Emergency server help: get in touch

Imunify360 Missing from WHM: 4 Fixes

Restore the Imunify360 icon in WHM when the plugin is registered but disabled, the agent is stopped, the install was corrupted, or a cPanel update removed the plugin registration, using imunify360-agent enable-plugin and reinstall steps.

Published Updated 5 min read

Imunify360 normally appears as an icon under the Plugins section of WHM and as a menu entry in the left sidebar. When it disappears, the firewall may still be running perfectly underneath, or it may have stopped entirely; the interface gives no clue which. The causes fall into a handful of buckets: the plugin was deliberately or accidentally disabled, the agent service is down so the plugin refuses to render, the WHM plugin files were removed or corrupted by an interrupted install, or a cPanel upgrade rebuilt the plugin registry without the entry. Each has a quick check and a quick fix.

Short answer: Run imunify360-agent enable-plugin, log out of WHM and back in, and the icon usually returns; if not, restart the agent with systemctl restart imunify360 and check imunify360-agent rstatus. If the plugin files are missing or the install log shows a “file too short” error, re-download and rerun i360deploy.sh, which reinstalls the WHM plugin without touching the firewall’s data.

Check whether the plugin is disabled

Imunify360 keeps a plugin state separate from the agent. Support staff sometimes disable it to isolate a problem, and a scripted deployment may leave it off. Re-enable and check the agent state:

imunify360-agent enable-plugin
imunify360-agent rstatus
imunify360-agent version

Then log out of WHM completely and log back in, because the sidebar and plugin list are built at login. If the icon is present but clicking it shows a page stating the agent is not running, the plugin is fine and the service is the problem.

Restart a stopped agent

The agent service must be active for the WHM page to load anything:

systemctl status imunify360
systemctl restart imunify360
journalctl -u imunify360 --since "15 min ago" | tail -50

The journal shows whether the agent failed on startup, commonly because of a corrupt SQLite database after a disk-full event, an expired licence, or a Python dependency broken by an OS update. A licence problem shows in rstatus; a database problem shows as an integrity error in the log and is fixed with the agent’s own imunify360-agent doctor command, which collects diagnostics and repairs common issues. Disk space should be confirmed with df -h /var before anything else.

Re-register the WHM plugin

cPanel tracks third-party WHM plugins in its own registry. A major cPanel update, or a manual run of /usr/local/cpanel/scripts/install_plugin for another product, can leave Imunify360 unregistered even though its files are intact. Confirm the files exist and re-register:

ls -la /usr/local/cpanel/whostmgr/docroot/cgi/imunify/
ls /var/cpanel/apps/ | grep -i imunify
/usr/local/cpanel/scripts/install_plugin /usr/share/imunify360/cpanel/imunify360.tar.bz2 --theme jupiter

Adjust the archive path to what your build ships; find / -name "imunify360*.tar.bz2" 2>/dev/null locates it. If the directory under the WHM docroot is empty, the plugin was removed and a reinstall is the fastest route.

Reinstall the plugin cleanly

Download the deployment script fresh and rerun it. A message such as “file too short” during a previous install indicates a truncated download, often caused by a proxy or a full disk, and the resulting package is unusable:

cd /root
wget -O i360deploy.sh https://repo.imunify360.cloudlinux.com/defence360/i360deploy.sh
bash i360deploy.sh

The script detects the existing installation, verifies the packages and restores the WHM plugin. Licences, blocked lists, whitelists and WAF settings are stored in the agent’s database and survive the reinstall. If the deploy script itself fails to download, check outbound HTTPS from the server and any local CSF rule that might be blocking the repository host, then compare the file size with the one on the vendor site before running it. For ImunifyAV installations the equivalent script is imav-deploy.sh.

Verify

Log in to WHM and confirm the Imunify360 entry under Plugins opens the dashboard with the version shown in the footer. From the shell, imunify360-agent rstatus should report the licence as valid and imunify360-agent version should match the latest rollout stage for your server; if it is behind, see Update, force-update or roll back Imunify360. Check that systemctl is-active imunify360 imunify360-webshield prints active for both.

The common pitfall is assuming a missing icon means the firewall is off and hastily installing CSF or another firewall on top. Two firewalls managing the same iptables or nftables chains produce rules that fight each other and lock out legitimate traffic. Confirm the state of the agent first, and if you do need a temporary replacement, uninstall Imunify360 properly rather than running both.

Imunify360 missing from WHM at a glance

Imunify360 Missing from WHM summary card: Run imunify360-agent enable-plugin, log out of WHM and back in, and the icon usually returns; if not, restart the agent…
In short: Run imunify360-agent enable-plugin, log out of WHM and back in, and the icon usually returns; if not, restart the agent with systemctl restart imunify360 and check imunify360-agent rstatus.

Official documentation: Imunify360 documentation, cPanel & WHM documentation, Linux man pages.

Related guides: Fix WordPress “cURL error 28: Failed to connect” caused by Imunify360 or CSF · Whitelist IPs and countries in Imunify360 from the CLI · Imunify360 in 2026: WAF by default, L7 rate limiting and Under Attack Mode tuning.

Frequently asked questions

Does Imunify360 missing from WHM mean the firewall has stopped protecting the server?

Not necessarily. The WHM plugin is only the interface; the agent, WebShield and WAF continue running if the service is active, which systemctl status imunify360 and imunify360-agent rstatus confirm.

How long does reinstalling the Imunify360 plugin take?

Running enable-plugin and re-logging takes a minute. A full rerun of i360deploy.sh takes five to ten minutes depending on how many packages need to be re-downloaded.

Can I undo a plugin reinstall or restore a previous state?

Nothing needs undoing: the reinstall replaces only the interface files and packages. Whitelists, blacklists and settings remain in the agent’s database, which you can back up beforehand with imunify360-agent backup-systems or a copy of /var/imunify360/.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.