MegaWit Shield (MWS) finds and removes webshells, backdoors and injected code in real time — everything ConfigServer eXploit Scanner (cxs) did, plus auto-disinfection, proactive runtime defense, cloud threat intelligence and a full WHM dashboard.
Signature, heuristic, ClamAV and cloud detection — combined with real-time watching, upload blocking and runtime defense.
On-access (inotify) detection flags malware the instant a file is created, modified or uploaded — not just on a schedule.
Strips injected malicious blocks and keeps your legitimate code. Every clean is backed up and fully reversible.
A PHP guard refuses to execute a known-malicious script at runtime — stopping attacks even before removal.
A ModSecurity hook inspects uploads and rejects malicious files before they ever hit the disk.
A curated signature DB, optional ClamAV, and a consensus-backed cloud hash feed shared across every protected server.
Verifies WordPress core against official checksums and scans MySQL/WordPress tables for injected payloads.
Live stats, event feed, per-account threat view, quarantine with restore, scheduled scans — in 5 languages.
Each cPanel account gets its own scan tile — customers can check their own site, safely scoped to their home.
Email, Slack, Telegram & webhooks — instant or daily digest, branded HTML mail, plus license-expiry reminders.
Manage protection, review threats and run scans right from WHM — no SSH required.
ConfigServer eXploit Scanner (cxs) is discontinued and never cleaned or gave you a dashboard. Here's how MWS compares.
| Capability | MegaWit Shield | ConfigServer cxs | Imunify360 |
|---|---|---|---|
| Real-time on-access scanning | ✓ | ✓ | ✓ |
| Upload-time blocking | ✓ | ✓ | ✓ |
| Automatic malware clean-up | ✓ | ✗ | ✓ |
| Proactive runtime (PHP) defense | ✓ | ✗ | ✓ |
| Cloud threat intelligence | ✓ | ✗ | ✓ |
| WordPress & database scanning | ✓ | ✗ | ✓ |
| Full WHM dashboard + end-user plugin | ✓ | ✗ | ✓ |
| Actively maintained | ✓ | Discontinued | ✓ |
| One-time (lifetime) license option | ✓ | ✓ | ✗ |
| Price | $74.25/yr | ~$60/yr | $$$ higher |
No credit card. The trial activates automatically on first install — one per server.
SSH into your cPanel/WHM server (CentOS 7+, CloudLinux, AlmaLinux, Rocky, Ubuntu or Debian).
This installs the agent, downloads signatures, sets up real-time protection and cron scans, and starts your 15-day trial automatically.
Go to WHM » Plugins » MegaWit Shield. You'll see live protection status, run scans, and manage everything from there — no command line needed after this.
Buy a key, then paste it in WHM » MegaWit Shield » Settings » License — no SSH required. It binds to this server and unlocks continuous protection after the trial.
No per-account fees. Protect every cPanel account on the server for one flat price.
Yes. cxs is discontinued, and MWS is a modern, drop-in replacement. It does everything cxs did — real-time and upload scanning — and adds automatic clean-up, proactive runtime defense, cloud threat intelligence, WordPress/database scanning and a full WHM dashboard.
Run the one-line installer and a 15-day trial activates automatically — one per server, no credit card. When you're ready, paste a license key in the WHM panel to continue.
One license = one server, with unlimited cPanel accounts. The license binds to the server automatically on activation (by a hardware fingerprint, not just an IP). You can move it to another server anytime from your billing panel.
CentOS 7+, CloudLinux, AlmaLinux, Rocky Linux, Ubuntu and Debian. The agent is a single static binary with no dependencies.
No. The agent is lightweight, event-driven (inotify) and written in Go. Full scans are scheduled off-peak and heuristics are tuned to avoid false positives on legitimate WordPress and plugin code.
Only for the initial install command. After that, activate your license and manage everything from the WHM panel — no SSH needed.
Start a free 15-day trial in minutes, or grab a license and protect every account on your server today.