Security (Imunify360, ModSecurity)

Supporting Software & Tools for Securing Shared Hosting Servers

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

A shared hosting server runs hundreds of websites side by side, so its security has to work in layers: keep accounts apart, filter bad traffic, find malware, and keep copies to restore from. This article explains which tools protect your site on Domain India shared hosting, what each one does for you, and which tools to choose if you run your own VPS.

Key takeaways

Domain India cPanel and DirectAdmin shared hosting runs on CloudLinux with CageFS, which keeps every account in its own sandbox. Imunify360 provides a web application firewall, malware scanning with automatic cleanup and PHP attack blocking; a CSF firewall blocks repeated failed logins; AutoSSL or Let's Encrypt provides free certificates; and JetBackup 5 takes weekly backups you can restore yourself. All of it is server-wide, so every plan gets the same protection. On your own VPS, you choose and manage the tools yourself.

1. The layers of shared-server security

Isolation
Each account runs in its own sandbox, so a hacked site can't read or change its neighbours' files.
Traffic filtering
A web application firewall and a network firewall stop attacks before they reach your site.
Malware defence
Scanners find and clean infected files; PHP-level protection blocks malicious scripts as they run.
Recovery
Backups let you roll back when something gets through anyway.

No single tool covers all four. The rest of this article follows these layers.

2. Isolation: CloudLinux and CageFS

Our cPanel and DirectAdmin shared servers run CloudLinux. Two parts of it matter to you:

  • CageFS gives each account a private view of the file system. Your scripts see your own files and a safe set of system tools, not other customers' home folders or the server's configuration.
  • LVE limits give each account its own share of CPU, memory and processes. A busy or compromised neighbour can't use up the whole server. When your own site reaches its limit you may see a 508 error; see understanding the resource limit is reached error.

PHP on shared hosting also has a set of risky functions disabled, such as those that run shell commands. This stops many attacks that rely on uploading a script and executing system commands. The list and the alternatives are in PHP disabled functions on shared hosting.

3. Traffic filtering: Imunify360 WAF and the CSF firewall

Imunify360 runs on our cPanel and DirectAdmin shared servers. Its web application firewall (WAF) inspects each web request and blocks known attack patterns such as SQL injection, cross-site scripting and password-guessing against WordPress and other CMS logins. On cPanel it runs the full ruleset with application-specific rules. It also protects against floods of requests.

CSF (ConfigServer Security & Firewall) is the network firewall on the same servers. It allows only the ports the services need and temporarily blocks an IP address after repeated failed logins to cPanel, email, FTP or SSH.

Both are configured for the whole server. A Starter account and a Business account on the same server get exactly the same protection, and you don't need to install or switch anything on.

Blocked, or a legitimate request refused?

If a single page or form gives a 403 error, a WAF rule may have caught a legitimate request. If your whole connection to the server stops working, your IP was probably blocked after failed logins, often from an old password saved in a mail app. For the first, see the Imunify360 WAF guide; for the second, see have I been blocked?. In both cases a ticket with your IP address and the time sorts it out.

4. Malware defence: scanning and automatic cleanup

Imunify360 also scans the files on the server. On our cPanel server, measured in September 2026, it checks new and changed files as they are written; when it finds malicious code in a file, it removes the malicious code automatically and keeps the original copy for 14 days; and its Proactive Defense feature watches PHP scripts as they run and stops known malicious behaviour.

Two points to keep in mind:

  • Automatic cleanup is a feature of the software. It is not a hand-cleaning service, and it can't fix everything: a stolen password, a malicious admin user in WordPress, or an outdated plugin with a known hole all need your attention.
  • The scanner is run by the server. If you think your site is compromised, follow the security checklist for a hacked or defaced website and open a ticket.

5. Encryption and recovery: free SSL and JetBackup

  • SSL. Every hosting plan includes free SSL. On cPanel, AutoSSL issues and renews Let's Encrypt certificates automatically; DirectAdmin does the same with Let's Encrypt. See how to enable free SSL.
  • Backups. JetBackup 5 runs on our cPanel and DirectAdmin servers. It takes weekly account backups (on Sunday, keeping 5 copies), and you can download them or restore files, databases, email and more yourself from JetBackup in your panel. See backup and restore with JetBackup. Keep your own copy as well, especially before big changes.
  • Login security. On the cPanel and DirectAdmin servers, SSH accepts key logins only, no passwords. Jailed SSH is available on every shared plan on request; it is off by default.

6. What you still have to do yourself

Server tools protect the platform. Most hacked sites, though, are broken into through the application: an old plugin, a weak password, or a nulled theme. Your part:

  1. Keep software updated.
    Update WordPress, plugins, themes and any PHP application as soon as security releases appear. Delete what you don't use.
  2. Use strong, unique passwords and two-factor sign-in.
    Turn on two-factor authentication for your Domain India account and for your CMS.
  3. Choose a current PHP version.
    Old PHP versions get no security fixes. See how to change your PHP version.
  4. Never use folder permissions of 777.
    Use 755 for folders and 644 for files.
  5. Keep an off-server copy.
    Download a JetBackup copy from time to time and before major changes.

7. Tools for your own VPS

On a Domain India VPS you have root access and manage security yourself; none of the shared-hosting tools above are installed for you, and there is no cPanel on a VPS. The old list of "tools to install" has changed since it was written. For a new server in 2026:

JobGood current choiceNotes
Firewallfirewalld (AlmaLinux, Rocky) or ufw (Ubuntu, Debian)Allow only the ports you use. ConfigServer stopped developing CSF in 2025, so avoid it on a new server
Brute-force blockingFail2BanReads logs and bans IPs after repeated failures on SSH, mail or web logins
Web application firewallModSecurity v3 or Coraza with the OWASP Core Rule SetOr Imunify360 with your own licence
Malware scanningClamAV, or a commercial scannerSchedule scans; real-time scanning needs more setup
Security auditLynisInstall it from your distribution's packages and run it after setup and after major changes
File integrity and intrusion detectionAIDE, or Wazuh for a fuller host IDSWazuh grew out of OSSEC and is actively maintained
Log reviewLogwatch for daily summariesA full ELK stack is heavy for one small server

Install tools from your distribution's package manager, not from old tarball links, so they receive security updates. Start with the basics in the SSH security hardening checklist and essential VPS security tips.

8. Where Domain India fits

If you want the protection above without running it yourself, choose shared hosting; the same security stack covers every plan:

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

The cards show Domain India list prices on 19 September 2026, excluding 18% GST. Compare cPanel hosting, DirectAdmin hosting and VPS servers.

9. Frequently asked questions

What security software protects Domain India shared hosting?

Domain India's cPanel and DirectAdmin shared servers run CloudLinux with CageFS account isolation, Imunify360 for web application firewall and malware protection, the CSF firewall with login-failure blocking, free SSL through AutoSSL or Let's Encrypt, and JetBackup 5 for weekly backups.

Do higher plans get better security?

No. The security tools are configured for the whole server, so every account on a server gets the same protection, whatever its plan.

Does Imunify360 clean malware automatically?

Yes. On Domain India's cPanel server, when Imunify360 finds malicious code in a file, it removes that code automatically and keeps the original for 14 days. It does not fix weak passwords, rogue admin users or outdated plugins, so you still need to secure the application itself.

How often are shared hosting accounts backed up?

Weekly. JetBackup 5 takes account backups every Sunday on the cPanel and DirectAdmin servers and keeps 5 copies, which you can download or restore from JetBackup in your control panel.

Why was my IP address blocked?

The server firewall blocks an IP temporarily after repeated failed logins, often from an old password saved in an email app or FTP client. Correct the saved password and open a support ticket with your IP address to have the block reviewed.

Can I install Fail2Ban or ClamAV on shared hosting?

No. On shared hosting the server tools are managed by Domain India and you can't install system software. On a VPS you have root access and can install and configure any of these tools yourself.

Ready for hosting with the security layers already in place? Compare cPanel hosting and DirectAdmin hosting, or choose a VPS if you want to manage the server yourself.

Questions about security on your account?

Our support team is on 24/7 live chat, and tickets get a first response within 15 minutes.

Open a support ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Shared Hosting Security Tools: What We Run | Domain India