Imunify360 is a security suite that runs at the server level — enabled by default on every DoSieci hosting account. You don't install it, you don't configure it, and you usually don't even need to know it's there to benefit from its protection.
What exactly does Imunify360 do?
It's several mechanisms working together:
- Antivirus — scans the files on your account for known malware and webshells, meaning files someone is trying to plant to take control of the site.
- Web Application Firewall (WAF) — blocks common attack patterns, such as SQL injection attempts or malicious file uploads through a form, before the request even reaches WordPress.
- Brute-force attack protection — after several failed login attempts to WordPress, Plesk, or email, the attacker's IP address is temporarily blocked.
- Proactive Defense — watches how PHP scripts behave in real time and halts suspicious activity before it causes damage.
- Quarantine — an infected file is isolated rather than silently deleted, so nothing disappears without a trace.
What do you see in Plesk?
Most customers never need to look at the Imunify360 settings — it works in the background. If you want to check your account's scan status, you'll find the relevant security section in the Plesk panel. If something is detected and blocked, you'll usually get a notice from us or from the system itself explaining what happened.
What Imunify360 doesn't replace
No automatic security tool is 100% effective — new threats appear faster than the signatures needed to detect them. That's why the first line of defense remains regular updates to WordPress, your theme, and your plugins, along with unique passwords. If you suspect a break-in despite having Imunify360 active — for example, the site redirects elsewhere, warnings appear in Google Search Console, or you spot unfamiliar files — contact us instead of waiting for the system to catch the problem on its own.
