Malware Detection & Cleanup
Find suspicious files, contain threats according to policy and attempt to clean malicious injections.
OPSSHIELD CPGUARD SERVER SECURITY
Protect your Linux hosting server with malware detection and clean-up, Web Application Firewall protection, abusive IP blocking, CMS threat intelligence and server-level security monitoring, brought together in one comprehensive security platform.
Big Wet Fish Hosting is an OPSSHIELD Partner.
ONLINE
FULL-STACK SERVER SECURITY
Server security requires more than malware scanning. cPGuard brings together file and database scanning, web attack filtering, abusive IP intelligence, firewall controls, CMS vulnerability information, reputation monitoring and server-level checks.
Find suspicious files, contain threats according to policy and attempt to clean malicious injections.
Intelligent code analysis helps flag suspicious patterns that signature matching alone may miss.
ModSecurity rules inspect hostile requests before they reach vulnerable application code.
Block known abusive sources at the server firewall and control unwanted connection traffic.
Discover supported CMS installations and see vulnerable core, plugin and theme components.
Track suspicious activity, domain reputation and sending IP issues from one security platform.
DETECT · CONTAIN · CLEAN
Threats can arrive through uploads, vulnerable code or compromised accounts. cPGuard combines active monitoring with scheduled and on-demand investigation, then gives administrators a choice of response.
Monitor file changes and analyse suspicious content as activity occurs.
Daily and weekly scan options provide a recurring check of recently modified files.
Administrators can trigger full, path-specific or targeted scans when investigating an incident.
Machine-learning-assisted analysis helps identify suspicious code patterns beyond traditional signatures.
Depending on server policy, detections can trigger alerts, quarantine or file disabling. The default file action is email notification until changed.
cPGuard can attempt to clean malicious injections, and supported compromised CMS core files can be restored from clean sources.
MALWARE ISN’T ALWAYS IN A FILE
Compromises can place malicious JavaScript, redirects and other payloads directly into a WordPress database. cPGuard’s database scanner is designed to identify suspicious content and code injections alongside threats in website files.
Database threats can otherwise remain after infected files have been cleaned, creating a path for malicious redirects or reinfection.
FILE + DATABASE VISIBILITY
BLOCK THE REQUEST BEFORE IT BECOMES A COMPROMISE
cPGuard uses ModSecurity with its own hosting-focused rules and commercial Malware.Expert protection. Malicious HTTP requests can be rejected before vulnerable application code processes them. WAF rules are configured during activation; the module is not enabled by default after installation.
Layer 7 inspection of request patterns, headers and parameters, with rule logging and exclusions when legitimate traffic needs to be allowed.
Additional modules can include CAPTCHA protection for CMS login pages, malicious scanner filtering, web shell protection and bad crawler controls, depending on configuration.
STOP KNOWN ATTACKERS EARLIER
cPGuard’s IPDB draws on abusive IP intelligence. Known malicious addresses can be blocked by the system-level server firewall before they reach the web server, PHP or the website application. That reduces exposure and avoids spending application resources on obvious abuse.
↓
↓
↓
↓
HUMANS IN. BOTS OUT.
cPGuard can challenge automated traffic on WordPress, Joomla and other supported login URLs. CAPTCHA verification happens away from the local application, reducing the work caused by repeated bot login attempts.
KNOW WHAT IS VULNERABLE
cPGuard discovers supported CMS installations and identifies outdated or vulnerable components using threat and CVE intelligence. For WordPress, that can include core, plugins and themes, with information to help administrators prioritise investigation and updates.
Security software does not remove the need to update WordPress, plugins, themes and other applications.
COMPONENT · SEVERITY · CONTEXT
YOUR SERVER’S REPUTATION MATTERS
A compromised site can damage a domain’s standing. Spam scripts can damage a sending IP’s standing. Earlier visibility helps administrators investigate before visitors or email delivery are affected further.
cPGuard can check hosted domains against Google Safe Browsing so administrators can see when a site may have been flagged as unsafe following a compromise.
DNSBL and RBL monitoring can identify server IP addresses that appear on mail-related blocklists, helping teams investigate spam or compromised accounts.
Third-party reputation services control their own listings and removal processes.
LOOK BEYOND PUBLIC_HTML
Server security needs visibility beyond the web root. Depending on the control panel, server policy and enabled modules, cPGuard can help surface suspicious processes, unwanted mail and security events.
Look for unexpected processes and patterns associated with malware, spam scripts or cryptomining.
Where supported and enabled, monitor unusual email sending that could indicate a compromised account or script.
Review administrator notifications and daily security information so important detections are not overlooked.
Where configured, defined security thresholds can trigger stronger responses, including account suspension policies.
HOW THE SECURITY STACK WORKS
Distinct controls work at different points in the request and response path. Each layer gives your hosting team another way to see, stop or contain a threat.
Scan files, databases and CMS installations for malware and security threats.
Use WAF rules to reject malicious web requests.
Stop known abusive sources through IPDB and firewall controls.
Quarantine or disable detected malicious files according to policy.
Attempt to remove malicious injections or restore supported CMS files from clean sources.
Continue checking events, reputation, CMS threats and suspicious activity.
ONE SECURITY VIEW
The cPGuard App Portal gives administrators a central view of protected servers. Review detections, WAF events, IP reputation activity, reports and alerts, then manage configuration and switch between servers as needed.
Bulk administration, command-line tools and API access offer additional flexibility for technical teams.
ILLUSTRATIVE ADMINISTRATOR VIEW
VISIBILITY FOR HOSTING USERS
On supported control panels, cPGuard can provide user-level interfaces for malware scan information, manual scans, CMS threats, WAF activity and bot events. User plugins are available for cPanel, DirectAdmin and Webuzo.
Available functions depend on the panel and the configuration applied to your BWF server.
BUILT FOR LINUX HOSTING
cPGuard supports a broad range of Linux hosting stacks, from established control panels to compatible standalone servers.
cPanel / WHM · DirectAdmin · Plesk · Enhance · Webuzo · CyberPanel · Control Web Panel · RunCloud · InterWorx · Webmin · Standalone Linux
Apache · Nginx · LiteSpeed · OpenLiteSpeed
AlmaLinux · Rocky Linux · CloudLinux · RHEL · Ubuntu · Debian · Amazon Linux
Compatibility depends on the operating system, control panel and web-server configuration. BWF can confirm compatibility before activation.
MORE CONTROL WHEN YOU NEED IT
Administrators can tailor protection to the environment. These additional controls and reports help investigate incidents, reduce abuse and avoid unnecessary disruption to legitimate traffic.
SIMPLE PER-SERVER LICENSING
The same comprehensive security platform for your hosting environment. Choose a licence based on the number of hosting accounts on the server.
£6+ VAT
per server / month
Up to 50 hosting accounts
£11+ VAT
per server / month
Unlimited hosting accounts
Both licences cover the same cPGuard security capabilities. The account limit is the difference.
DEFENCE IN DEPTH
OPSSHIELD cPGuard adds substantial server-level protection. It belongs alongside current software, strong passwords, two-factor authentication where available, suitable access controls, off-server backups and application-specific vulnerability protection where needed.
No security platform can guarantee that a server or website will never be compromised.
FREQUENTLY ASKED QUESTIONS
OPSSHIELD is the company behind cPGuard. BWF supplies the cPGuard server-security suite as our OPSSHIELD server-security offering.
No. It is a Linux server-security platform designed for hosting environments. WordPress receives additional CMS-specific functionality, but malware scanning, WAF, firewall, reputation and server-security functions are not limited to WordPress.
No. Security and backups perform different functions. Maintain appropriate off-server backups even on a protected server.
No. Vulnerable CMS software should still be updated. cPGuard can identify vulnerabilities and provide additional attack protection, but keeping software current remains important.
Yes. cPGuard provides a ModSecurity-based WAF using cPGuard protection rules and commercial Malware.Expert rules. The WAF needs to be enabled and configured during activation.
Depending on the configured server policy, cPGuard can alert administrators, quarantine a file, disable it or attempt to clean malicious injections. Its default file action is email notification until changed.
Yes. Its database scanner can identify suspicious or malicious injections within WordPress databases, alongside scanning website files.
cPGuard includes server-level controls for abusive IPs, connection floods, single-source DoS activity, SYN floods and malicious bots. It is not a replacement for upstream network-level volumetric DDoS filtering.
cPGuard is designed for hosting environments with an emphasis on low resource usage. Actual resource consumption depends on the server, workload and security configuration.
Supported environments include cPanel / WHM, DirectAdmin, Plesk, Enhance, Webuzo and several other panels, plus compatible standalone Linux servers. BWF can confirm your particular server setup before activation.
Yes, cPGuard can be installed on compatible existing Linux hosting environments. BWF will confirm operating system, web server and panel compatibility before activation.
User-level interfaces are available for certain supported panels, including cPanel, DirectAdmin and Webuzo. Available functions depend on the panel and the BWF server configuration.
£6 + VAT per server per month for up to 50 hosting accounts, or £11 + VAT per server per month for unlimited hosting accounts.
Open a BWF Sales support ticket and tell us which server you would like protected.
SERVER SECURITY, HANDLED
Malware detection, database scanning, WAF protection, abusive IP blocking, CMS threat intelligence and server monitoring, brought together in one comprehensive Linux security platform.