Column 1
Skip to content
Column 1

Install ImunifyAV on cPanel and WHM: Malware Scan Checklist

ImunifyAV dashboard in WHM for malware scan review and hosted-site maintenance

ImunifyAV can give a cPanel and WHM administrator a practical malware-review workflow, but it is not a substitute for keeping the server, WordPress, themes, and plugins current. This guide replaces the older Security Advisor installation shortcut with a current, root-admin process that protects hosted sites while scans and remediation are planned.

Who should use this guide

This workflow is for the server owner or an administrator with root-level control of a supported cPanel or WHM host. Individual cPanel users can review the results their host makes available, but they should not attempt to install or reconfigure a server-wide security product. Before scheduling work, confirm the operating system, cPanel support, available memory and disk capacity against the current ImunifyAV requirements and installation documentation.

Use the current vendor deployment instructions from a root administrator session instead of relying on an old WHM Security Advisor prompt. That keeps the installation source, package support, and licensing choice current. ImunifyAV is the free scanner tier; ImunifyAV+ and Imunify360 add features that may change the available scanning and cleanup options.

Plan the change before installing

  1. Choose a quiet maintenance window and tell account owners that security scanning may use disk and CPU resources.
  2. Confirm that the host has a tested recovery path for the sites it manages. A malware finding is not a reason to make an unreviewed bulk deletion.
  3. Review current cPanel and operating-system updates first. Start with the cPanel and WHM upgrade checklist when the host also needs platform maintenance.
  4. Record who can approve cleanup decisions and how customers should report an affected login, checkout, or site feature.

Install and verify the WHM integration

After the vendor-supported installation completes, sign in to WHM as an administrator and open the ImunifyAV interface. Confirm that the service is healthy, the malware scanner is available, and normal WHM administration still works. If the interface is missing or the host is not on a supported platform, stop and follow the vendor's compatibility guidance rather than forcing a package onto the server.

For hosting teams, the first success condition is visibility: the administrator can see the scanner state, the account context for a finding, and a history that can be reviewed with the customer. Do not treat an empty dashboard as proof that every hosted WordPress site is secure; it only shows what the installed scanner has reported.

Set a scan budget that respects production traffic

A full server scan can compete with backups, updates, databases, ecommerce traffic, and customer jobs. Start with conservative resource settings, schedule broad work away from peak activity, and watch the host during the first run. ImunifyAV documents CPU and I/O controls in its configuration reference; use the WHM interface or the vendor's current administration guidance to set a budget that fits the server.

When a server carries many accounts, begin with the account or site that has a confirmed concern, then widen the review deliberately. For recurring scans, check which cadence is available for the installed edition. The free tier and paid tiers do not offer identical scheduling choices.

Review findings before any cleanup

Each finding needs context. Review the affected account, file role, modification timing, and whether the file belongs to a managed WordPress core, theme, plugin, upload, custom application, or an administrator tool. A detection can be valuable evidence, but it is not permission to remove an entire directory or deactivate a production site without checking the impact.

  • For WordPress core, replace files through the supported WordPress update process.
  • For themes and plugins, compare the installed version with a trusted vendor or WordPress.org source and update or replace unsupported software.
  • For customer uploads or custom code, coordinate with the owner before making an irreversible change.
  • After remediation, test the public site, administrator login, forms, ecommerce checkout, scheduled tasks, and any integration that depends on the affected files.

Use the WordPress security update checklist when a finding leads to core, plugin, or theme patching. For a customer-facing cleanup plan, the WordPress Support hub groups the update, recovery, performance, and troubleshooting guidance that usually follows a malware review.

Protect privacy and customer trust

Scan reports can contain account names, file paths, and other operational details. Limit access to the people resolving the issue, summarize findings for customers without exposing another account's data, and keep support tickets focused on the affected service. Review the product's analysis and notification settings before enabling any option that shares suspicious files or sends automated notices.

Keep the server healthy after the first scan

Make scanner review part of normal hosting maintenance. Keep cPanel, the operating system, PHP, WordPress, and extensions updated; investigate unexpected resource pressure; and retest the customer journey after each confirmed cleanup. Pair the scan workflow with the disk and inode reporting guide so growing file counts or storage use are noticed before a maintenance window becomes an outage.

When to ask for help

Escalate when the scanner service will not stay healthy, a finding affects multiple accounts, cleanup would alter custom application code, or the host shows signs of a broader compromise. A safe response prioritizes containment, evidence preservation through approved operational processes, supported updates, and customer communication over hurried bulk actions.

Bottom line: install ImunifyAV using the current vendor-supported route, manage scan intensity carefully, review each finding in context, and verify the hosted sites after every approved change.