Free checklist · No signup, no gated download

WHM Server Security Checklist

A practical, no-fluff checklist for hardening a WHM/cPanel server β€” the firewall, ModSecurity, SSH, account hygiene, backups, and monitoring. Everything is on this page; there's nothing to download and no form to fill in. Work top to bottom and you'll close the gaps attackers probe first.

Why this matters

Most WHM breaches start with the basics left undone

Weak SSH exposure, a firewall left at defaults, a stale account, no working backup. None of it is exotic β€” which is exactly why it's worth a methodical pass.

A cPanel/WHM server is a big attack surface: every hosted site, every mailbox, and root itself. Attackers rarely need a novel exploit β€” they scan for open SSH on port 22, brute-force weak passwords, hit outdated web apps, and look for servers with no monitoring so their activity goes unnoticed. This checklist walks the fundamentals in a sensible order. Treat it as a recurring audit, not a one-time task: run it after any migration, and revisit it every few months.

The checklist

14 things to lock down on every WHM server

Grouped by area. Each item is real, actionable, and uses features cPanel/WHM and CSF actually provide.

🧱 Firewall & CSF

  • Install and configure a host firewall (CSF/LFD).

    Deploy ConfigServer Security & Firewall (CSF) and enable LFD. Take CSF out of TESTING mode once your rules are correct, and open only the ports you actually need (WHM, cPanel, mail, SSH, web).

  • Turn on Login Failure Daemon (LFD) brute-force protection.

    LFD watches auth logs and temporarily blocks IPs after repeated failed logins to SSH, cPanel, FTP, and mail. Confirm it is enabled and that its alert email goes to an inbox you read.

  • Allowlist your own admin IPs before tightening rules.

    Add your static admin IP(s) to csf.allow first, so hardening the firewall can never lock you out of your own server.

πŸ›‘οΈ ModSecurity & web attacks

  • Enable ModSecurity with a maintained rule set.

    Turn on the WHM ModSecurity vendor and keep an actively maintained rule set enabled so common web attacks (SQLi, XSS, scanners) are filtered at the web-server layer.

  • Review ModSecurity hits, don't just enable and forget.

    Periodically read the audit log to spot which domains are being probed and to catch false positives before they break a legitimate site.

  • Keep cPanel, WHM, and all software on the latest stable tier.

    Set cPanel to auto-update on a stable/release tier and keep PHP versions and web apps patched. Unpatched software is the most common way in.

πŸ” SSH & root

  • Disable direct root SSH login and use key-based auth.

    Set PermitRootLogin no (or prohibit-password), disable password authentication in favour of SSH keys, and use a strong passphrase on the key.

  • Move SSH off port 22 and restrict access.

    Change the SSH port and, where practical, restrict it to known admin IPs via the firewall. This alone removes the bulk of automated brute-force noise.

  • Use strong, unique passwords and enable 2FA on WHM.

    Enforce a strong password policy and enable two-factor authentication for WHM/root and reseller logins.

πŸ‘€ cPanel accounts

  • Audit accounts and remove stale ones.

    Review the account list regularly. Suspend or terminate accounts that are no longer in use β€” dormant accounts with old, vulnerable apps are a favourite foothold.

  • Enforce password strength and disable unused services per account.

    Require strong passwords for cPanel/FTP/email, and turn off features (shell access, unused FTP accounts) that an account doesn't need.

πŸ’Ύ Backups

  • Configure automated, off-server backups and test a restore.

    Use WHM Backup Configuration to run scheduled backups to a remote destination β€” a backup you have never restored is a backup you don't have. Test a real restore periodically.

πŸ“Ÿ Monitoring & alerting

  • Watch load, disk, and security events β€” and make alerts reach you.

    Keep an eye on system load and disk usage, and ensure firewall/LFD and ModSecurity signals are actually surfaced somewhere you look, not just written to a log nobody reads.

  • Correlate attacks per domain and catch repeat offenders.

    Go beyond raw logs: know which sites are being targeted and which IPs keep coming back, so you can block or harden before an incident escalates.

Staying on top of it

How Safety Monitor Pro helps you stay on top of this checklist

Several items above are ongoing β€” they need visibility, not a one-time flip of a switch. That's the part Safety Monitor Pro handles: it reads the signals your server already produces and puts them in one native WHM dashboard.

πŸ”Ž

Reviewing ModSecurity hits

Parses the ModSecurity audit log into a readable, per-domain feed of web attacks β€” so "review your hits" becomes a glance instead of a grep session.

🧱

Understanding CSF blocks

Reads your CSF/LFD state and surfaces block and allow reasons in plain language. It complements CSF; it does not replace your firewall.

🚨

Catching repeat offenders

Correlates activity to highlight brute-force attempts and repeat-offender IPs, so the "catch repeat offenders" item is handled for you.

🌍

Seeing attacker origin

A self-contained country and ASN database shows where traffic comes from and supports country-based rules through CSF β€” no external API key.

βš–οΈ

Load safety

Load Guard watches load average and high-consumption users. By design it never kills services or site PHP and never suspends accounts β€” it surfaces and advises.

πŸ”

Never locking yourself out

On first entry it offers to allowlist your current admin IP β€” the same allowlist-yourself-first rule this checklist opens with.

Safety Monitor Pro installs as a native WHM plugin (AppConfig) with no external agent, and runs alongside suites like Imunify360 and CloudLinux without competing for the same enforcement layer. (No partnership or certification is implied.)

Turn the ongoing items into a single dashboard

Safety Monitor Pro keeps the monitoring items on this checklist visible inside WHM. Instant activation after payment. Pay with Stripe or PayPal. Full pricing is on the product page.

Questions? We answer engineer-to-engineer during business hours (8 AM – 8 PM GMT).

Chat with us β†’