BashSecureFOR PLESK SERVERS

A Plesk malware scanner built around subscriptions, domains and live PHP.

Find malware and hidden backdoors across every Web root. Watch new files as they appear, stop dangerous PHP execution with Live Defense and patch vulnerable WordPress plugins without losing the subscription behind the alert.

Subscription-aware findings Observe before blocking Reversible recovery
BashSecure scanning a Plesk server, isolating malicious files and preserving healthy subscriptions and hosted domains
WEB ROOTS→SCANNED
HOSTILE PHP→STOPPED LIVE
PLUGIN EXPOSURE→PATCHED SAFELY
SUBSCRIPTION CONTEXT→PRESERVED
Plesk server malware protection

A file path is not enough when one server contains many customers and applications.

Plesk organizes hosting around customers, subscriptions, domains and application roots. A useful security product should keep that structure visible. Otherwise an administrator is left translating a long filesystem path before deciding who owns the site and which service may have been exposed.

BashSecure links malware findings, live PHP events, integrity changes and vulnerable plugins to their Plesk context. The administrator can move from the server view to the affected subscription without mixing unrelated domains into the same incident.

Protection begins with evidence. Scans report what they find, filesystem monitoring observes new files and Live Defense can start in Log mode. File quarantine, runtime termination and automated response remain deliberate actions controlled by the server operator.

BashSecure in the Plesk Web path

Inspect the dangerous behavior before it reaches the hosted application.

Requests may pass through a proxy and Web server before dynamic PHP work begins. BashSecure keeps the runtime event connected to the script, domain and subscription where it occurred.

INTERNET TRAFFICVisitors, bots and hostile requests
BASHSECUREInspect · attribute · stop Hostile execution ends here
01nginxProxy and static traffic
02Apache + PHPDynamic application requests
PLESK SUBSCRIPTIONSEvery hosted domain remains in context
File evidenceShow the exact path and content observed.
Request evidenceKeep the source, URL and executing script.
Plesk ownershipIdentify the subscription and hosted domain.
Subscription-aware administration

Review the server without flattening every site into one list.

BashSecure presents security status by subscription and domain, while still giving the Plesk administrator a complete server view.

BASHSECUREPlesk server overview
Protection reporting
ServerSubscriptionsFindingsLive DefensePatchingQuarantine
SCAN STATEComplete
LIVE DEFENSELog mode
RECOVERYReversible
store.examplesubscription: commerce-demo
Hidden executable content/httpdocs/media/header.png
Quarantined
portal.examplesubscription: portal-demo
Runtime command attempt/httpdocs/index.php
Observed live

Interface preview. All subscription and domain names are fictional examples.

Plesk malware scanner

Inspect what a file contains, even when its extension tells a different story.

BashSecure examines PHP, JavaScript, HTML and other Web content for malware, backdoors and Web shells. An attacker cannot make executable content harmless by naming it like an image. Teams comparing a Plesk virus scanner get content-aware website inspection tied to the correct subscription and domain.

Changed-file scanning

Use fast incremental checks for normal protection instead of rereading every unchanged Web root.

Scheduled server sweeps

Run a complete review in a controlled window and retain the result for each intended path.

Subscription boundaries

Keep files, findings and policy associated with the Plesk subscription that owns them.

No false all clear

When a scan cannot finish, the result remains incomplete rather than being displayed as clean.

BashSecure stopping a hostile request in the Plesk Web stack while legitimate traffic continues to healthy subscriptions
Live Defense for Plesk PHP

See the request that tried to compromise the subscription.

Scheduled scanning finds evidence already stored on disk. Live Defense observes PHP while it executes and records the request context behind dangerous behavior. When an approved Kill policy is active, the hostile request can be aborted before it completes the action.

OFF

Available but inactive

Keep runtime protection disabled for a subscription that is not ready.

LOG

Observe first

See the source, URL, script and subscription without terminating the request.

KILL

Stop selected behavior

Abort a confirmed dangerous runtime action and retain the event for investigation.

SOURCE203.0.113.51Documentation address
→
REQUEST/api/importSuspicious POST
→
SCRIPT/httpdocs/index.phpRuntime evidence
→
SUBSCRIPTIONportal.exampleFictional domain
Controlled incident response

Contain the affected subscription without hiding what changed.

Safe Plesk malware removal should preserve evidence and recovery options. BashSecure separates detection from action so operators can confirm a finding before changing a customer file or runtime policy.

01

Reversible quarantine

Move a confirmed malicious file outside the Web root without deleting it, while preserving path, ownership and permissions for restoration.

02

Subscription scan

Review the affected subscription after a live event suggests that the attacker may have written more than one file.

03

Attack attribution

Connect the source address and requested URL to the script, domain and subscription where dangerous behavior began.

04

Source response

Optionally challenge or block the attacking address through the companion firewall integration.

05

False-positive control

Trust an exact file or checksum for one subscription or across the server after administrator review.

06

Patch follow-up

Flag vulnerable application software so cleanup leads to a fixed entry point instead of another reinfection.

Plesk vulnerability scanner

Patch the exposed plugin, not only the malware it allowed.

BashSecure inventories supported WordPress plugins inside Plesk subscriptions and compares installed versions with published vulnerability information. The result distinguishes affected, unaffected, unknown and unsupported states. A vulnerable plugin is reported as exposure, not mislabeled as an infection.

When a supported official update exists, BashSecure saves the current plugin before any replacement. The recognized release is downloaded and verified against published checksums, then checked again after installation. Individual rollback remains available if the update changes site behavior.

✓Subscription and domain identifiedKnow exactly where the affected version runs.
✓Official package onlyDo not patch from an unknown archive or mirror.
✓Current version saved firstPreserve the files before the update begins.
✓Rollback remains individualReverse one plugin without changing other patches.
VULNERABILITY PATCHINGSubscription review
Verified update
SUBSCRIPTIONcommerce-demostore.example · fictional domain
checkout-blocksinstalled 4.2.0
Known vulnerabilityInput validation
Patch to 4.2.4
01Match exposure
02Save current
03Verify official
04Keep rollback

Fictional software, subscription and domain shown for demonstration.

CMS core integrity

Keep modified core files separate from confirmed malware.

BashSecure can compare WordPress, Joomla and Drupal core files with the official release. A difference may indicate a hidden backdoor, but it can also be a customization or version mismatch. Integrity results remain their own evidence category so the administrator can review the context before approving an official restore.

WordPress core comparison

Report missing and modified core files against the relevant official package.

Evidence without an automatic malware verdict

Joomla and Drupal integrity

Review supported CMS core changes across Plesk domains from the same server workflow.

Multiple application families

Optional official restore

Replace a confirmed modified core file only when the operator chooses the official version.

Controlled remediation
Plesk operational context

Give the server administrator the overview and keep each subscription distinct.

Security teams need server-level coverage. Customer and reseller boundaries still matter during investigation and recovery.

SERVER VIEW

Coverage across Plesk

Review scan completion, findings, vulnerable plugins, Live Defense events, quarantine and response history across hosted subscriptions.

  • Filter by subscription or domain
  • Compare protection modes
  • Review incomplete scans
  • Control recovery actions
SUBSCRIPTION VIEW

Focused incident context

Follow the affected Web root, application, file and request without exposing the data of unrelated hosted customers.

  • Own domains and files
  • Account-scoped evidence
  • Clear operator decisions
  • No cross-subscription leakage
Designed for hosting workloads

Protect busy Plesk servers without making the scanner the busiest process.

Website traffic, PHP, databases, mail and backups already compete for server resources. BashSecure reduces repeat work through incremental scans, supports idle I/O priority and can throttle when the server becomes busy.

Full scans remain scheduled and operator controlled. Subscription-aware filtering also lets a team investigate one affected customer without forcing an immediate full-server sweep after every event.

SCAN PROFILEPlesk hosting serverActive
Routine protectionChanged files
I/O priorityIdle
Server load risesThrottle
Full reviewScheduled
Example configuration. The server owner controls the final policy.
Controlled Plesk rollout

Establish coverage before enabling active response.

Start with visibility, review real subscription activity and move into enforcement only where the evidence supports it.

01

Install on Plesk

Discover subscriptions, domains and application roots on the server.

02

Complete a baseline scan

Review malware and integrity state without changing customer files.

03

Observe live PHP

Use Log mode to understand runtime detections in their subscription context.

04

Approve responses

Enable Kill, quarantine, patching or source response by policy.

BashSecure plans

Licensing for one server or a hosting fleet.

Every plan runs the same malware scanning and Live Defense runtime protection. Pick a plan by how many hosting accounts you need to cover.

Basic

Up to 10 hosting accounts

$12per month
Get BashSecure
  • Malware scanning across every hosted account
  • Live Defense runtime protection (Off, Log or Kill)
  • Reversible quarantine
  • Attack source, request and script attribution
  • Up to 10 hosting accounts
  • Unlimited domains
Most popular
Premium

Unlimited hosting accounts

$23per month
Get BashSecure
  • Everything in Basic
  • Vulnerability Patching for WordPress plugins
  • Core file integrity monitoring
  • Unlimited hosting accounts
  • Unlimited domains

Price per server, per month, excluding VAT. Cancel anytime. Talk to us.

Plesk malware scanner questions

What to know before adding BashSecure to a Plesk server.

What is a Plesk malware scanner?

A Plesk malware scanner checks hosted website files for malicious code, backdoors and Web shells while retaining the subscription and domain that own each path. BashSecure adds real-time file monitoring, Live Defense, attribution, reversible quarantine and vulnerability patching.

Does BashSecure scan every Plesk subscription?

BashSecure is designed for server-wide coverage while organizing results by subscription and domain. Operators can review completion across the server and apply different monitoring or response policies where required.

Is BashSecure a Plesk virus scanner?

BashSecure provides the malware and malicious-file scanning people often seek with that phrase, but it is designed specifically for hosting Web roots, PHP applications and account-aware server security rather than as a general desktop antivirus.

Can BashSecure detect a backdoor saved as an image?

Yes. It evaluates file content rather than trusting the extension alone, allowing suspicious executable content to be identified even when the filename appears to describe an image or another harmless type.

Will BashSecure delete files automatically?

No. Detection is the safe default, and files are not silently deleted. A confirmed malicious file can be moved into reversible quarantine while its original path, ownership and permissions are retained for restoration.

How does Live Defense work on Plesk?

Live Defense observes PHP runtime behavior and associates an event with the source address, URL, script, domain and Plesk subscription. It can start in Log mode and only stop selected hostile behavior after the administrator enables Kill.

What does the Plesk vulnerability scanner check?

BashSecure inventories supported WordPress plugins and compares installed versions with published vulnerability information. Affected, unaffected, unknown and unsupported states remain distinct so uncertainty is not presented as safety.

Are vulnerability patches reversible?

Yes, for supported official updates. BashSecure saves the existing plugin, verifies the recognized release using published checksums and keeps individual rollback available if the update affects site behavior.

Does a vulnerable plugin mean the subscription is infected?

No. A vulnerable version is exposure that needs review or patching. BashSecure reports it separately because the presence of vulnerable software is not proof that malware has been installed.

Is BashSecure suitable for shared Plesk hosting?

Yes. It supports incremental scans, idle I/O priority, load-aware throttling and subscription-scoped investigation so protection can run alongside many hosted customers and normal server services.

BASHSECURE FOR PLESK

Find malware in the right subscription. Stop the live attack. Patch the exposed plugin.

Bring scanning, runtime defense, attribution, quarantine and reversible vulnerability patching into one Plesk security workflow.