What is CPGuard? Complete Guide to Hosting Security in 2026
Everything you need to know about CPGuard — the security suite protecting hosting servers from malware, attacks, and cyber threats.
Contents
What is CPGuard?
CPGuard is an all-in-one server security suite for web hosting environments, combining a malware scanner, Web Application Firewall (WAF), antivirus engine, network firewall, email security, and brute-force protection in a single platform. Designed for DirectAdmin and cPanel, it allows hosting providers to deploy comprehensive server protection without managing multiple separate tools.
The solution was built specifically for shared and VPS hosting environments where a single compromised account can affect every other site on the same server. By operating at the server level, CPGuard intercepts threats before they reach individual websites, providing a crucial layer of defence that application-level plugins cannot replicate.
- All-in-one: malware, WAF, antivirus, firewall, and email in one platform
- Supports DirectAdmin and cPanel (verify other supported control panels at cpguard.io)
- Lower combined resource usage than running separate security tools
- Automatic signature and rule updates daily
- Centralised dashboard for complete security visibility
Core Components of CPGuard
CPGuard's architecture is built around several security modules that work in concert. Each targets a distinct attack vector, creating the layered defence model that security professionals recommend: even if one layer is bypassed, the next layer catches the threat before damage occurs.
- Malware Scanner: scans all server files for malicious code signatures
- WAF: blocks SQL Injection, XSS, CSRF before reaching the application
- Antivirus: detects viruses and backdoors hidden in uploaded files
- Network Firewall: manages IP blocking and port-level access control
- Email Security: filters spam and phishing at the mail server level
- Brute Force Protection: auto-blocks IPs making repeated failed login attempts
(verify other supported control panels at cpguard.io)
Why Hosting Servers Need CPGuard
Modern web attacks are almost entirely automated. Botnets scan the entire internet continuously, probing every IP address for known vulnerabilities in WordPress, PHP applications, and control panel software. A server without protection will face thousands of such probes daily, and it only takes one successful attempt to compromise an account — which can then spread malware to other accounts on the same server.
- Automated bots probe servers for vulnerabilities 24 hours a day
- New WordPress and PHP vulnerabilities emerge weekly
- One compromised account can affect all sites on a shared server
- Infected servers often get blacklisted by search engines and email providers
How CPGuard's Malware Scanner Works
The malware scanner is one of CPGuard's most actively used components. It performs both scheduled scans of all server files and real-time scanning of newly uploaded files — critical for catching malware injected through file uploads before it can execute.
When the scanner detects a suspicious file, it compares it against a constantly updated signature database. Detected files can be automatically quarantined (moved to an isolated location) to prevent the malware from running while the administrator reviews the situation.
- Scheduled full-server scans and real-time upload scanning
- Detects PHP shells, backdoors, and cryptocurrency miners hidden in code
- Automatic quarantine to isolate infected files immediately
- Email reports sent to administrators after each scan
- Signature database updated automatically every day
Web Application Firewall (WAF)
CPGuard's WAF sits between web visitors and the server, analysing every HTTP/HTTPS request before it reaches PHP or the database. It uses a rule set aligned with the OWASP Top 10 — the industry standard list of critical web application security risks — to block SQL Injection, Cross-Site Scripting, Remote Code Execution, Path Traversal, and similar attacks.
This means websites are protected even when their application code contains vulnerabilities — a valuable safety net while patches are being applied.
- Blocks SQL Injection and XSS before reaching the database
- Prevents Remote File Inclusion (RFI) and Local File Inclusion (LFI)
- OWASP Top 10-aligned rule set, updated as new threats emerge
- Whitelist mode for applications with legitimate unusual requests
- Complete attack log for forensic review
Email Security and Spam Protection
CPGuard's email security module integrates with the server's mail stack to scan both inbound and outbound messages. Outbound scanning is particularly important: if an account on the server is compromised and used to send spam, the entire server IP can be blacklisted by major email providers, causing all legitimate email from the server to be rejected.
- Inbound spam filtering using SpamAssassin rules
- Outbound scanning to prevent server IP blacklisting
- Phishing link detection in email body
- Malware scanning for email attachments
CPGuard and DirectAdmin Integration
CPGuard integrates directly into the DirectAdmin control panel, making security management accessible without SSH or command-line access. Hosting providers running DirectAdmin — such as AsiaGB.com — can activate CPGuard protection for all customers automatically.
- Native DirectAdmin plugin — no SSH or command line required
- Individual accounts can view their own security status
- Admins get a security overview across all hosted accounts
- WAF rules and whitelists configurable through the control panel UI
Choosing Hosting with Server-Level Security
When evaluating hosting providers, always ask what server-level security tools they deploy. Whether CPGuard, Imunify360, or an equivalent system, server security protects every account on that machine. Providers without these protections carry significantly higher risk.
AsiaGB.com provides server-level security protections alongside SSD storage, DirectAdmin control panel, 24-hour Thai-language support, and 99% uptime — making it a reliable choice for individuals and businesses that need dependable, well-protected hosting.
- Ask providers exactly which server security tools they use
- Good hosting should include malware scanning and WAF by default
- Check uptime history and security track record before committing
- Fast support response is critical when a security incident occurs