Comparisons
CXS alternatives in 2026: the honest field guide
ConfigServer closed on 31 August 2025. What replaced cxs, what the options cost as at 4 September 2026, and what runs on a stock CyberPanel host.
ConfigServer’s eXploit Scanner is the product most CyberPanel and cPanel operators used for this job, and it no longer exists. This is the field as it stands on 4 September 2026: what actually happened, what a stalled cxs installation means in practice, and what the replacements cost.
Prices below were read from each vendor’s own pricing page on 4 September 2026. They move; re-check before you budget.
What happened, precisely
Way to the Web Ltd announced on 30 July 2025 that it and configserver.com would close permanently on 31 August 2025. The snapshot of that day reads, verbatim:
Way to the Web Ltd and Configserver.com will be closing down permanently on 31 August 2025. The server software market has changed drastically in the more than 25 years since our company began, and we now find the business is no longer profitable so must come to an end.
Quote that carefully: the second sentence was removed from the page at some point before the 31 August snapshot . Anyone quoting the announcement should say which version they are quoting. The company itself, Way to the Web Limited, no. 03829549 , was dissolved on 10 March 2026.
This was a planned, announced wind-down by a business of more than 25 years, which open-sourced its flagship free product on the way out. It deserves to be described that way.
What a running cxs installation means today
Four documented consequences, which together make the migration case without any exaggeration:
- the fingerprint database was frozen on 31 August 2025;
- the IP reputation backend was switched off;
- no licence reactivation and no licence IP changes are possible — so a server you rebuild or migrate cannot be re-licensed;
- the vendor recommended no replacement product, and cxs was never open-sourced: no fork, no successor.
Measured from our own host on 4 September 2026: configserver.com still resolves but refuses TCP on ports 80 and 443, its archived homepage has returned 404 since 30 November 2025, and download.configserver.com returns NXDOMAIN from both 1.1.1.1 and 8.8.8.8. The domain registration itself runs to 18 January 2027. We have not verified that download.configserver.com was in fact the update host for cxs, so treat “updates are therefore broken” as an inference rather than a finding — the frozen fingerprint database is the documented fact, and it is enough.
csf is a different story, and it is alive
Do not confuse the two products. csf was released under GPLv3 on 28 August 2025, three days before the closure, at version 15.00 with the auto-update mechanism deliberately disabled. The vendor’s own GitHub account is gone, so the code survives because it was forked: Aetherinox/csf-firewall
— the fork behind configserver.dev — was at v15.10 as of February 2026, and cPanel maintains a mirror
, announcing the switchover from 25 February 2026
and describing its own effort as maintenance only.
“csf is abandoned” is false and should not be repeated. Note also that configserver.dev is the community fork, not the vendor; reasoning from the domain name misattributes community work.
The asymmetry is what defines this market: the free firewall was rescued by forks, the paid scanner was not.
The price anchor everyone is comparing against
cxs was $60 per server, one time, with lifetime updates ($50 until mid-2014), with a volume ladder down to an effective floor of $36 per server (archived product page , ordering policy ). There was never an “unlimited” SKU; monthly cxs prices circulating online came from third-party licence resellers, not from the vendor.
The field that replaced it charges roughly $5–20 per server per month. That is $60–240 in the first year, and again every year after. Every cxs refugee notices this in the first five minutes, so it is better stated plainly than glossed over.
The per-server field, September 2026
| Product | Vendor / country | Price per server | Real-time on write | Cleanup | Notes |
|---|---|---|---|---|---|
| Imunify360 | CloudLinux Software, Inc. (US) | $12–45/mo (1–4 servers), $5–20/mo (5+); VAT not stated | Yes | Yes | Tiered by hosting accounts on the server; on CyberPanel the documented route requires converting to CloudLinux OS |
| ImunifyAV / AV+ | CloudLinux Software, Inc. (US) | AV free; AV+ $7/mo | — | AV+ only | Documentation lists supported panels as cPanel, Plesk, DirectAdmin |
| BitNinja | BitNinja Technologies Zrt. (Hungary, EU) | $8–52/mo list, $5–23/mo from 5 servers; VAT not stated | Yes | Yes | EU company; its privacy policy lists processors in several countries including the US |
| Patchman | CloudLinux Software, Inc. (US; Dutch origin) | €20–45/mo virtual, €45–100/mo dedicated | Not claimed | Yes | Sells automated CMS patching rather than scanning |
| cPGuard | OPSSHIELD (India) | $4.50–10/mo | Yes | Yes | Vendor site is opsshield.com |
| ISPProtect | projektfarm GmbH (Germany, EU) | €82.68/yr, stated excl. VAT | No — on demand | No | The only vendor in the set that states its VAT treatment |
| Defensia | Barcelona (Spain, EU) | Free for 1 server (monitor only), €9/mo | No — event detection | No | States that its servers and primary processing are in the EU |
| Sentinel Anti-malware | Danami | $5–15/mo, or $189 one-time | — | — | Plesk only; runs LMD and ClamAV underneath |
| maldet (LMD) | R-fx Networks | Free, GPL-2.0 | Yes (inotify) | Limited | Alive as a project — v2.0.1 released 29 April 2026 — but see the feed note below |
| ClamAV | Cisco / Talos | Free, GPL-2.0 | No (engine only) | No | Documented as “not a traditional anti-virus or endpoint security suite” |
| Shelltrap | Panomity GmbH (Germany, EU) | Per server, see our pricing page | Yes (fanotify, tier-reported) | Quarantine with restore | Built for CyberPanel; files never leave the server |
Two footnotes that matter more than the table.
The free stack has a feed problem right now. maldet is not abandoned — v2.0.1 shipped on 29 April 2026 — but when we measured its signature CDN on 4 September 2026, rfxn.yara carried Last-Modified: Sun, 24 May 2026 14:33:02 GMT and maldet.sigs.ver read 2026052490478. A paid ClamAV signature feed in the same category, measured in the same pass, had been updated on 3 September 2026 — so this is specific to the free feed, not a property of signature feeds in general. Re-measure it yourself; a single push would change the picture.
Only one competitor makes an explicit EU-processing commitment. Defensia states that its servers and primary data processing infrastructure are located within the European Union. BitNinja is an EU company whose privacy policy nonetheless lists processors in several jurisdictions. If that axis matters to you, GDPR and data residency in malware scanning sets out what to ask.
Not a comparable purchase: per-site products
Wordfence Premium, Care and Response are $149, $590 and $1,250 per site per year; Sucuri Basic, Pro and Business are $229, $339 and $549 per site per year. On a 250-site server, Wordfence Premium alone would arithmetically be $37,250 a year — a structural point about per-site versus per-server licensing, not a claim that anyone pays it. Wordfence is a per-site WordPress plugin; Sucuri scans remotely behind a DNS-level WAF. Neither is a server-side on-write scanner. The architectural comparison is in Wordfence versus a server-level scanner .
If you specifically run CyberPanel
The beachhead problem is provable from three vendors’ own pages. CyberPanel’s knowledge base states that Imunify360 requires converting the operating system to CloudLinux OS ; Imunify’s documentation lists ImunifyAV’s supported panels as cPanel, Plesk and DirectAdmin ; and CyberPanel’s add-on bundle contains no security scanner. CloudLinux does market Imunify360 directly at former ConfigServer customers on a dedicated landing page , which is fair positioning but does not change the OS requirement.
So: there is no officially supported, real-time malware scanner for a stock CyberPanel server. People do run Imunify unofficially — that is a different sentence from it being supported.
How to choose
- Detection or cleanup? ISPProtect and Defensia do not clean; Imunify360, BitNinja and cPGuard do. Decide whether cleanup is something you want automated at all on customer sites.
- Real time or on demand? Ask which kernel API, and what happens when its event queue overflows — see fanotify vs inotify .
- Per server or per site? The arithmetic diverges above about twenty sites.
- Where does the data go? Ask whether file contents leave the server by default, and get the answer from the technical documentation rather than the brochure.
- What happens if the vendor disappears? This is the cxs lesson, and it is now a procurement question rather than a philosophical one: licence portability after a rebuild, exportable quarantine and findings, documented formats.
What this means for CyberPanel operators
- Treat a running cxs installation as a frozen one and plan the migration on your own schedule — the signature database has not moved since 31 August 2025.
- Keep csf where it suits you, from a maintained fork, and stop describing it as part of the same problem.
- Price the options over three years, not one month, and put the cxs $60 anchor next to them explicitly rather than pretending the market did not change.
- On stock CyberPanel, verify that the product you are evaluating supports your OS without a commercial OS conversion; the practical setup path is in the CyberPanel setup guide and the installation docs .
- Add “what happens when you shut down” to your vendor questionnaire. Under the EU supply-chain rules for in-scope providers, limiting vendor lock-in is a criterion you are expected to consider anyway; see what CyberPanel operators should do next .
Shelltrap is a per-server licence, built for CyberPanel, with signed feeds and no file leaving the host. See pricing .
Frequently asked
Was cxs abandoned?
No, and it matters to say so. Way to the Web announced the closure on 30 July 2025, closed on 31 August 2025, and released csf under GPLv3 three days before closing. It was a planned wind-down by a 25-year-old business, not an abandonment.
Is csf dead too?
No. csf was released under GPLv3 on 28 August 2025 and is maintained in community forks; the cPanel mirror describes its own effort as maintenance only. The asymmetry is the point: the free firewall was rescued by forks, the paid scanner was not.
Can I keep running my existing cxs licence?
It will keep running, but its fingerprint database was frozen on 31 August 2025, the IP reputation backend was switched off, and licences can no longer be reactivated or moved to a new server IP — so a server rebuild or migration ends it.
Sources
Every number, date and vendor claim in this article links to one of these.
- configserver.com closure announcement, archived 30 July 2025 — accessed 2026-09-04
- configserver.com closure announcement, archived 31 August 2025 — accessed 2026-09-04
- Companies House — Way to the Web Limited, company no. 03829549 — accessed 2026-09-04
- cpanel/cpanel-csf — csf under GPLv3, maintained mirror — accessed 2026-09-04
- Aetherinox/csf-firewall — community fork behind configserver.dev — accessed 2026-09-04
- configserver.com — ConfigServer eXploit Scanner product page, archived 29 August 2025 — accessed 2026-09-04
- configserver.com — ordering policy, archived 29 August 2025 — accessed 2026-09-04
- cPanel — cPanel will provide its own fork of CSF starting 25 February 2026 — accessed 2026-09-04
- Imunify360 pricing — accessed 2026-09-04
- ImunifyAV product page — accessed 2026-09-04
- BitNinja pricing — accessed 2026-09-04
- Patchman (pricing on vendor homepage) — accessed 2026-09-04
- cPGuard pricing (OPSSHIELD) — accessed 2026-09-04
- ISPProtect (projektfarm GmbH) — accessed 2026-09-04
- Defensia pricing — accessed 2026-09-04
- Sentinel Anti-malware (Danami) — accessed 2026-09-04
- CloudLinux — ConfigServer EOL landing page (vendor marketing) — accessed 2026-09-04
- ImunifyAV documentation — supported control panels — accessed 2026-09-04
- CyberPanel knowledge base — how to install and use Imunify360 on CyberPanel — accessed 2026-09-04
- CyberPanel add-ons — accessed 2026-09-04
- Linux Malware Detect signature feed, rfxn.yara (measured with curl -I) — accessed 2026-09-04
- Linux Malware Detect project repository — accessed 2026-09-04
- ClamAV documentation — accessed 2026-09-04
- Wordfence plans and pricing (official landing page) — accessed 2026-09-04
- Sucuri pricing — accessed 2026-09-04
More from the research desk
CXS is gone: what CyberPanel operators should do next
Way to the Web closed on 31 August 2025. csf survived via GPLv3 forks, cxs did not. What that means for a stock …
GuidesCyberPanel malware scanner setup with Shelltrap
Install a host-level malware scanner on a stock CyberPanel server: requirements, signed packages, report-only first, and …
AnalysisCyberPanel's security history, and what it teaches operators
Three pre-auth RCEs, a ransomware wave, a quiet 2025 and a busy 2026. What is verified about CyberPanel's incidents, and …
Shelltrap watches the files this article is about
Real-time detection, an upload gate in front of your PHP, explainable verdicts, and nothing leaving your server.