Table of Contents
The problem it solves
Shared hosting security is not about your server; it is about the one customer who installed a nulled theme in 2022 and never updated it. That site gets a web shell, the web shell sends spam, the IP gets blacklisted, and every other customer’s mail bounces. Imunify360 is built for exactly that failure mode: find the malware, stop it running, and block the traffic that put it there.
In practice
We have run it on cPanel/CloudLinux servers for several years. The malware scanner is the best we have used on PHP: it decodes the eval(base64_decode(...)) layers that fool signature scanners, and its cleanup removes the injected code from a legitimate file instead of deleting the file and breaking the site. Proactive Defense is the feature that justifies the subscription: it hooks PHP execution and kills known-malicious behaviour (mass mailers, backconnect shells) even from files the scanner has not flagged yet.
The firewall side is a mixed bag. WebShield’s challenge page stopped a run of bot floods that used to exhaust MaxRequestWorkers, and the shared blocklist means new servers start with the IPs that attacked older ones already greylisted. But greylisting is enthusiastic: a customer whose office runs an old scanner plugin gets their IP challenged and calls support. The whitelist works; you will use it.
Resource use is fine day to day and noticeable during full scans on a 300-account server; schedule them at night. The dashboard is clear, the CLI (imunify360-agent) is complete, and it coexists with CSF if you keep CSF for port rules and let Imunify handle the reputation side.
Alternatives
Free: ClamAV plus maldet for scanning, CSF+LFD for brute force, and ModSecurity with the OWASP CRS. That combination covers less than Imunify does out of the box and needs more of your time. Paid: BitNinja (similar scope and price), and Imunify’s own cheaper tier, ImunifyAV+, which is only the scanner.
Imunify360 plans and prices
Prices last checked: 30 September 2026. USD, per server licence, before tax. Vendors change prices; confirm at checkout.
| Plan | Hosting accounts | Price per year | Effective per month |
|---|---|---|---|
| Single user | 1 | $144 | ≈ $12 |
| Up to 30 users | 2 to 30 | $300 | ≈ $25 |
| Up to 250 users | 31 to 250 | $420 | ≈ $35 |
| Unlimited users | More than 250 | $540 | ≈ $45 |
Every plan has the same feature set (firewall, WAF, malware scanner, proactive defence) and a 30-day money-back guarantee; the only difference is how many hosting accounts the server holds. Volume pricing applies from 5 servers. If you only need malware scanning, ImunifyAV+ starts at about $7 a month. A shared hosting server with 100 accounts sits in the “up to 250” tier, which works out at roughly $0.35 per account per month.
Verdict
Four stars because the price and the greylisting false positives are real costs. If you run a shared server, the first compromised-account clean-up it prevents pays for the year. If you run your own applications on a VPS and keep them updated, spend the money on backups instead.
Imunify360 review at a glance



Official documentation: cPanel & WHM documentation, Linux man pages.
Related guides: Fix WordPress “cURL error 28: Failed to connect” caused by Imunify360 or CSF · Whitelist IPs and countries in Imunify360 from the CLI · Imunify360 in 2026: WAF by default, L7 rate limiting and Under Attack Mode tuning.
Frequently asked questions
Is Imunify360 worth it for shared hosting?
On shared servers with many customer sites it usually pays for itself by stopping malware-driven spam and blacklistings.
What is the difference between Imunify360 and ImunifyAV?
ImunifyAV is the malware scanner; Imunify360 adds the WAF, proactive defence, patching and firewall features.
Can Imunify360 replace CSF?
It includes a firewall and brute-force protection, so many hosts run it instead of CSF. Do not run two firewalls that manage iptables at once.