8 min
Imunify360 vs Wordfence for WordPress hosting providers
A server-wide security suite the host controls vs a per-site plugin the customer buys — how Imunify360 and Wordfence actually differ for a shared WordPress fleet.
2026-08-14
7 min
Enable Imunify360 WAF for WordPress: virtual patching explained
WAF for WordPress ships free with every Imunify360 and ImunifyAV licence — it blocks known plugin and theme exploits at the request level before the vulnerable code runs.
2026-08-11
4 min
Tune Imunify360 WAF to stop blocking legitimate traffic
Disable Comodo/OWASP duplicate rulesets, set LF_MODSEC=0, and use /etc/imunify360/whitelist/*.txt to stop blocking legitimate plugin traffic.
2026-05-16
4 min
Whitelist Plesk ModSecurity rules without breaking ruleset updates
Surgical fixes for Plesk ModSecurity false positives — by rule ID, by IP, per-domain, and per-directory — with snippets that survive ruleset updates.
2026-05-16
10 min
ModSecurity rule sets on cPanel: OWASP CRS vs Comodo cWAF
A practical look at the four ModSecurity rule sets that ship with WHM — OWASP CRS, Comodo cWAF, Atomicorp Basic, and Imunify360 — and when each one is the right pick.
2026-05-16
7 min
Install Imunify360 on a cPanel and CloudLinux server
A 20-minute install of Imunify360 on a cPanel + CloudLinux node — license activation, the installer, Proactive Defense, and the three default settings to change before letting customers log in.
2026-05-15