Website security is not a luxury, it is an absolute necessity. Every day, thousands of websites worldwide are hacked, infected with malware or abused for phishing. Do not think it only happens to large companies: small websites on shared hosting in particular are a popular target because they are often less well secured. Fortunately there is Imunify security, an extensive security suite that works at server level and automatically protects your website against the most common threats.

In this article we explain what Imunify security is exactly, how it works, which components it contains and why it is an essential part of modern web hosting. At Theory7, Imunify is included as standard on all hosting plans, at no extra cost. We tell you exactly what that means for your website.

What is Imunify security?

Imunify is an all-in-one security platform developed specifically for web servers. It combines several security technologies in a single solution that runs at server level. That means you as a website owner do not have to install or configure anything: the protection is automatically active as soon as your website runs on a server with Imunify.

The strength of Imunify lies in its layered approach. Instead of a single line of defense, it offers multiple security layers that work together. If an attack slips through one layer, it is intercepted by the next. This defense-in-depth strategy is the same approach that large companies use for their server infrastructure.

Imunify is developed by CloudLinux, a company that has specialized in server security and stability for more than fifteen years. The product is continuously updated with the latest threat intelligence and protection techniques. Every day, millions of attacks are blocked on servers around the world that run Imunify.

The five security layers of Imunify

To understand why Imunify security is so effective, we need to look at the five core components. Each component protects against a specific type of threat, and together they form an almost impenetrable shield around your website.

1. Malware scanner: automatic detection and cleanup

The malware scanner is the heart of Imunify. This scanner continuously checks all files on the server for known and unknown malware. It works with an extensive database of malware signatures that is updated several times per day. But it goes further than just detecting known malware.

Imunify also uses heuristic analysis to recognize suspicious code that is not yet in the database. Suppose a new WordPress exploit appears: even before that specific malware is known, the scanner can recognize unusual patterns in PHP files. Infected files are automatically quarantined so they cannot cause any damage.

The scanner works in real time when files are uploaded and also performs periodic full scans. As a result, malware uploaded through a vulnerability is detected within a few minutes. With many other hosting providers you have to run a malware scanner yourself, but with servers that have Imunify that is not necessary.

2. Web application firewall (WAF): blocking attacks

The built-in web application firewall analyzes all incoming web traffic and blocks suspicious requests before they reach your website. The WAF protects against the most common attack techniques such as SQL injection, cross-site scripting (XSS), remote file inclusion and local file inclusion.

What sets Imunify apart from a standard WAF is its use of artificial intelligence. The system continuously learns from attack patterns across millions of websites worldwide. If a new attack technique is detected on a server in another country, that knowledge is shared within minutes with all other Imunify servers. This creates a collective immune system that keeps getting smarter.

The WAF also works at a low level in the web server, so it barely affects the performance of your website. Visitors notice nothing of the checks, only malicious requests are stopped.

3. Brute-force protection: stopping intrusion attempts

Brute-force attacks are one of the most common threats to websites. In a brute-force attack, an attacker systematically tries thousands of combinations of usernames and passwords to log in to your WordPress admin, FTP account or email account.

Imunify detects these attacks automatically and blocks the attacker's IP address after a certain number of failed attempts. The system is smart enough to distinguish between a legitimate user who has forgotten their password and an automated attack. A real user who enters a wrong password three times is not blocked, but a bot that makes a hundred attempts per minute is refused right away.

The brute-force protection works for all services on the server: SSH, FTP, SMTP, POP3, IMAP and web applications. As a result you are protected against attacks on every access point to your hosting account.

4. Proactive defense: stopping suspicious processes

The proactive defense is a unique technology that analyzes PHP scripts in real time while they are running. If a script shows suspicious behavior, such as trying to read system files, connect to a command-and-control server or encrypt files, it is stopped right away.

This is particularly powerful because it also protects against zero-day exploits: vulnerabilities that are not yet known and for which no patch is available yet. Even if an attacker manages to place malicious code on your server, that code cannot be executed if the proactive defense detects suspicious behavior.

The proactive defense uses machine learning to learn the normal behavior of PHP scripts. As a result it can recognize deviant behavior without needing a specific signature for it. This makes it one of the most advanced security measures available for shared hosting.

5. Kernel patching and reputation management

Imunify keeps the server kernels up to date with security patches without the server having to be restarted. This may sound technical, but it is important: many servers run for weeks or months with known vulnerabilities because a restart causes downtime. With patch management these vulnerabilities are closed right away, without interruption.

In addition, Imunify maintains a reputation database of IP addresses. IP addresses known for spreading malware or spam, or for carrying out attacks, are proactively blocked. This grey list is continuously updated based on information from millions of servers worldwide.

Imunify on shared hosting: why it is so important

On shared hosting you share a server with dozens or even hundreds of other websites. That brings a specific security risk: if another website on the same server is hacked, the attacker could in theory reach your files too. This is known as the cross-site contamination problem.

Imunify security is therefore extra valuable on shared hosting. The combination of the malware scanner, the WAF and the proactive defense ensures that malicious activity on a hacked website cannot spread to other accounts on the same server.

At Theory7 we go one step further by combining Imunify with CloudLinux CageFS. CageFS places each hosting account in an isolated environment, a kind of virtual cage. Every website can only see and access its own files. Even if an attacker manages to run malicious code, they cannot get beyond the boundaries of that one account. This layered security model, Imunify plus CageFS, offers a level of security comparable to a VPS, but on shared hosting.

How Imunify protects your WordPress website

WordPress is the most widely used CMS in the world and therefore also the biggest target for hackers. The combination of a popular platform with thousands of plugins of varying quality makes WordPress websites vulnerable to a wide range of attacks. Imunify security is particularly effective for WordPress websites for a number of reasons.

First, Imunify scans all WordPress files for known malware and modifications to core files. If a hacker places a backdoor in a theme or plugin, this is detected automatically. Second, the WAF protects against the most common WordPress attacks: SQL injection through vulnerable plugins, XSS attacks through contact forms and unauthorized access to the REST API.

Third, the brute-force protection prevents attackers from exploiting the wp-login.php attack surface. WordPress login pages are one of the most attacked URLs on the internet. Without protection, a bot can make thousands of login attempts per hour. With Imunify these bots are quickly recognized and blocked.

Imunify versus standalone security solutions

You may wonder: do I still need a WordPress security plugin if my server already runs Imunify? The answer is nuanced. Imunify and security plugins work at different levels and complement each other.

Feature Imunify (server level) Plugin (application level)
Malware scanning All files on the server WordPress files only
Firewall All web traffic WordPress requests only
Brute-force All services (SSH, FTP, etc.) wp-login only
Update monitoring Kernel patches Plugin and theme updates
Installation needed No (server level) Yes (per website)

The ideal approach is to use Imunify as a base and additionally run a lightweight security plugin for WordPress-specific checks. Avoid heavy security plugins that carry out the same tasks as Imunify, however, as that leads to unnecessary server load and possible conflicts.

Why Theory7 includes Imunify as standard

At Theory7, Imunify security is included free on all web hosting plans, from the Mini plan of €0.49 per month to our largest plans. We believe website security should not be a premium feature you pay extra for. It is a basic requirement, just like an SSL certificate.

Many hosting providers only offer Imunify on more expensive plans or as a paid add-on. We have deliberately chosen to include it as standard because we believe every website, large or small, deserves professional security. In combination with CloudLinux CageFS, a LiteSpeed web server and free SSL certificates, our plans offer a level of security that with many competitors you only get at VPS level.

It also saves our support department a lot of work. Hacked websites cost not only the owner time and money, but us as a hosting provider too. By protecting proactively with Imunify, we prevent problems instead of solving them afterwards. That is better for everyone.

Practical tips for maximum security

Imunify offers excellent protection at server level, but there are additional measures you can take yourself to secure your website even better. Think of it as a layered model: Imunify forms the foundation, and you build extra layers on top of it.

  • Keep your CMS and plugins up to date - most hacks exploit known vulnerabilities for which a patch is already available
  • Use strong, unique passwords - at least 12 characters with letters, numbers and special characters
  • Enable two-factor authentication - adds an extra security layer to your login
  • Remove unused plugins and themes - every plugin is a potential attack surface
  • Make backups regularly - if something does go wrong you can recover quickly
  • Limit the number of admin accounts - the fewer accounts with full rights, the smaller the risk

With Imunify security as a base and these additional measures, you make it as hard as possible for attackers. Absolute security does not exist, but by combining multiple layers you keep the risk to a minimum.

Frequently asked questions about Imunify security

What is Imunify security exactly?

Imunify is an extensive security suite for web servers that combines several protection layers: a malware scanner, a web application firewall (WAF), brute-force protection, proactive defense and patch management. It runs at server level and automatically protects all websites on the server without you having to install anything yourself.

Do I have to install Imunify myself on my hosting?

No, Imunify is installed and managed at server level by the hosting provider. At Theory7, Imunify is active as standard on all web hosting plans. You do not have to configure anything yourself. The protection works automatically in the background for all your websites.

Does Imunify replace a WordPress security plugin?

Imunify offers protection at server level, while WordPress security plugins work at application level. Ideally you use both for maximum protection. Imunify already catches most threats before they reach your WordPress installation, but a plugin such as Wordfence or Sucuri adds extra checks for WordPress-specific vulnerabilities.

Does Imunify also protect against DDoS attacks?

Imunify offers protection against brute-force attacks and suspicious network activity, but it is not full DDoS mitigation. For large-scale DDoS protection you need a solution such as Cloudflare or a dedicated DDoS mitigation service. Imunify focuses primarily on malware, vulnerabilities and intrusion attempts at application level.

How does Imunify work together with CloudLinux CageFS?

Imunify and CloudLinux CageFS together form a layered security model. CageFS isolates each hosting account in its own closed-off environment so that a hacked website cannot reach other websites on the same server. On top of that, Imunify scans and blocks malware and attacks. Together they offer protection comparable to a VPS environment but on shared hosting.

Sources and references

  • Cloudflare - Learning Center (cloudflare.com/learning)
  • Wordfence - WordPress Security Report (wordfence.com)
  • Sucuri - Website Security Research (sucuri.net)