Imunify360 is a security layer that is active by default on the hosting environment and protects your website against malware, brute-force attacks, and vulnerable scripts. You don’t need to install anything: it runs at server level and is visible via Plesk. In this article you’ll learn how to view and configure the main components, and what to do if something gets blocked.
What Imunify360 does exactly
Imunify360 combines multiple security features in one system. It scans files for malware, blocks suspicious login attempts, filters malicious traffic with a firewall, and checks whether installations such as WordPress or other CMSs contain vulnerable plugins. Everything happens automatically in the background, so your website stays protected without you needing to actively manage it.
Opening and configuring Imunify360 in Plesk
In Plesk, you’ll find Imunify360 as a separate menu item in the left-hand menu of your subscription. From there you get access to the dashboard with an overview of scans, blocks, and the status of your domains. Most default settings are already optimally configured, but it’s useful to know where you can adjust them.
Log in to Plesk
Go to your Plesk environment and sign in with your account details.
Open Imunify360
Click Imunify360 in the left-hand menu to open the security dashboard.
Review the overview
Check the tab with notifications and scans to see if anything has been blocked recently.
Adjust settings if needed
For example, set up email notifications so you’re automatically informed of suspicious activity.
Would you prefer us to review the settings with you? That’s possible via the knowledge base or by contacting support.
Malware scans and cleanup
Imunify360 periodically scans website files for malware. If the system finds a suspicious file, it is flagged in the dashboard, along with the file name and location. In many cases, Imunify360 also offers an option to automatically disinfect the file or place it in quarantine.
When you get a notification, always first check whether the file belongs to your own CMS or theme, or whether it’s an unknown file added through a vulnerability. Then update your CMS, themes, and plugins, since outdated software is the most common cause of an infection.
Managing blocked IPs and exceptions
If Imunify360 detects repeated failed login attempts or suspicious behavior from an IP address, it is temporarily blocked. This can sometimes also affect your own IP address, for example if you’ve entered the wrong password several times yourself.
In the Imunify360 dashboard you’ll find an overview of blocked IP addresses. You can remove an IP address from the block list yourself or add it to a whitelist so it is never blocked again. This is useful if you work from a fixed office address.
Not sure whether a block is justified, or can’t figure it out yourself? Then contact Tandata’s 24/7 support via WhatsApp, ticket, or email; help is available even at night.
Frequently asked questions
Does Imunify360 cost extra?
No, Imunify360 is included by default with the hosting environment and requires no separate installation or license from you.
My own IP address is blocked, what now?
Go to the Imunify360 dashboard in Plesk, look up the IP address in the block list, and remove it or add it to the whitelist.
Imunify360 has flagged a file as malware, but it’s my own file
Check whether the file actually belongs to your website. If so, you can restore it or mark it as an exception in the dashboard.
Does Imunify360 also protect my domain name against abuse?
Imunify360 secures the hosting account and the website itself. Separate settings apply to the registration and protection of your domain names, such as a domain lock.
Can I switch providers without losing security data?
Yes, when switching to Tandata, Imunify360 becomes active immediately on your new environment, independent of your previous hosting provider.
Conclusion
Imunify360 runs by default on your hosting environment and automatically protects your website against malware and suspicious traffic. Via Plesk you can immediately view the dashboard, check notifications, and release IP addresses or add them to the whitelist. If you get stuck, Tandata’s support team is available 24/7.