BashEdge for Plesk

A Plesk firewall that protects more than ports.

Protect every subscription across the full request path. BashEdge combines a server firewall, Plesk WAF, application-layer DDoS protection and intrusion prevention in one native extension.

One command to install No reboot Monitor before blocking
BashEdge stopping hostile traffic before it reaches the nginx and Apache layers of a Plesk Web server and its hosted websites
Native Plesk Extensionnginx + Apache awareEvery subscription coveredExisting rules preserved
Plesk server security

Your server is a chain. Attackers only need one weak point.

A Plesk server does more than accept traffic on ports 80 and 443. Requests pass through nginx, Apache or PHP, reach different applications, and share the same CPU, workers and network capacity.

A network firewall controls who can connect. ModSecurity inspects Web requests. BashEdge connects these layers with server-wide rate intelligence, visitor verification, application-aware rules and evidence tied to the subscription being targeted.

NETWORK EDGE

Unexpected ports and hostile sources

Control inbound and outbound traffic while keeping your current firewall rules intact.

WEB LAYER

Injection, probing and application abuse

Inspect requests before they reach WordPress, Joomla, Drupal or a custom application.

SHARED CAPACITY

One domain consuming the whole server

Contain request floods before a targeted subscription affects every hosted customer.

How BashEdge works with Plesk

Stop hostile traffic before it becomes Web server load.

BashEdge sits across the request path rather than protecting a single website in isolation. It separates hostile automation from legitimate visitors before expensive application work begins.

INTERNET TRAFFICVisitors, bots and attacks
BASHEDGEInspect · verify · contain Hostile traffic stops here
01
nginxProxy and static traffic
02
Apache + PHPDynamic application requests
PLESK SUBSCRIPTIONS
Every hosted domain
1. Inspect

Requests are evaluated against source reputation, rate, path, method, application behavior and maintained attack rules.

2. Decide

Trusted traffic passes. Suspicious visitors can be watched or verified. Confirmed attacks are blocked.

3. Explain

Every action records the rule, reason and target so the hosting team can understand exactly what happened.

Plesk Firewall, ModSecurity and BashEdge

Keep the tools that work. Cover the gaps between them.

Plesk security is strongest when each layer has a clear job. BashEdge is designed to work alongside the controls already on the server, not erase them.

Why this matters

A valid connection can still carry an application attack. A valid-looking Web request can still be part of a distributed flood. BashEdge correlates behavior across requests, sources and subscriptions.

Security layerPrimary roleBest at
Plesk FirewallNetwork accessPorts, protocols and source rules
Plesk ModSecurityRequest inspectionRule-based Web attack detection
PLESK DDOS PROTECTIONTraffic under control LIVE
Hostile requests contained18,420/min
Unverified trafficVisitors challengedVerified traffic passed
486 subscriptions remain availableLockdown Mode is verifying new visitors before the Web server
Application-layer DDoS protection for Plesk

When requests are valid but the volume is not.

Traditional port rules cannot distinguish a customer from a bot repeatedly requesting expensive application paths. BashEdge identifies high-rate clients, coordinated sources, rotating identities and distributed request patterns.

  • Protect one domain or the entire server. Scope Lockdown Mode to the subscription under attack or every hosted site.
  • Keep trusted visitors moving. Allowlists and verified search crawlers continue without interruption.
  • Choose the duration. Run protection for a fixed incident window or until you disable it.
Web Application Firewall for Plesk

Protection that understands the application behind each domain.

More than 50 maintained rules cover common and emerging Web attacks. CMS-aware controls add context for the applications hosting teams see every day.

01

Injection and execution

SQL injection, command injection, code execution, framework exploits and PHP configuration attacks.

02

Files and credentials

Traversal, file inclusion, exposed environment files, cloud credentials, backups and database dumps.

03

Persistent access

Webshells and PHP backdoors uploaded into media directories or other writable application paths.

04

Application abuse

XSS, SSRF, NoSQL injection, deserialization, GraphQL abuse and parameter pollution.

Application-aware controlsWordPress login and XML-RPC abuseJoomla administrator and component probingDrupal login and module enumeration
Built for multi-site Plesk servers

One security workflow for every kind of hosted subscription.

Hosting providers

Protect hundreds of customer domains without asking each account owner to install or tune a separate security product.

Web agencies

Keep managed client websites available and trace an incident to the exact domain, rule and source.

WordPress servers

Contain login attacks, XML-RPC abuse, enumeration and request floods before they consume shared workers.

Business VPS servers

Protect the Plesk panel, Web applications, mail, SSH, FTP and database services from one place.

Threat evidence inside Plesk

See why a request was stopped, not just that an IP was blocked.

Move from a server alert to the source, action, detection rule, reason and targeted subscription. Synthetic data below demonstrates the level of context available.

TimeActionRule and reasonSubscription
18:42:09Blockedcredential-file-probeRequested environment and cloud credential filesshop.example
18:41:56Verifieddistributed-request-rateCoordinated request burst across 18 pathsportal.example
18:41:31Blockedquery-sql-injectionSQL injection pattern found in the URLbilling.example
All domains, events and traffic figures are synthetic demonstration data.
PLESKExtensions / BashEdge Connected
SERVER COVERAGEEvery subscription protected
100%covered
  • Web Application FirewallActive
  • Network firewallActive
  • Intrusion preventionActive
  • Application DDoSActive
Native Plesk Extension

Install once. Protect every subscription.

BashEdge discovers the Plesk layout, understands nginx and Apache, and brings every protection layer into the panel your hosting team already uses.

  1. 01Install with one commandNo reboot or planned downtime.
  2. 02Observe real trafficRules begin in monitor mode so nothing changes unexpectedly.
  3. 03Activate with evidenceReview matches, allowlist trusted services and choose the action for each rule.
Safe by default

Security should not become another availability risk.

BashEdge is resource-capped, preserves existing firewall rules and fails safe. If the service ever stops, it does not leave customer traffic trapped behind stale blocking decisions.

Monitor firstPreview what rules would do before changing traffic.
Control every ruleWatch, verify or block independently.
Preserve trusted trafficAllowlist services, networks and addresses.
Update without restartsNew protection arrives automatically.
Plesk security questions

What to know before protecting your server.

What does BashEdge add to Plesk security?

BashEdge brings the Plesk firewall, Web Application Firewall, application-layer DDoS protection, intrusion prevention and live threat evidence into one server-wide workflow. It protects the request path before hostile traffic consumes the Web server or a hosted application.

Can BashEdge run alongside ModSecurity in Plesk?

Yes. BashEdge can run alongside your existing Plesk ModSecurity configuration. You can keep the controls already in place while adding maintained application rules, visitor verification, rate controls and clearer threat context.

Does BashEdge replace the Plesk Firewall extension?

It does not require you to discard working firewall rules. BashEdge detects the existing configuration and adds centrally managed network controls without wiping the rules already protecting the server.

How does Plesk DDoS protection work?

BashEdge detects high request rates, coordinated clients, hostile bots and repeated attack patterns at the application layer. Lockdown Mode can verify new visitors for one targeted domain or all hosted subscriptions while trusted traffic continues.

Does it understand Plesk nginx and Apache configurations?

Yes. BashEdge discovers the Plesk Web server layout automatically, including the nginx-to-Apache request path, so protection can be applied without asking each subscription owner to configure a separate service.

Can I see which subscription is being attacked?

Yes. Threat activity links the source, network, country, detection rule, action and targeted host. Hosting teams can move from a server load spike to the affected domain and attack pattern without leaving Plesk.

Will enabling the WAF break customer websites?

Protection starts in monitor mode and changes no customer traffic. You can preview rule matches, allowlist trusted services and activate each rule as watch, verify or block after reviewing its impact on your server.

How is BashEdge installed on a Plesk server?

Installation uses one command and requires no reboot or planned downtime. After installation, BashEdge is managed as a native Plesk Extension.

Protect the full Plesk request path.

Start in monitor mode, review BashEdge against traffic from your own server, and activate protection when you are ready.

Start free trial