Opens in a new tab

OPSSHIELD CPGUARD SERVER SECURITY

Full-Stack Linux Server Security, Built for Hosting

Protect your Linux hosting server with malware detection and clean-up, Web Application Firewall protection, abusive IP blocking, CMS threat intelligence and server-level security monitoring, brought together in one comprehensive security platform.

Big Wet Fish Hosting is an OPSSHIELD Partner.

SERVER SECURITY / CPGUARD
OPSSHIELDProtection layersOne server. One security view.

ONLINE

LAYERS CONNECTEDIllustrative security overview

FULL-STACK SERVER SECURITY

One security suite. Multiple layers of protection.

Server security requires more than malware scanning. cPGuard brings together file and database scanning, web attack filtering, abusive IP intelligence, firewall controls, CMS vulnerability information, reputation monitoring and server-level checks.

01 / DETECT

Malware Detection & Cleanup

Find suspicious files, contain threats according to policy and attempt to clean malicious injections.

02 / ANALYSE

AI-Assisted Threat Detection

Intelligent code analysis helps flag suspicious patterns that signature matching alone may miss.

03 / FILTER

Web Application Firewall

ModSecurity rules inspect hostile requests before they reach vulnerable application code.

04 / BLOCK

Firewall & IPDB Protection

Block known abusive sources at the server firewall and control unwanted connection traffic.

05 / KNOW

CMS Threat Intelligence

Discover supported CMS installations and see vulnerable core, plugin and theme components.

06 / MONITOR

Server & Reputation Monitoring

Track suspicious activity, domain reputation and sending IP issues from one security platform.

DETECT · CONTAIN · CLEAN

Malware protection that does more than run a scheduled scan

Threats can arrive through uploads, vulnerable code or compromised accounts. cPGuard combines active monitoring with scheduled and on-demand investigation, then gives administrators a choice of response.

01

Real-Time Scanner

Monitor file changes and analyse suspicious content as activity occurs.

02

Scheduled Scanning

Daily and weekly scan options provide a recurring check of recently modified files.

03

Manual Scanning

Administrators can trigger full, path-specific or targeted scans when investigating an incident.

04

AI-Assisted Detection

Machine-learning-assisted analysis helps identify suspicious code patterns beyond traditional signatures.

05

Flexible Response

Depending on server policy, detections can trigger alerts, quarantine or file disabling. The default file action is email notification until changed.

06

Cleanup & Core Recovery

cPGuard can attempt to clean malicious injections, and supported compromised CMS core files can be restored from clean sources.

MALWARE ISN’T ALWAYS IN A FILE

Scan the WordPress database too

Compromises can place malicious JavaScript, redirects and other payloads directly into a WordPress database. cPGuard’s database scanner is designed to identify suspicious content and code injections alongside threats in website files.

Database threats can otherwise remain after infected files have been cleaned, creating a path for malicious redirects or reinfection.

01WEBSITE FILESSCANNED
02WORDPRESS DATABASESCANNED
03CMS CORECHECKED

FILE + DATABASE VISIBILITY

BLOCK THE REQUEST BEFORE IT BECOMES A COMPROMISE

A commercial Web Application Firewall built for hosting

cPGuard uses ModSecurity with its own hosting-focused rules and commercial Malware.Expert protection. Malicious HTTP requests can be rejected before vulnerable application code processes them. WAF rules are configured during activation; the module is not enabled by default after installation.

REQUEST INSPECTION

HTTP REQUESTcPGuard WAFAPPLICATION

Layer 7 inspection of request patterns, headers and parameters, with rule logging and exclusions when legitimate traffic needs to be allowed.

SQL InjectionCross-Site ScriptingLocal File InclusionRemote File InclusionMalicious UploadsWeb ShellsExploit AttemptsBad Crawlers

Additional modules can include CAPTCHA protection for CMS login pages, malicious scanner filtering, web shell protection and bad crawler controls, depending on configuration.

STOP KNOWN ATTACKERS EARLIER

Block malicious traffic before it reaches the website

cPGuard’s IPDB draws on abusive IP intelligence. Known malicious addresses can be blocked by the system-level server firewall before they reach the web server, PHP or the website application. That reduces exposure and avoids spending application resources on obvious abuse.

  • IPv4 and IPv6 filtering
  • Temporary and WAF-triggered bans
  • Port, protocol and country controls
  • Single-source DoS and SYN flood mitigation
  • Bad bot and aggressive crawler filtering
INTERNET

↓

IPDB INTELLIGENCE

↓

SERVER FIREWALL ABUSIVE IP → BLOCKED

↓

WEB APPLICATION FIREWALL

↓

WEBSITE

HUMANS IN. BOTS OUT.

Reduce brute-force attacks and unwanted automated traffic

cPGuard can challenge automated traffic on WordPress, Joomla and other supported login URLs. CAPTCHA verification happens away from the local application, reducing the work caused by repeated bot login attempts.

CMS login protectionBrute-force mitigationBad crawler detectionMalicious user-agent blockingBot filteringAI scraper controls

KNOW WHAT IS VULNERABLE

Visibility into vulnerable CMS software

cPGuard discovers supported CMS installations and identifies outdated or vulnerable components using threat and CVE intelligence. For WordPress, that can include core, plugins and themes, with information to help administrators prioritise investigation and updates.

Keep software current.

Security software does not remove the need to update WordPress, plugins, themes and other applications.

CMS THREAT INTELLIGENCE

WORDPRESS COREVERSION VISIBILITY
PLUGINSVULNERABILITY CHECKS
THEMESTHREAT INFORMATION

COMPONENT · SEVERITY · CONTEXT

YOUR SERVER’S REPUTATION MATTERS

Spot reputation problems before they become bigger problems

A compromised site can damage a domain’s standing. Spam scripts can damage a sending IP’s standing. Earlier visibility helps administrators investigate before visitors or email delivery are affected further.

01 / WEBSITE TRUST

Domain Reputation

cPGuard can check hosted domains against Google Safe Browsing so administrators can see when a site may have been flagged as unsafe following a compromise.

02 / MAIL DELIVERY

IP Reputation

DNSBL and RBL monitoring can identify server IP addresses that appear on mail-related blocklists, helping teams investigate spam or compromised accounts.

Third-party reputation services control their own listings and removal processes.

LOOK BEYOND PUBLIC_HTML

Threats do not always stay inside the website

Server security needs visibility beyond the web root. Depending on the control panel, server policy and enabled modules, cPGuard can help surface suspicious processes, unwanted mail and security events.

PROCESS

Suspicious activity

Look for unexpected processes and patterns associated with malware, spam scripts or cryptomining.

MAIL

Outgoing spam

Where supported and enabled, monitor unusual email sending that could indicate a compromised account or script.

REPORTS

Security alerts

Review administrator notifications and daily security information so important detections are not overlooked.

POLICY

Account protection

Where configured, defined security thresholds can trigger stronger responses, including account suspension policies.

HOW THE SECURITY STACK WORKS

From attack attempt to remediation

Distinct controls work at different points in the request and response path. Each layer gives your hosting team another way to see, stop or contain a threat.

01

DETECT

Scan files, databases and CMS installations for malware and security threats.

02

FILTER

Use WAF rules to reject malicious web requests.

03

BLOCK

Stop known abusive sources through IPDB and firewall controls.

04

CONTAIN

Quarantine or disable detected malicious files according to policy.

05

CLEAN

Attempt to remove malicious injections or restore supported CMS files from clean sources.

06

MONITOR

Continue checking events, reputation, CMS threats and suspicious activity.

ONE SECURITY VIEW

See what is happening across your servers

The cPGuard App Portal gives administrators a central view of protected servers. Review detections, WAF events, IP reputation activity, reports and alerts, then manage configuration and switch between servers as needed.

Bulk administration, command-line tools and API access offer additional flexibility for technical teams.

SECURITY OVERVIEW
SERVER STATUSIN VIEWMALWARE DETECTIONSREVIEWWAF EVENTSREVIEWIP REPUTATIONMONITORREPORTS & ALERTSMANAGE

ILLUSTRATIVE ADMINISTRATOR VIEW

VISIBILITY FOR HOSTING USERS

A security view for your customers too

On supported control panels, cPGuard can provide user-level interfaces for malware scan information, manual scans, CMS threats, WAF activity and bot events. User plugins are available for cPanel, DirectAdmin and Webuzo.

Available functions depend on the panel and the configuration applied to your BWF server.

SCAN INFORMATIONMANUAL SCANSCMS THREATSWAF EVENTSBOT ACTIVITY

BUILT FOR LINUX HOSTING

Works with modern hosting environments

cPGuard supports a broad range of Linux hosting stacks, from established control panels to compatible standalone servers.

Control panels

cPanel / WHM · DirectAdmin · Plesk · Enhance · Webuzo · CyberPanel · Control Web Panel · RunCloud · InterWorx · Webmin · Standalone Linux

Web servers

Apache · Nginx · LiteSpeed · OpenLiteSpeed

Linux families

AlmaLinux · Rocky Linux · CloudLinux · RHEL · Ubuntu · Debian · Amazon Linux

Compatibility depends on the operating system, control panel and web-server configuration. BWF can confirm compatibility before activation.

MORE CONTROL WHEN YOU NEED IT

Details that strengthen the wider security policy

Administrators can tailor protection to the environment. These additional controls and reports help investigate incidents, reduce abuse and avoid unnecessary disruption to legitimate traffic.

WordPress core file integrity checksPHP upload protectionDaily security reportsAutomatic security notificationsWordPress wp-cron controlsSpam activity monitoringCountry filteringTemporary firewall bansWhitelisting and exclusionsSecurity policy configuration

SIMPLE PER-SERVER LICENSING

Powerful server protection from £6 per month

The same comprehensive security platform for your hosting environment. Choose a licence based on the number of hosting accounts on the server.

Both licences cover the same cPGuard security capabilities. The account limit is the difference.

DEFENCE IN DEPTH

Security works best in layers

OPSSHIELD cPGuard adds substantial server-level protection. It belongs alongside current software, strong passwords, two-factor authentication where available, suitable access controls, off-server backups and application-specific vulnerability protection where needed.

No security platform can guarantee that a server or website will never be compromised.

FREQUENTLY ASKED QUESTIONS

The details, made simple

What is the difference between OPSSHIELD and cPGuard?

OPSSHIELD is the company behind cPGuard. BWF supplies the cPGuard server-security suite as our OPSSHIELD server-security offering.

Does cPGuard only protect WordPress?

No. It is a Linux server-security platform designed for hosting environments. WordPress receives additional CMS-specific functionality, but malware scanning, WAF, firewall, reputation and server-security functions are not limited to WordPress.

Does OPSSHIELD replace my backups?

No. Security and backups perform different functions. Maintain appropriate off-server backups even on a protected server.

Does it replace WordPress updates?

No. Vulnerable CMS software should still be updated. cPGuard can identify vulnerabilities and provide additional attack protection, but keeping software current remains important.

Does it include a Web Application Firewall?

Yes. cPGuard provides a ModSecurity-based WAF using cPGuard protection rules and commercial Malware.Expert rules. The WAF needs to be enabled and configured during activation.

What happens when malware is found?

Depending on the configured server policy, cPGuard can alert administrators, quarantine a file, disable it or attempt to clean malicious injections. Its default file action is email notification until changed.

Can cPGuard scan WordPress databases?

Yes. Its database scanner can identify suspicious or malicious injections within WordPress databases, alongside scanning website files.

Does it provide DDoS protection?

cPGuard includes server-level controls for abusive IPs, connection floods, single-source DoS activity, SYN floods and malicious bots. It is not a replacement for upstream network-level volumetric DDoS filtering.

Will it slow down my server?

cPGuard is designed for hosting environments with an emphasis on low resource usage. Actual resource consumption depends on the server, workload and security configuration.

Which control panels are supported?

Supported environments include cPanel / WHM, DirectAdmin, Plesk, Enhance, Webuzo and several other panels, plus compatible standalone Linux servers. BWF can confirm your particular server setup before activation.

Can it protect an existing server?

Yes, cPGuard can be installed on compatible existing Linux hosting environments. BWF will confirm operating system, web server and panel compatibility before activation.

Can my hosting users see security information?

User-level interfaces are available for certain supported panels, including cPanel, DirectAdmin and Webuzo. Available functions depend on the panel and the BWF server configuration.

How much does it cost?

£6 + VAT per server per month for up to 50 hosting accounts, or £11 + VAT per server per month for unlimited hosting accounts.

How do I order it?

Open a BWF Sales support ticket and tell us which server you would like protected.

SERVER SECURITY, HANDLED

Add another layer of protection to your server

Malware detection, database scanning, WAF protection, abusive IP blocking, CMS threat intelligence and server monitoring, brought together in one comprehensive Linux security platform.

OPSSHIELD powered by cPGuard