WordPress Server Security for cPanel, WHM & Plesk

WordPress security that
scans your database.

A lightweight agent for hosting providers that finds rogue admins, wp_options injections, and SEO spam that Imunify360 and Wordfence can't see — because they don't scan the database. CleanShift does.

Open Source600KB agent · 1.2MB RAM · deploys in 60 seconds

Born from a real CVE-2024-28000 incident — built to find what file scanners miss.

Works with

🖥️

cPanel / WHM

Root or user-level

🛡️

Plesk

Admin extension

📝

WordPress

mu-plugin guard — no root needed

🐧

Any Linux VPS

CentOS · Alma · Ubuntu · CloudLinux

The scanning agent requires root SSH access. The WordPress Guard plugin works on any hosting — no root needed.

cleanshift — enterprise deployment
~ cleanshift-installer --license-key=CS_ENT_****
Validating license against cleanshift.osg.co.in...
License: Enterprise Tier ✓
~ cleanshift scan --server --scan-mode deep
Scanning 120 nodes across 3 data centres...
Found 2,847 database-level threats missed by Imunify360
Found 412 rogue wp_admin injections
~ cleanshift clean --server --mode auto
Running CVE-2024-28000 playbook...
✓ All threats remediated. 120/120 nodes clean.

What makes us different

Security that sees what others can't.

Database-Level Scanning

The industry scans files. We scan the database. Rogue admin accounts, wp_options injection payloads, SEO spam markers, persistence backdoors — we find what Imunify360 and Wordfence physically cannot detect.

wp_optionsrogue adminsSEO spampersistence markers
600KB

Agent footprint.
Competitor average: 80MB.

Real-Time Guard

A zero-config PHP mu-plugin blocks REST API abuse, unauthorized admin creation, and cron hijacking before anything hits disk.

Cross-Site Correlation

If one site is compromised, CleanShift instantly checks every other site on the server for the same IOCs. No manual work.

CVE Playbooks

Automated remediation procedures specific to each vulnerability. Not generic quarantine — surgical cleanup with 1-click rollback.

cPanel · WHM · Plesk

Deploy to 1,000 servers in minutes.

Your DevOps team will love the CLI. Your CFO will love the risk mitigation. And you'll finally sleep through the night.

99.99%
Uptime
< 1ms
Latency
1.2MB
RAM

New in v1.4

Detection capabilities that learn and evolve.

SEO Spam Detection

Detects gambling, pharma, and casino keyword injection in your WordPress database. Catches author burst attacks (50+ spam posts per day) and hidden redirect chains.

keyword scanburst detectionredirect traps

Dropper & Artifact Detection

Finds zero-byte PHP dropper stubs, compressed backdoor payloads (.gz/.zip in web dirs), and misleading extensions like .php.bak or .jpg.php.

0-byte dropperscompressed payloadsfake extensions

Verification Scanning

Post-remediation mode re-scans only previously-flagged locations. Confirms cleanup in seconds, not minutes. 10x faster than a full scan.

Community Intelligence

Crowd-sourced threat hashes from every CleanShift agent feed into your scanner. New malware patterns detected anywhere protect you everywhere.

IoC Contribution

Every scan automatically contributes discovered indicators back to the collective intelligence — making the entire network smarter.

Three steps

From vulnerable to protected in under 60 seconds.

Step 01

Install the Agent

A single authenticated command deploys the 600KB agent. No dependencies to wrangle, no Java, no heavy daemons.

Step 02

Deep Scan Everything

CleanShift scans files AND the database — finding rogue admins, wp_options injections, and persistence markers that legacy scanners miss completely.

Step 03

Auto-Remediate & Harden

CVE-specific playbooks surgically clean threats and harden configurations. Real-time guards activate to prevent re-infection. You get Telegram alerts.

How we compare

The competition doesn't scan the database.

FeatureCleanShiftImunify360Wordfence
Database scanning
Auto-remediation with rollback
Cross-site correlation
CVE-specific playbooks
SEO spam detection
Email security scanner
Plugin auto-updater
Server-level view
WordPress depthDeepShallowDeep
Resource footprint600KBHeavyHeavy
Real-time guards
Starting price₹0$12/mo$149/yr

What's Inside

More than a scanner.
A full security platform.

Every paid plan includes the full feature set — no add-ons, no feature gating per module.

🔍

File + Database Scanner

Scans both the filesystem and the WordPress database — catching rogue admins, wp_options injections, SEO spam, and persistence backdoors that file-only scanners miss.

Auto-Remediation with Rollback

One-click fixes with timestamped backups. If anything goes wrong, CleanShift rolls back automatically. 4 minutes vs 3 hours of manual cleanup.

📧

Email Security Scanner

SPF, DKIM, and DMARC validation. Blacklist checks across Spamhaus, Barracuda, and SpamCop. Know when your server IP is listed before your clients complain.

🔌

Plugin Auto-Updater

Safe update pipeline: backup → update → verify site loads → rollback on failure. Update all outdated plugins across your fleet in one operation.

🗺️

Fleet Dashboard

One screen for every server. Cross-server threat map, health grades, and bulk scan-all. Built for agencies and hosting providers managing dozens of servers.

📅

Scheduled Scans

Set cron-based schedules per server. Daily, weekly, or custom. Security score trending over time so you can see if you're improving.

🤖

AI Threat Analysis

Confidence scoring on every detected threat. Reduces false positives and helps prioritize what to fix first. Built on your crowd-sourced threat intelligence.

📖

Custom Playbooks

Build remediation playbooks matched to specific CVEs. Run them on-demand or trigger automatically when a matching threat is detected.

🌐

Joomla & Drupal Support

The scanner adapts to the CMS it finds. WordPress gets the deepest analysis, but Joomla and Drupal installs are also scanned and reported.

🛡️

SSL Monitor

Tracks certificate expiry across all sites on your server. Get alerted before a certificate lapses and takes a site down.

🏥

Server Health Dashboard

PHP version, disk usage, MySQL health, and cPanel/Plesk panel status — all in one view. Spot problems before they become incidents.

🔄

Migration Orchestrator

Pre-migration security clearance scan. Flags junk files, active threats, and missing .htaccess before you move an account. Post-migration verification built in.

Pricing

Pay per site. No server tax.

One price per WordPress site — not per server. A server with 50 sites costs what 50 sites cost. Volume discounts kick in automatically as you grow.

Free

₹0/forever

1 site. Detect everything. Fix when ready.

  • Full scan (file + database)
  • Vulnerability scanning
  • 30-day scan history
  • Telegram alerts
  • mu-plugin guard
Start Free
Most Popular

Starter

₹99/site/mo

1–10 sites. Freelancers & solo devs.

  • Everything in Free
  • Auto-remediation with rollback
  • AI threat analysis
  • CVE playbooks
  • Scheduled scans
  • Fleet dashboard
  • Plugin auto-updater
Get Started

Agency

₹69/site/mo

11–50 sites. For agencies & consultants.

  • Everything in Starter
  • 30% volume discount
  • Multi-client fleet view
  • White-label reports
  • Email security scanner
  • Joomla &amp; Drupal support
Get Agency

Reseller

₹49/site/mo

51–200 sites. Hosting resellers & MSPs.

↓ ₹29/site for 200+ sites (Provider).

  • Everything in Agency
  • 50% volume discount
  • WHMCS billing integration
  • Migration orchestrator
  • Custom playbooks
  • Dedicated onboarding
Contact Sales via WhatsApp

The maths: 30 sites × ₹69 = ₹2,070/month. One hacked site costs ₹5,000–50,000 in lost revenue & cleanup. CleanShift pays for itself on the first prevention.

FAQ

Common questions

Is CleanShift only for WordPress?

CleanShift is designed primarily for WordPress on shared hosting (cPanel/WHM, Plesk). The agent scans any WordPress installation it finds on the server. Non-WordPress CMS support (Joomla, Drupal) is included in paid plans.

Does CleanShift remove malware or just detect it?

The free tier detects and reports threats with step-by-step manual fix instructions. Paid plans add one-click auto-remediation with timestamped backups and rollback safety.

Why does the agent need root access?

Server-level scanning requires access to all user home directories and database credentials. The agent only reads during scanning — write operations happen only during explicit remediation. All source code is open source and auditable.

Will it slow down my server?

The agent uses ~1.2MB of RAM and scans run as low-priority background processes. No inbound ports are opened. There is zero impact on website load times.

How does per-site pricing work?

You pay per WordPress site, not per server. One server with 50 sites counts as 50 sites. Volume brackets apply automatically — 11+ sites drop to ₹69/site, 51+ to ₹49/site, 200+ to ₹29/site.

What happens when a threat is detected?

You receive a detailed report showing exactly what was found, where, and how to fix it. On paid plans, CleanShift can auto-remediate with timestamped backups and full rollback capability.

Built by people who manage real servers.

CleanShift is built by Kamyab Infotech — a team that runs hosting infrastructure, cleans malware from production servers, and manages WordPress at scale. This tool exists because we needed it ourselves.

Request Early Access

Not ready to deploy yet? Join the waitlist to get exclusive updates and priority access to new enterprise features.