
- Backups off the server. Configure Backup › Backup Configuration in WHM, or a backup product you license, and send copies to remote storage. A backup that lives only on the same disk dies with it.
- Test restores. Restore one account to a test server every few months.
- Watch the logs. Apache errors are in
/etc/apache2/logs/error_logand cPanel's in/usr/local/cpanel/logs/error_log. Check ModSecurity's audit log and LVE fault counts when sites slow down. - Alerts. Set a contact address in Server Contacts › Contact Manager so WHM can warn you about disk space, failed services and licence problems.
9. Domain India: let us run the server
If you'd rather not manage CloudLinux, EasyApache, licences and patches, our shared cPanel hosting already runs this stack for you, with CageFS, Imunify360 and weekly JetBackup backups. You choose your PHP version; we look after the server. Prices on the card are live and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If you need root access, a Domain India VPS is self-managed. cPanel isn't offered on our VPS plans; you can install it yourself with your own licence, as described in installing cPanel on a VPS.
Can I use EasyApache 4 or CloudLinux Manager on Domain India shared hosting?
No. Both are root-level WHM tools. On Domain India shared cPanel hosting, set your PHP version in MultiPHP Manager and PHP settings in the MultiPHP INI Editor, and open a ticket if you need a server module.
What security does Domain India shared cPanel hosting already have?
CloudLinux with CageFS isolation and per-account resource limits, Imunify360 with a web application firewall and ModSecurity running server-wide, automatic removal of known malicious code from infected files, a server firewall and weekly JetBackup backups.
Should I still install CSF on a new cPanel server?
No. ConfigServer stopped developing CSF in 2025, so it receives no further fixes. Use firewalld, which cPanel supports, together with cPHulk brute-force protection, or a maintained commercial security suite.
Which Apache MPM should I use on a cPanel server?
The event MPM with PHP-FPM. It handles many connections efficiently and is required for HTTP/2. Prefork is only needed for old setups that run PHP inside Apache.
Is it safe to offer old PHP versions?
Only as a short-term bridge. CloudLinux's patched alt-php builds reduce the risk, but applications on old PHP should be upgraded. Make PHP 8.3 or later the default and enable older versions only for accounts that need them.
Does a Domain India VPS come with cPanel?
No. Domain India VPS plans are self-managed and cPanel is not offered on them. You can install cPanel with a licence you buy elsewhere, or choose shared cPanel hosting where the server is managed for you.
Ready to decide who runs the server? Compare cPanel shared hosting with a self-managed VPS, or open a ticket if your shared account needs a PHP extension or module.
Shared cPanel hosting on CloudLinux with CageFS, Imunify360 and weekly backups, managed for you.
See cPanel hosting plans