BashEdge for cPanel & WHM

Complete cPanel security.
Keep every hosted site online.

BashEdge combines a Web Application Firewall, application-layer DDoS protection, network firewall and intrusion prevention for every account on your cPanel server, managed directly from WHM.

One-command install No reboot or downtime Starts in monitor mode
LIVE PROTECTIONAttack activity
Lockdown Mode
Attacks blocked1,284in the last 24 hours
Attack sources638184 coordinated
Requests inspected2.4Macross all accounts
Sites protected486all sites online
Attacks blocked over timeLast hour · by minute
846Blocked
Blocked by attack typeTop detections · last hour
100%Contained
Native WHM pluginEvery cPanel account protectedNo separate security consoleAutomatic rule updates

One attacked site can take hundreds of customers offline.

On a shared cPanel server, every account depends on the same Web server capacity. A request flood or compromised application aimed at one domain can slow down every site. BashEdge contains hostile traffic before one customer's problem becomes a server-wide outage.

18,420/minHostile requests detected612/minVerified traffic passed
Hostile request volume falling sharply at the BashEdge protection boundary while verified traffic remains stable before the Web server
How BashEdge works with cPanel

Stop hostile traffic before it becomes Web server load.

BashEdge protects the shared request path instead of treating every website as an isolated problem. Attacks are contained before they consume Apache workers, PHP processes or capacity needed by other cPanel accounts.

INTERNET TRAFFICVisitors, bots and attacks
BASHEDGEInspect · verify · contain Hostile traffic stops here
01
EA-NginxProxy and static traffic, when enabled
02
Apache + PHPDynamic application requests
CPANEL ACCOUNTS
Every hosted domain
1. Inspect

Evaluate each request using its source, rate, path, method, application behavior and maintained attack rules.

2. Decide

Pass trusted visitors, verify suspicious clients and stop confirmed attacks before application processing.

3. Explain

Record the rule, reason, source and targeted domain so the hosting team can see exactly what happened in WHM.

One cPanel security platform

Protect the websites, network and logins your customers depend on.

One BashEdge installation covers every account and domain while keeping each protection layer visible and controllable inside WHM.

Stop attacks across every hosted site

More than 50 maintained Web Application Firewall rules stop SQL injection, remote code execution, file inclusion, credential probing, webshell uploads and other application attacks.

Keep sites online during request floods

BashEdge identifies high-rate clients, distributed scans, hostile bots and clients rotating identities before they consume the Web server.

Protect every server login

Repeated attacks against WHM, cPanel, Webmail, phpMyAdmin, SSH, FTP, Exim and database services are blocked at the network layer.

Control inbound and outbound traffic

Open, close or restrict ports and ranges without wiping the firewall rules already protecting your cPanel server.

Apply protection that understands the application

WordPress, Joomla and Drupal receive protection for their own login, enumeration and abuse patterns instead of one generic ruleset.

See proof directly in WHM

Trace every threat to its source, network, country, campaign and targeted account without opening a separate security console.

Web Application Firewall for cPanel

Stop the attacks that target websites, not just ports.

BashEdge maintains more than 50 attack rules and updates them automatically. Every hosted domain is protected against common application attacks without asking each customer to configure a separate website firewall.

Injection and execution: SQL injection, command injection, code injection, framework exploits and PHP configuration attacks.Files and credentials: traversal, file inclusion, exposed configuration files, cloud credentials, backups and database dumps.Persistent access: webshells and PHP backdoors uploaded into media or upload directories.Modern applications: XSS, SSRF, NoSQL injection, insecure deserialization, GraphQL abuse and parameter pollution.
APPLICATION PROTECTION50+ maintained rules
Injection and execution
SQL injectionRemote code executionCommand injectionHeader injection
Files and credentials
Directory traversalCredential probingWebshell uploadBackup hunting
Application abuse
Cross-site scriptingSSRFGraphQL probingOpen redirect
Rules update automatically without a restart
Application-aware protection

Protect each CMS against the attacks aimed at it.

A WordPress login attack is not the same as Joomla component probing or Drupal module enumeration. BashEdge applies protection that understands the application behind each domain.

WP

WordPress protection

Stop login brute force, user and plugin enumeration, XML-RPC abuse and REST API batch probing.

J!

Joomla protection

Protect administrator logins and stop automated component enumeration across hosted sites.

D

Drupal protection

Contain login brute force and module enumeration before they become repeated server load.

Protection during an active attack

Lockdown Mode puts the whole server behind visitor verification in one click.

Protect every hosted site, or only the domain being targeted. Legitimate visitors and verified search engines continue through while automated attack traffic is held back.

  • Activate for one site or every cPanel account
  • Run it for a fixed time or until you turn it off
  • Keep legitimate crawlers and allowlisted services moving
LIVE PROTECTIONLockdown Mode
ACTIVE
SERVER STATUSAttack contained

New visitors are being verified before reaching hosted sites.

Lockdown Mode is active now
184hostile sources contained
486hosted sites protected
Protection scopeAll hosted domains
DurationUntil disabled
Beyond the Web Application Firewall

Protect the rest of the cPanel server too.

Website attacks are only part of the problem. BashEdge also controls network access, protects server logins and gives you precise rules for unusual traffic.

01

Network firewall

Control inbound and outbound traffic by direction, protocol, port, source range and exception. Existing firewall rules stay in place.

02

Intrusion prevention

Set thresholds and block durations independently for WHM, cPanel, SSH, FTP, Exim, Webmail, databases and phpMyAdmin.

03

Custom rules and rate limits

Control traffic by path, method, country, network, address, user agent, status or request rate. Rules can watch, verify or block and expire automatically.

Rule impact previewMONITOR MODE
Remote code execution32 matches in the last 24 hoursWatch
Credential file probing148 matches in the last 24 hoursVerify
SQL injection61 matches in the last 24 hoursBlock
No customer traffic changedReview false positives →
Safe by default

See what BashEdge would stop before it changes traffic.

Protection begins in monitor mode. Review the impact of every rule against traffic from your own server, allowlist trusted addresses and services, then choose watch, verify or block when you are ready.

Every rule is individually controllable Trusted traffic can never be affected Resource limits protect server stability
Live threat visibility

Go from a traffic spike to the exact attack.

See the source, network, country, rule, reason, targeted domain and action taken without leaving WHM.

WhenAddressActionRuleReasonHost hit
18:42:09203.0.113.47Blockedcredential-file-probeRequested environment and cloud credential filesstorefront.example
18:41:56198.51.100.22Verifieddistributed-request-rateCoordinated high-rate requests across 18 pathsportal.example
18:41:31192.0.2.18Blockedquery-sql-injectionRequest contained SQL injection in the URLbilling.example
18:40:58203.0.113.91Blockedweb-brute-forceRepeated WordPress login and user enumerationnewsroom.example
All domains, addresses, traffic volumes and events shown here are synthetic demonstration data.
Native cPanel and WHM integration

Protection for every account on your cPanel server.

BashEdge installs as a WHM plugin, understands Apache and EA-Nginx automatically, and gives hosting teams per-account and per-domain visibility.

Protect cPanel, Webmail and phpMyAdmin logins Protect Exim, SSH, FTP and database services Work alongside the firewall rules already in place Built and tested on servers carrying 2,000+ domains
WHMSecurity Center / BashEdge Protection active
BASHEDGE SECURITYServer protection
486 domains covered
100%covered
All protection layers activeWeb, network and login protection cover every hosted account. Last rule update 3 minutes ago
Web Application FirewallActive50+ attack rules
Network firewallActiveNo conflicts found
Intrusion preventionActive8 services watched
Application DDoSActive184 sources contained
Protection that stays current

Less security work for every server you manage.

New attack patterns are delivered automatically. Protection survives restarts and upgrades, and if BashEdge ever stops it never leaves the server blocking customer traffic.

AutomaticRule and product updates
No restartNew protection arrives live
Fleet-awareAttacks seen once strengthen every protected server
Fails safeCustomer traffic is never left blocked
cPanel security questions

What server owners ask before enabling protection.

Will BashEdge slow down a busy shared server?

BashEdge is resource-capped so it cannot destabilise a busy shared server. It is built and tested on cPanel servers carrying more than 2,000 domains.

Will the Web Application Firewall break my customers’ sites?

Protection begins in monitor mode and changes no traffic. You see what each rule would have done against traffic from your own server, allowlist trusted services, and activate rules only when you are ready.

Does BashEdge conflict with my existing firewall?

No. BashEdge detects conflicts and works alongside the firewall already on the server. It never wipes your existing rules.

How long does installation take?

Installation uses one command and requires no reboot or planned downtime. BashEdge is then managed as a native plugin inside WHM.

Does BashEdge protect WordPress, Joomla and Drupal?

Yes. Each application receives protection for its own attack patterns, including login brute force and enumeration. WordPress protection also covers XML-RPC abuse and REST API batch probing.

Can I protect only the site being attacked?

Yes. Lockdown Mode can cover one targeted site or every account on the server, for a fixed time or until you turn it off.

Keep every cPanel account online.

Evaluate BashEdge against traffic from your own server. Monitor first, review every rule, then activate protection when you are ready.

Start free trial