cxs was ConfigServer’s commercial scanner and, unlike CSF, nobody forked it: the licence server went away with the company and installs stopped updating their signatures in September 2025. A scanner with year-old signatures is a false sense of security. The replacement most providers land on is Linux Malware Detect (maldet) using ClamAV as its scanning engine, optionally alongside ImunifyAV for the cleanup and reporting that maldet does not do. This guide sets that up and maps each cxs feature to its replacement.
Table of Contents
Short answer: Remove cxs and its Apache include, install ClamAV (the WHM plugin on cPanel, EPEL elsewhere), then install Linux Malware Detect from rfxn.com with scan_clamscan="1" and quarantine_hits="1" in conf.maldet. Run maldet --monitor users as a service to replace cxs upload scanning, keep the daily cron for scheduled sweeps, and add the free ImunifyAV where automated cleanup of injected code is needed.
Remove cxs
Stop the watch daemon, remove the cron entries and the WHM plugin, and delete the package:
systemctl disable --now cxswatch 2>/dev/null
rm -f /etc/cron.d/cxs-cron /etc/cron.daily/cxs*
/etc/cxs/uninstall.sh 2>/dev/null || rm -rf /etc/cxs /usr/sbin/cxs
grep -rl cxs /etc/httpd/conf.d/ /usr/local/apache/conf/ 2>/dev/null
The last command finds the Apache or ModSecurity include that hooked cxs into upload scanning. Remove that include and restart the web server, or every upload will fail once the binary is gone.
Install ClamAV
ClamAV supplies the signature engine. On AlmaLinux 9 and 10 it comes from EPEL; on cPanel, install it as the WHM plugin so the panel manages the daemon and signature updates:
dnf install -y epel-release
dnf install -y clamav clamav-update clamd
freshclam
systemctl enable --now clamav-freshclam clamd@scan
On cPanel, use WHM, then cPanel, then Manage Plugins, tick ClamAV Scanner and save; that installs the cpanel-clamav package and the daemon socket at /var/cpanel/clamd.sock or /var/clamd. Check which socket your build uses before configuring maldet:
ls -la /var/clamd /var/cpanel/clamd.sock /run/clamd.scan/clamd.sock 2>/dev/null
Install maldet
cd /root
curl -fsSLO https://www.rfxn.com/downloads/maldetect-current.tar.gz
tar xzf maldetect-current.tar.gz
cd maldetect-*/ && ./install.sh
maldet -u
The installer places the configuration at /usr/local/maldetect/conf.maldet. Set these lines so maldet uses ClamAV’s engine (which is several times faster than its own), quarantines rather than only reports, and emails findings:
email_alert="1"
email_addr="security@example.net"
scan_clamscan="1"
quarantine_hits="1"
quarantine_clean="0"
scan_ignore_root="1"
inotify_user="root"
quarantine_clean="0" is deliberate: automatic cleaning of injected PHP is unreliable and a half-cleaned file breaks the customer’s site in ways that are harder to diagnose than an intact infected one. Quarantine, notify, then clean by hand or with ImunifyAV.
Run a first sweep of all home directories to establish a baseline:
maldet -a /home/?/public_html
maldet --report list
Replace cxs’s upload scanning
cxs’s headline feature was scanning files as they were uploaded through PHP or FTP. maldet does this with its inotify monitor, which watches directories for new files and scans each one on arrival:
maldet --monitor users
systemctl enable --now maldet
--monitor users watches every home directory. On a server with many thousands of sites, inotify watch limits become the constraint; raise fs.inotify.max_user_watches in sysctl.d to a few million and confirm memory is acceptable. For FTP uploads, that is sufficient. For PHP uploads, the inotify path also catches them, because the file lands on disk before the application moves it.
Scheduled scans
maldet installs a daily cron in /etc/cron.daily/maldet that scans files modified in the last day and updates signatures. That replaces cxs’s daily scan. For a full weekly sweep, add:
0 3 * * 0 root /usr/local/maldetect/maldet -b -a /home/?/public_html >/dev/null 2>&1
-b backgrounds it and the report is emailed on completion.
Where ImunifyAV fits
ImunifyAV is the scanner component of Imunify360 and is free in its basic form on cPanel, DirectAdmin and plain Linux, with the paid ImunifyAV+ tier (repriced in August 2026) adding one-click cleanup and scheduled per-user scans in the panel. It uses CloudLinux’s signature database, which is tuned to shared-hosting malware and updates faster than the community feeds maldet relies on. Its cleanup engine is the reason to add it: it removes injected code from a file while leaving the legitimate content in place, which maldet cannot do.
The two coexist without conflict, provided only one is set to quarantine automatically. A common arrangement is maldet with inotify for real-time detection and quarantine, plus ImunifyAV for weekly full scans and cleanup. Install ImunifyAV from the CloudLinux installer script and check its status:
imunify-antivirus rstatus
imunify-antivirus malware on-demand start --path /home
If you later buy Imunify360, its own WAF and proactive defence replace the need for inotify scanning; see the Imunify360 tuning guide.
Common pitfall. Running the first full scan at midday on a busy server. A ClamAV pass over a terabyte of small PHP files consumes a core and saturates disk reads for hours. Use nice -n 19 ionice -c3 in the cron line, run the baseline overnight, and set scan_max_filesize in conf.maldet so large media files are skipped.
Verify
Drop the EICAR test string into a watched directory and confirm maldet catches it within seconds and quarantines it:
printf 'X5O!P%%@AP[4\\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*' > /home/testuser/public_html/eicar.txt
sleep 10
maldet --report list | head -3
ls /usr/local/maldetect/quarantine/
Then confirm the email arrived and that the daily cron ran by checking /usr/local/maldetect/logs/event_log the next morning. Signature freshness matters as much as coverage; maldet -u and freshclam should both show recent update timestamps, and our server security audit script flags a server where either is more than three days old.
Cxs replacement at a glance

Official documentation: Imunify360 documentation, cPanel & WHM documentation, AlmaLinux wiki.
Related guides: CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.
Frequently asked questions
Is maldet with ClamAV free for commercial hosting servers?
Yes. Linux Malware Detect is released under the GPL and ClamAV is open source, so both run on any number of servers without a licence. ImunifyAV’s basic scanner is also free; only ImunifyAV+ and Imunify360 are paid.
Does maldet scan uploads in real time like cxs did?
Yes, through its inotify monitor. maldet --monitor users watches every home directory and scans each new file on arrival, which covers FTP and PHP uploads alike; on very large servers raise fs.inotify.max_user_watches so the monitor can cover every path.
Can I keep using cxs with its old signatures?
The binary still runs, but the licence server and signature feed are gone, so it detects nothing written since September 2025 and blocks nothing new. Treat it as removed and replace it rather than relying on stale detection.