The WHM Security Plugin that lives inside your server
Safety Monitor Pro installs directly into WHM and turns the signals your server already produces — ModSecurity, CSF/LFD, cPanel access logs, system load — into one live security dashboard. No external agent, no data leaving your box.
Your WHM server already knows it's under attack. You just can't see it.
A default WHM install scatters its security signals across half a dozen logs and tools. ModSecurity writes cryptic audit entries, CSF and LFD email you deny notices, cPanel logs the hits, and load average spikes without explanation. Piecing that together during an incident — across dozens of accounts — is slow, manual, and easy to get wrong.
Most "security plugins" for shared hosting either bolt on a heavy external agent, ship their own conflicting firewall, or phone your server's data out to a third-party cloud. That adds moving parts, license overhead, and a new attack surface — the opposite of what a busy sysadmin wants. What's missing is simple: a single, native place inside WHM that reads what's already there and tells you what's happening right now.
A WHM security plugin built the way WHM actually works
Written in PHP, installed via AppConfig, running inside your existing WHM — here is what it does, honestly.
Native, agentless install
Installs as a standard WHM plugin (AppConfig). There is no resident daemon and no external agent to keep patched — it reads the logs and state your server already generates.
Live intrusion monitoring
Parses the ModSecurity audit log into a readable, per-domain view of web attacks — brute-force attempts, repeat offenders, and which sites are being probed, updated on page load.
CSF / LFD firewall visibility
Reads your CSF state and surfaces block and allow reasons in plain language. It complements CSF — it does not replace your firewall.
GeoIP country blocking
A self-contained country and ASN database (no external API key) lets you see attacker origin and apply country-based firewall rules through CSF.
Load Guard
Watches load average and high-consumption users. Its hard rule: it never kills services or site PHP and never suspends accounts — it surfaces and advises, it does not act destructively.
Never-block-self
On first entry it offers to allowlist your current admin IP, so tightening the firewall can never lock you out of your own server.
Runs alongside suites like Imunify360 and CloudLinux without competing for the same enforcement layer — it focuses on visibility and load safety. (No partnership or certification is implied.)
See your WHM server's security in one dashboard
Instant activation after payment. Payments are processed securely by our approved payment providers. Full pricing and the live demo are on the product page.
Questions? We answer engineer-to-engineer during business hours (8 AM – 8 PM GMT).