Feature

Panelica Shield: Built-In Malware Scanning for Every Hosting Account

Back to Blog
Managing servers the hard way? Panelica gives you isolated hosting, built-in Docker and AI-assisted management.
Start free

Panelica Shield is the malware scanner built into the Panelica hosting panel. It checks every file in your hosting accounts against the Linux Malware Detect (LMD) signature set, Panelica's own signatures and any file hashes you add, recognises official WordPress files by their release checksums, and shows the scan live in the browser while it runs. Infected files go to a quarantine where no website can execute them, and every one of them can be restored exactly as it was. Shield is included in the panel itself — there is no separate add-on to buy — and it is available from panelica-server 1.0.551 on the beta update channel.

3
signature sources: LMD, Panelica and your own hashes
6 h
interval between automatic LMD signature checks
3
scan types: quick, full and one folder
0
files moved automatically unless you turn it on

Why a Hosting Panel Needs Its Own Malware Scanner

On a web server, most malware does not arrive as a virus. It arrives as a PHP file: a web shell dropped into wp-content/uploads through an outdated plugin, a backdoor appended to a theme file, a mailer script hidden in an image folder. Generic antivirus engines were designed for email attachments and desktop files, and they are not very good at this. What works on hosting servers is a combination of hash signatures for known files, code-pattern signatures for known families of PHP malware, and a way to tell an official WordPress file from a modified one.

Panelica's previous scanner relied on heuristics, and when we measured it against real samples it missed too much. Shield replaces it completely with a signature engine designed for exactly this job. It does not touch ClamAV, which keeps running for mail as before.

What Shield Checks Every File Against

  • LMD signatures — the Linux Malware Detect set maintained by R-fx Networks, the de facto standard for PHP malware on shared hosting. Shield downloads it a few minutes after the panel starts, checks the published SHA-256 before using it, refuses an incomplete pack, and looks for updates every six hours.
  • Panelica signatures — shipped inside the panel binary and updated with every panelica-server release, so a server that cannot reach the LMD download servers is still covered.
  • Your signatures — the MD5 or SHA-256 of any file you know to be malicious. Shield reports every file with exactly that content.
  • WordPress release checksums — official WordPress core and plugin files are recognised as known good and skipped. A core file outside wp-content that differs from the official file of the installed version is reported as a modified core file, so you can compare it with the original.

Under the hood, the engine runs four kinds of rules: MD5 hashes, SHA-256 hashes, code patterns and combined rules. The Signatures tab shows how many of each are loaded and when the LMD set was last checked.

Panelica Shield Signatures tab showing the LMD signature set, Panelica built-in signatures and administrator hashes

The Signatures tab: LMD, Panelica's built-in signatures and your own hashes, with the engine breakdown and the last update check.

Three Ways to Scan

ScanWhat it readsWhen to use it
Quick scanThe website folders of every account: public_html and subdomainsThe fastest way to catch web shells and injected code
Full scanEvery file in the account home folders; domain logs, SSL keys and session files are skippedAfter an incident, or as the nightly scan
Custom scanOne folder — inside an account, or for the root administrator under /home, /var/www, /srv, /opt or /tmpChecking one site or one suspicious directory
Panelica Shield overview with protection status and the quick, full and custom scan options

The Shield page: protection status at the top, the three scan types below.

Watching a Scan Live

A scan does not run behind a spinner. As soon as it starts, the page switches to a live view fed over a WebSocket connection: files scanned, data read, read speed, folders, files skipped as known good, unreadable files and findings, plus the path being read right now. Findings appear in a live feed the moment they are found, not when the scan ends. You can stop a scan at any time; findings found so far are kept.

A full scan in progress in Panelica Shield with live counters for files, data, speed and findings

A full scan in progress: counters update in real time and findings appear in the live feed as they are found.

When the scan finishes, the status card summarises what needs attention: open threats, modified core files, files in quarantine, the number of protected accounts, and a 30-day trend of new findings.

Panelica Shield status card reporting three threats found with counters for open threats, modified core files and quarantine

After a scan on our test server with three planted samples: three open threats, nothing modified, nothing quarantined yet.

Reviewing a Finding

The Findings tab lists every finding with its file path, the signature that matched, the source (LMD, Panelica, custom or integrity check), size, when it was last seen and its status. Filters separate open findings from quarantined, deleted, resolved and files marked as safe, and a search box finds a path or signature name.

Panelica Shield findings list with file paths, LMD signature names and actions to view, quarantine, delete or mark as safe

Each finding shows the matching signature and its source. Actions: view, quarantine, delete or mark as safe.

Opening a finding shows what you need to decide without logging in over SSH: the owner (UID:GID), permissions, modification time, first and last time Shield saw it, SHA-256 and MD5 hashes, every signature that matched, and the beginning of the file with the matched lines highlighted. Findings that matched by hash have no excerpt, because the whole file content is the evidence.

Panelica Shield finding detail with file metadata, hashes and the matched lines highlighted in the file content

The finding detail: file metadata, hashes and the matched lines highlighted in the content.

Quarantine That You Can Undo

Quarantining a file moves it to a place where no website can run it and records where it came from. If it turns out to be a false positive, Restore puts it back at its original path with its original owner and permissions; Restore and mark as safe does the same and tells Shield not to report that exact content again. Deleting a quarantined copy is a separate, explicit step.

Panelica Shield quarantine list with the original location, signature, size and restore actions

Quarantined files keep their original location, so a restore is exact.

Marking a file as safe works by content, not by path: Shield stores the file's SHA-256 and skips that exact content for that account, or for every account if you choose so. If the file changes later, it is checked again.

Settings That Stay Conservative by Default

Every setting that could move a customer's file is off until you turn it on:

SettingDefaultWhat it does
Nightly scanOff (starts at 03:00 server time when enabled)A full scan of every account once a day
Quarantine threats automaticallyOffMoves signature matches to quarantine as soon as they are found; modified core files are never moved automatically
Notify on new threatsOnA panel notification when a scan finds new threats
Use LMD signaturesOnDownloads and updates the LMD set; Panelica's signatures and yours are always used
Maximum size to read per file50 MBCode patterns are searched up to this size; larger files are still matched by hash
Parallel readers4More is faster but puts more load on the disk (1 to 16)
Excluded pathsNoneA name such as node_modules, or a path relative to each home folder
Panelica Shield settings for the nightly scan, automatic quarantine, notifications, LMD, read size, parallel readers and excluded paths

Shield settings. Automatic quarantine shows a warning: a false positive takes the file out of the website until you restore it.

Who Can Use It

Out of the box, Shield is available to the root administrator. Access for administrators or resellers is granted through the panel's permission settings, and the scope is enforced on the server side: someone who can see only some accounts sees only those accounts' findings, folders and totals, even while a server-wide scan is running. A reseller watching the live view does not see which folder of another customer is being read.

Getting Started

1
Update to the beta channel — Shield ships with panelica-server 1.0.551 and panel-frontend 4.5.354 or later. Under Panel Settings › System Updates choose Stable + Beta, then apply the updates from Support › System Updates. Beta builds are for testing; try them on a server you can afford to experiment with first.
2
Wait for the signatures — open Security › Panelica Shield. The LMD set downloads by itself a few minutes after the panel starts; the Signatures tab shows its version.
3
Run a quick scan — it reads the website folders of every account and usually finishes fastest. Review the findings before quarantining anything.
4
Turn on the nightly scan — choose the hour, and decide whether automatic quarantine fits your servers. On servers with many customers, start with notifications only.
Shield is a scanner, not a firewall. It finds malicious files that are already on the disk. Keep ModSecurity, the firewall and plugin updates in place: they stop the upload in the first place, and Shield catches what got through.

Frequently Asked Questions

Is Panelica Shield an extra paid module?

No. It is part of the panel and does not need a separate license or add-on purchase.

Does Shield replace ClamAV?

No. ClamAV keeps scanning mail as before. Shield is a separate engine for website files, built around LMD signatures and WordPress checksums.

Can Shield delete a customer's file by mistake?

Not unless you allow it. Automatic quarantine is off by default, quarantine is reversible with the original owner and permissions, and permanent deletion is always a separate confirmation.

How often are the signatures updated?

Shield checks the LMD set for updates every six hours and can be told to check or re-download immediately from the Signatures tab.

What happens if the panel restarts during a scan?

The scan is marked as interrupted in the scan history, with the findings found up to that point kept. Start it again when the panel is back.

Will a large media library slow the scan down?

Code patterns are searched only in the first 50 MB of a file by default, and official WordPress files are skipped by checksum. You can also exclude folders such as caches or node_modules.

Related Reading on panelica.com

Security-first hosting panel

Stop bolting tools onto a legacy panel.

Panelica is a modern, security-first hosting panel — isolated services, built-in Docker and AI-assisted management, with one-click migration from any panel.

Zero-downtime migration Fully isolated services Cancel anytime
Share:
Atomic updates included.