Defensia runs alongside Plesk Obsidian's native tools. It auto-discovers all your vhost access logs, extends fail2ban's basic protection with a full WAF engine, scans vhost directories for malware, and surfaces CVE advisories — all from a single dashboard.
Start FreeComplementary security — not a replacement for Plesk, a deep extension of it.
Auto-discovers every domain under /var/www/vhosts/system/*/logs/access_log. Full OWASP WAF engine applied to each domain — SQL injection, XSS, RCE, and path traversal detection with per-request scoring.
Monitors /var/log/auth.log (Debian/Ubuntu) and /var/log/secure (RHEL/CentOS) for failed SSH logins including Plesk SSH users. Escalating bans with configurable thresholds.
Plesk ships fail2ban but it's reactive and config-heavy. Defensia adds WAF-scored bans, a real-time dashboard, cross-server ban propagation, and CVE-aware context that fail2ban can't provide.
OWASP Core Rule Set engine scored per request per domain. Detects SQLi, XSS, RCE, SSRF, path traversal, .env probing, and scanner fingerprints (sqlmap, nikto, nuclei). Works with both nginx and Apache proxies.
Recursively scans all vhost directories (/var/www/vhosts/) for backdoors, web shells, and injected PHP. Detects obfuscated code, base64 payloads, and known malware signatures. Real-time progress per domain.
Checks all installed packages against NVD + EPSS + CISA KEV databases. Surfaces exploitable CVEs affecting your Plesk version, PHP builds, and OS packages with severity and patch guidance.
Plesk stores per-domain logs under /var/www/vhosts/system/. Defensia finds and monitors every one — no configuration needed.
HTTPS log variants (proxy_access_ssl_log) auto-merged. New domains added in Plesk are detected automatically — no agent restart needed.
Plesk ships solid baseline security. Defensia fills the gaps that Plesk's native tools don't cover.
Imunify360 and Plesk's own ModSecurity extension are the common alternatives. Here's how they compare.
| Feature | Defensia | Plesk ModSecurity Ext. | Imunify360 |
|---|---|---|---|
| Price (per server) | €9/mo | ~$10/mo (ext.) | $12–45/mo |
| Plesk required | No (any Linux) | Yes | Yes (cPanel/Plesk) |
| Vhost log auto-discovery | Yes | No | Yes |
| WAF engine | OWASP CRS scoring | ModSecurity (manual) | ModSecurity |
| SSH brute force | 15 patterns + journald | Via fail2ban | PAM module |
| Malware scanner | Full (YARA + signatures) | ImunifyAV (basic) | Full (paid) |
| CVE scanning | NVD + EPSS + CISA KEV | No | No |
| Real-time dashboard | Included | Plesk panel only | Included |
| Multi-server view | Included | No | Separate product |
| Open source agent | Yes (MIT) | No | No |
Every layer of a Plesk server covered — web, system access, and ongoing vulnerability tracking.
No. Defensia and Plesk's fail2ban instance run independently. Defensia does not touch fail2ban's jail.conf or its iptables rules. Both can protect SSH simultaneously. You can disable Plesk fail2ban if you want to simplify, or leave both running — there is no conflict.
Yes. Plesk Obsidian uses nginx as a reverse proxy in front of Apache by default. Defensia reads the access_log files that Apache writes — these contain the real client IPs including Plesk's X-Forwarded-For headers. The WAF engine parses both CLF and combined log formats automatically.
Defensia globs /var/www/vhosts/system/*/logs/access_log and also picks up proxy_access_ssl_log variants. Both HTTP and HTTPS traffic is covered. New domains added in Plesk are detected on the next polling cycle — no restart required.
No. The Defensia agent is a standard Go binary that runs as a systemd service. It reads log files directly from the filesystem. No Plesk API key, no extension marketplace installation, and no Plesk panel access is needed.
Yes. The malware scanner recursively scans /var/www/vhosts/ on demand or on schedule. It detects obfuscated PHP, base64-encoded payloads, known web shell signatures, and injected eval() chains — regardless of how the file was uploaded.
The current Defensia agent supports Linux only (Debian, Ubuntu, RHEL, CentOS, AlmaLinux, and Rocky Linux). Plesk for Windows is not supported at this time.
The agent queries the system package manager (apt or rpm) to enumerate installed software and versions. This includes Plesk-distributed PHP builds, Plesk panel packages (plesk-core, sw-cp-server), and all OS packages. Matches run against NVD, EPSS, and CISA's Known Exploited Vulnerabilities catalog.
ImunifyAV is bundled with Plesk Obsidian and provides basic malware scanning (detection only — removal requires a paid upgrade). Defensia's malware scanner runs independently, supports YARA rules, and is included in the Pro plan alongside the WAF, CVE tracking, and alerts. No separate scanner subscription needed.
One command. The agent finds all your vhosts, activates the WAF, and starts monitoring — no Plesk extension, no API key, no configuration file to edit.
Start Free See Pricing