Complete cPanel security.
Keep every hosted site online.
BashEdge combines a Web Application Firewall, application-layer DDoS protection, network firewall and intrusion prevention for every account on your cPanel server, managed directly from WHM.
One attacked site can take hundreds of customers offline.
On a shared cPanel server, every account depends on the same Web server capacity. A request flood or compromised application aimed at one domain can slow down every site. BashEdge contains hostile traffic before one customer's problem becomes a server-wide outage.

Stop hostile traffic before it becomes Web server load.
BashEdge protects the shared request path instead of treating every website as an isolated problem. Attacks are contained before they consume Apache workers, PHP processes or capacity needed by other cPanel accounts.
Evaluate each request using its source, rate, path, method, application behavior and maintained attack rules.
Pass trusted visitors, verify suspicious clients and stop confirmed attacks before application processing.
Record the rule, reason, source and targeted domain so the hosting team can see exactly what happened in WHM.
Protect the websites, network and logins your customers depend on.
One BashEdge installation covers every account and domain while keeping each protection layer visible and controllable inside WHM.
Stop attacks across every hosted site
More than 50 maintained Web Application Firewall rules stop SQL injection, remote code execution, file inclusion, credential probing, webshell uploads and other application attacks.
Keep sites online during request floods
BashEdge identifies high-rate clients, distributed scans, hostile bots and clients rotating identities before they consume the Web server.
Protect every server login
Repeated attacks against WHM, cPanel, Webmail, phpMyAdmin, SSH, FTP, Exim and database services are blocked at the network layer.
Control inbound and outbound traffic
Open, close or restrict ports and ranges without wiping the firewall rules already protecting your cPanel server.
Apply protection that understands the application
WordPress, Joomla and Drupal receive protection for their own login, enumeration and abuse patterns instead of one generic ruleset.
See proof directly in WHM
Trace every threat to its source, network, country, campaign and targeted account without opening a separate security console.
Stop the attacks that target websites, not just ports.
BashEdge maintains more than 50 attack rules and updates them automatically. Every hosted domain is protected against common application attacks without asking each customer to configure a separate website firewall.
Protect each CMS against the attacks aimed at it.
A WordPress login attack is not the same as Joomla component probing or Drupal module enumeration. BashEdge applies protection that understands the application behind each domain.
WordPress protection
Stop login brute force, user and plugin enumeration, XML-RPC abuse and REST API batch probing.
Joomla protection
Protect administrator logins and stop automated component enumeration across hosted sites.
Drupal protection
Contain login brute force and module enumeration before they become repeated server load.
Lockdown Mode puts the whole server behind visitor verification in one click.
Protect every hosted site, or only the domain being targeted. Legitimate visitors and verified search engines continue through while automated attack traffic is held back.
- Activate for one site or every cPanel account
- Run it for a fixed time or until you turn it off
- Keep legitimate crawlers and allowlisted services moving
Protect the rest of the cPanel server too.
Website attacks are only part of the problem. BashEdge also controls network access, protects server logins and gives you precise rules for unusual traffic.
Network firewall
Control inbound and outbound traffic by direction, protocol, port, source range and exception. Existing firewall rules stay in place.
Intrusion prevention
Set thresholds and block durations independently for WHM, cPanel, SSH, FTP, Exim, Webmail, databases and phpMyAdmin.
Custom rules and rate limits
Control traffic by path, method, country, network, address, user agent, status or request rate. Rules can watch, verify or block and expire automatically.
See what BashEdge would stop before it changes traffic.
Protection begins in monitor mode. Review the impact of every rule against traffic from your own server, allowlist trusted addresses and services, then choose watch, verify or block when you are ready.
Go from a traffic spike to the exact attack.
See the source, network, country, rule, reason, targeted domain and action taken without leaving WHM.
credential-file-probeRequested environment and cloud credential filesstorefront.exampledistributed-request-rateCoordinated high-rate requests across 18 pathsportal.examplequery-sql-injectionRequest contained SQL injection in the URLbilling.exampleweb-brute-forceRepeated WordPress login and user enumerationnewsroom.exampleProtection for every account on your cPanel server.
BashEdge installs as a WHM plugin, understands Apache and EA-Nginx automatically, and gives hosting teams per-account and per-domain visibility.
Less security work for every server you manage.
New attack patterns are delivered automatically. Protection survives restarts and upgrades, and if BashEdge ever stops it never leaves the server blocking customer traffic.
What server owners ask before enabling protection.
Will BashEdge slow down a busy shared server?
BashEdge is resource-capped so it cannot destabilise a busy shared server. It is built and tested on cPanel servers carrying more than 2,000 domains.
Will the Web Application Firewall break my customers’ sites?
Protection begins in monitor mode and changes no traffic. You see what each rule would have done against traffic from your own server, allowlist trusted services, and activate rules only when you are ready.
Does BashEdge conflict with my existing firewall?
No. BashEdge detects conflicts and works alongside the firewall already on the server. It never wipes your existing rules.
How long does installation take?
Installation uses one command and requires no reboot or planned downtime. BashEdge is then managed as a native plugin inside WHM.
Does BashEdge protect WordPress, Joomla and Drupal?
Yes. Each application receives protection for its own attack patterns, including login brute force and enumeration. WordPress protection also covers XML-RPC abuse and REST API batch probing.
Can I protect only the site being attacked?
Yes. Lockdown Mode can cover one targeted site or every account on the server, for a fixed time or until you turn it off.
Keep every cPanel account online.
Evaluate BashEdge against traffic from your own server. Monitor first, review every rule, then activate protection when you are ready.
Start free trial