Unexpected ports and hostile sources
Control inbound and outbound traffic while keeping your current firewall rules intact.
Protect every subscription across the full request path. BashEdge combines a server firewall, Plesk WAF, application-layer DDoS protection and intrusion prevention in one native extension.

A Plesk server does more than accept traffic on ports 80 and 443. Requests pass through nginx, Apache or PHP, reach different applications, and share the same CPU, workers and network capacity.
A network firewall controls who can connect. ModSecurity inspects Web requests. BashEdge connects these layers with server-wide rate intelligence, visitor verification, application-aware rules and evidence tied to the subscription being targeted.
Control inbound and outbound traffic while keeping your current firewall rules intact.
Inspect requests before they reach WordPress, Joomla, Drupal or a custom application.
Contain request floods before a targeted subscription affects every hosted customer.
BashEdge sits across the request path rather than protecting a single website in isolation. It separates hostile automation from legitimate visitors before expensive application work begins.
Requests are evaluated against source reputation, rate, path, method, application behavior and maintained attack rules.
Trusted traffic passes. Suspicious visitors can be watched or verified. Confirmed attacks are blocked.
Every action records the rule, reason and target so the hosting team can understand exactly what happened.
Plesk security is strongest when each layer has a clear job. BashEdge is designed to work alongside the controls already on the server, not erase them.
A valid connection can still carry an application attack. A valid-looking Web request can still be part of a distributed flood. BashEdge correlates behavior across requests, sources and subscriptions.
Traditional port rules cannot distinguish a customer from a bot repeatedly requesting expensive application paths. BashEdge identifies high-rate clients, coordinated sources, rotating identities and distributed request patterns.
More than 50 maintained rules cover common and emerging Web attacks. CMS-aware controls add context for the applications hosting teams see every day.
SQL injection, command injection, code execution, framework exploits and PHP configuration attacks.
Traversal, file inclusion, exposed environment files, cloud credentials, backups and database dumps.
Webshells and PHP backdoors uploaded into media directories or other writable application paths.
XSS, SSRF, NoSQL injection, deserialization, GraphQL abuse and parameter pollution.
Protect hundreds of customer domains without asking each account owner to install or tune a separate security product.
Keep managed client websites available and trace an incident to the exact domain, rule and source.
Contain login attacks, XML-RPC abuse, enumeration and request floods before they consume shared workers.
Protect the Plesk panel, Web applications, mail, SSH, FTP and database services from one place.
Move from a server alert to the source, action, detection rule, reason and targeted subscription. Synthetic data below demonstrates the level of context available.
18:42:09Blockedcredential-file-probeRequested environment and cloud credential filesshop.example18:41:56Verifieddistributed-request-rateCoordinated request burst across 18 pathsportal.example18:41:31Blockedquery-sql-injectionSQL injection pattern found in the URLbilling.exampleBashEdge discovers the Plesk layout, understands nginx and Apache, and brings every protection layer into the panel your hosting team already uses.
BashEdge is resource-capped, preserves existing firewall rules and fails safe. If the service ever stops, it does not leave customer traffic trapped behind stale blocking decisions.
BashEdge brings the Plesk firewall, Web Application Firewall, application-layer DDoS protection, intrusion prevention and live threat evidence into one server-wide workflow. It protects the request path before hostile traffic consumes the Web server or a hosted application.
Yes. BashEdge can run alongside your existing Plesk ModSecurity configuration. You can keep the controls already in place while adding maintained application rules, visitor verification, rate controls and clearer threat context.
It does not require you to discard working firewall rules. BashEdge detects the existing configuration and adds centrally managed network controls without wiping the rules already protecting the server.
BashEdge detects high request rates, coordinated clients, hostile bots and repeated attack patterns at the application layer. Lockdown Mode can verify new visitors for one targeted domain or all hosted subscriptions while trusted traffic continues.
Yes. BashEdge discovers the Plesk Web server layout automatically, including the nginx-to-Apache request path, so protection can be applied without asking each subscription owner to configure a separate service.
Yes. Threat activity links the source, network, country, detection rule, action and targeted host. Hosting teams can move from a server load spike to the affected domain and attack pattern without leaving Plesk.
Protection starts in monitor mode and changes no customer traffic. You can preview rule matches, allowlist trusted services and activate each rule as watch, verify or block after reviewing its impact on your server.
Installation uses one command and requires no reboot or planned downtime. After installation, BashEdge is managed as a native Plesk Extension.
Start in monitor mode, review BashEdge against traffic from your own server, and activate protection when you are ready.
Start free trial