A Plesk malware scanner built around subscriptions, domains and live PHP.
Find malware and hidden backdoors across every Web root. Watch new files as they appear, stop dangerous PHP execution with Live Defense and patch vulnerable WordPress plugins without losing the subscription behind the alert.

A file path is not enough when one server contains many customers and applications.
Plesk organizes hosting around customers, subscriptions, domains and application roots. A useful security product should keep that structure visible. Otherwise an administrator is left translating a long filesystem path before deciding who owns the site and which service may have been exposed.
BashSecure links malware findings, live PHP events, integrity changes and vulnerable plugins to their Plesk context. The administrator can move from the server view to the affected subscription without mixing unrelated domains into the same incident.
Protection begins with evidence. Scans report what they find, filesystem monitoring observes new files and Live Defense can start in Log mode. File quarantine, runtime termination and automated response remain deliberate actions controlled by the server operator.
Inspect the dangerous behavior before it reaches the hosted application.
Requests may pass through a proxy and Web server before dynamic PHP work begins. BashSecure keeps the runtime event connected to the script, domain and subscription where it occurred.
Review the server without flattening every site into one list.
BashSecure presents security status by subscription and domain, while still giving the Plesk administrator a complete server view.
Interface preview. All subscription and domain names are fictional examples.
Inspect what a file contains, even when its extension tells a different story.
BashSecure examines PHP, JavaScript, HTML and other Web content for malware, backdoors and Web shells. An attacker cannot make executable content harmless by naming it like an image. Teams comparing a Plesk virus scanner get content-aware website inspection tied to the correct subscription and domain.
Changed-file scanning
Use fast incremental checks for normal protection instead of rereading every unchanged Web root.
Scheduled server sweeps
Run a complete review in a controlled window and retain the result for each intended path.
Subscription boundaries
Keep files, findings and policy associated with the Plesk subscription that owns them.
No false all clear
When a scan cannot finish, the result remains incomplete rather than being displayed as clean.

See the request that tried to compromise the subscription.
Scheduled scanning finds evidence already stored on disk. Live Defense observes PHP while it executes and records the request context behind dangerous behavior. When an approved Kill policy is active, the hostile request can be aborted before it completes the action.
Available but inactive
Keep runtime protection disabled for a subscription that is not ready.
Observe first
See the source, URL, script and subscription without terminating the request.
Stop selected behavior
Abort a confirmed dangerous runtime action and retain the event for investigation.
Contain the affected subscription without hiding what changed.
Safe Plesk malware removal should preserve evidence and recovery options. BashSecure separates detection from action so operators can confirm a finding before changing a customer file or runtime policy.
Reversible quarantine
Move a confirmed malicious file outside the Web root without deleting it, while preserving path, ownership and permissions for restoration.
Subscription scan
Review the affected subscription after a live event suggests that the attacker may have written more than one file.
Attack attribution
Connect the source address and requested URL to the script, domain and subscription where dangerous behavior began.
Source response
Optionally challenge or block the attacking address through the companion firewall integration.
False-positive control
Trust an exact file or checksum for one subscription or across the server after administrator review.
Patch follow-up
Flag vulnerable application software so cleanup leads to a fixed entry point instead of another reinfection.
Patch the exposed plugin, not only the malware it allowed.
BashSecure inventories supported WordPress plugins inside Plesk subscriptions and compares installed versions with published vulnerability information. The result distinguishes affected, unaffected, unknown and unsupported states. A vulnerable plugin is reported as exposure, not mislabeled as an infection.
When a supported official update exists, BashSecure saves the current plugin before any replacement. The recognized release is downloaded and verified against published checksums, then checked again after installation. Individual rollback remains available if the update changes site behavior.
Fictional software, subscription and domain shown for demonstration.
Keep modified core files separate from confirmed malware.
BashSecure can compare WordPress, Joomla and Drupal core files with the official release. A difference may indicate a hidden backdoor, but it can also be a customization or version mismatch. Integrity results remain their own evidence category so the administrator can review the context before approving an official restore.
WordPress core comparison
Report missing and modified core files against the relevant official package.
Evidence without an automatic malware verdictJoomla and Drupal integrity
Review supported CMS core changes across Plesk domains from the same server workflow.
Multiple application familiesOptional official restore
Replace a confirmed modified core file only when the operator chooses the official version.
Controlled remediationGive the server administrator the overview and keep each subscription distinct.
Security teams need server-level coverage. Customer and reseller boundaries still matter during investigation and recovery.
Coverage across Plesk
Review scan completion, findings, vulnerable plugins, Live Defense events, quarantine and response history across hosted subscriptions.
- Filter by subscription or domain
- Compare protection modes
- Review incomplete scans
- Control recovery actions
Focused incident context
Follow the affected Web root, application, file and request without exposing the data of unrelated hosted customers.
- Own domains and files
- Account-scoped evidence
- Clear operator decisions
- No cross-subscription leakage
Protect busy Plesk servers without making the scanner the busiest process.
Website traffic, PHP, databases, mail and backups already compete for server resources. BashSecure reduces repeat work through incremental scans, supports idle I/O priority and can throttle when the server becomes busy.
Full scans remain scheduled and operator controlled. Subscription-aware filtering also lets a team investigate one affected customer without forcing an immediate full-server sweep after every event.
Establish coverage before enabling active response.
Start with visibility, review real subscription activity and move into enforcement only where the evidence supports it.
Install on Plesk
Discover subscriptions, domains and application roots on the server.
Complete a baseline scan
Review malware and integrity state without changing customer files.
Observe live PHP
Use Log mode to understand runtime detections in their subscription context.
Approve responses
Enable Kill, quarantine, patching or source response by policy.
Licensing for one server or a hosting fleet.
Every plan runs the same malware scanning and Live Defense runtime protection. Pick a plan by how many hosting accounts you need to cover.
Up to 10 hosting accounts
- Malware scanning across every hosted account
- Live Defense runtime protection (Off, Log or Kill)
- Reversible quarantine
- Attack source, request and script attribution
- Up to 10 hosting accounts
- Unlimited domains
Unlimited hosting accounts
- Everything in Basic
- Vulnerability Patching for WordPress plugins
- Core file integrity monitoring
- Unlimited hosting accounts
- Unlimited domains
Price per server, per month, excluding VAT. Cancel anytime. Talk to us.
What to know before adding BashSecure to a Plesk server.
What is a Plesk malware scanner?
A Plesk malware scanner checks hosted website files for malicious code, backdoors and Web shells while retaining the subscription and domain that own each path. BashSecure adds real-time file monitoring, Live Defense, attribution, reversible quarantine and vulnerability patching.
Does BashSecure scan every Plesk subscription?
BashSecure is designed for server-wide coverage while organizing results by subscription and domain. Operators can review completion across the server and apply different monitoring or response policies where required.
Is BashSecure a Plesk virus scanner?
BashSecure provides the malware and malicious-file scanning people often seek with that phrase, but it is designed specifically for hosting Web roots, PHP applications and account-aware server security rather than as a general desktop antivirus.
Can BashSecure detect a backdoor saved as an image?
Yes. It evaluates file content rather than trusting the extension alone, allowing suspicious executable content to be identified even when the filename appears to describe an image or another harmless type.
Will BashSecure delete files automatically?
No. Detection is the safe default, and files are not silently deleted. A confirmed malicious file can be moved into reversible quarantine while its original path, ownership and permissions are retained for restoration.
How does Live Defense work on Plesk?
Live Defense observes PHP runtime behavior and associates an event with the source address, URL, script, domain and Plesk subscription. It can start in Log mode and only stop selected hostile behavior after the administrator enables Kill.
What does the Plesk vulnerability scanner check?
BashSecure inventories supported WordPress plugins and compares installed versions with published vulnerability information. Affected, unaffected, unknown and unsupported states remain distinct so uncertainty is not presented as safety.
Are vulnerability patches reversible?
Yes, for supported official updates. BashSecure saves the existing plugin, verifies the recognized release using published checksums and keeps individual rollback available if the update affects site behavior.
Does a vulnerable plugin mean the subscription is infected?
No. A vulnerable version is exposure that needs review or patching. BashSecure reports it separately because the presence of vulnerable software is not proof that malware has been installed.
Is BashSecure suitable for shared Plesk hosting?
Yes. It supports incremental scans, idle I/O priority, load-aware throttling and subscription-scoped investigation so protection can run alongside many hosted customers and normal server services.
Find malware in the right subscription. Stop the live attack. Patch the exposed plugin.
Bring scanning, runtime defense, attribution, quarantine and reversible vulnerability patching into one Plesk security workflow.