If you run a WordPress site with us, you may notice a new plugin appearing in your WordPress admin area called Imunify Security. This article explains what it is, why it's there, and what it does for your site.

What is it?

Imunify Security is the WordPress companion plugin for Imunify360, the malware detection and security platform we run on all our servers. We're rolling it out automatically to WordPress sites as part of an upgrade to our server-wide security protection.

You don't need to install anything yourself, and there's nothing to configure to benefit from it. The plugin is added automatically so that the protection already running at server level is visible and useful directly from your WordPress dashboard.

Why we're doing this

Our servers already scan every WordPress installation for malware around the clock and clean up infections automatically where possible. Until now, that work happened entirely behind the scenes — you'd only hear from us if something needed your attention.

The Imunify Security plugin changes that by bringing real, useful visibility into your own WordPress dashboard, plus an extra layer of protection that works from inside WordPress itself. In short: your site gets better protected, and you get to see it happening.

What the plugin does

Security status at a glance

A dashboard widget shows your site's current security status, including recent scans and a clear record of any malware that was found and cleaned, with the file path and timestamp. No more wondering whether your site has been checked recently — it's right there when you log in.

An extra firewall layer built for WordPress

The plugin adds a Web Application Firewall that works specifically with WordPress. It watches for known, published vulnerabilities in the exact plugins, themes, and WordPress core version installed on your site, and blocks attempts to exploit them — without touching any of your site's files. This is often called "virtual patching": it buys you protection against a known vulnerability even before you've had the chance to update the affected plugin or theme.

This sits alongside the server-level protection we already provide (ModSecurity and Imunify360 itself) — it doesn't replace it, it adds another layer specifically tuned to WordPress.

Smarter handling of bot traffic

Every WordPress site receives constant automated traffic — search engine crawlers, AI/LLM crawlers, and less welcome bots probing for weaknesses. The plugin can identify and rate-limit this traffic before WordPress even finishes loading, cutting down on unnecessary load on your site while leaving real visitors completely unaffected.

Will this slow my site down or change how it looks?

No. The plugin does not alter your site's design, content, or front-end performance for genuine visitors. Its dashboard and notices are only visible to logged-in WordPress users, primarily administrators.

Do I need to do anything?

No action is required. The plugin is installed and maintained by us as part of your hosting service, and there's no cost to you. If you're curious, simply log in to your WordPress dashboard and look for the Imunify Security widget.

If you'd prefer not to have the extra WordPress-level firewall active on your site, you can turn it off from within the plugin itself, unless we've set it as mandatory at server level. If you have questions about your specific setup, open a ticket with our support team and we'll be glad to help.

More information

For full technical detail on the plugin, including how the firewall and bot protection work, please see CloudLinux's official documentation: Imunify Security Plugin for WordPress.

Updated by SP on 28/07/2026

Was this answer helpful? 0 Users Found This Useful (0 Votes)