Analysis
CXS is gone: what CyberPanel operators should do next
Way to the Web closed on 31 August 2025. csf survived via GPLv3 forks, cxs did not. What that means for a stock CyberPanel host, plus a checklist.
On 30 July 2025, Way to the Web Ltd published a short notice on its blog and on configserver.com. A month later the company was gone, and with it the commercial exploit scanner that a generation of hosting operators had installed as a matter of routine.
This was not an abandonment. It was a planned, announced wind-down by a business that had been trading for more than twenty-five years, and on its way out it released its flagship free product under the GPLv3. That distinction matters, and it changes what you should do about it.
What follows is the verified timeline, the asymmetry between csf and cxs that defines the situation today, and a checklist for anyone still running cxs on a CyberPanel host.
The timeline, from the vendor’s own pages
The announcement was published on 30 July 2025. The earliest Internet Archive capture of the announcement page is from 30 July 2025 at 19:56 UTC , and it reads:
Way to the Web Ltd and Configserver.com will be closing down permanently on 31 August 2025. The server software market has changed drastically in the more than 25 years since our company began, and we now find the business is no longer profitable so must come to an end.
A note on that quote, because it is easy to get wrong. The second sentence — the reason for closing — was removed from the announcement page at some point between 30 July and 31 August 2025. The final archived version of 31 August 2025 carries the first sentence but not the second. If you quote the “no longer profitable” wording, quote it as the 30 July version, which is what we have done here. Presenting it as text that stood on the page at closure would be inaccurate.
The dates that are defensible are these two, and only these two:
| Event | Date |
|---|---|
| Closure announced | 30 July 2025 |
| Company and website closed permanently | 31 August 2025 |
No “end of new sales” date was ever published, and we could find no usable archive capture of the sales pages, so any third-party article quoting one is unverified. Separately, csf was released under GPLv3 on 28 August 2025 — the commit titled “GPL v3 Release” by the author handle chirpy, timestamped 2025-08-28T14:15:56Z, carrying version.txt = 15.00, is preserved in the cPanel csf repository
. The identity behind the handle is not a rumour: the GPLv3 source header reads Copyright (C) 2006-2025 Jonathan Michaelson.
Way to the Web Limited (England and Wales, company number 03829549) was formally dissolved on 10 March 2026, per the Companies House register .
csf lived. cxs did not.
This is the single most important thing to understand, and it is the reason the two products need completely different responses.
csf — the free firewall — survived. It is GPLv3, and it is maintained. The most active community fork is Aetherinox/csf-firewall , which reached v15.10 in February 2026. cPanel began switching over to its own mirror on 25 February 2026 and describes that work as a maintenance effort only. Further forks exist under Sentinel Firewall, Black-HOST and DirectAdmin.
Two cautions follow from that. First, “csf is abandoned” is simply false, and you will see it written anyway. Second, the domain configserver.dev is the Aetherinox community fork, not the vendor — anyone reasoning from the domain name will credit community work to a company that no longer exists.
cxs — the paid exploit scanner — has no equivalent story. It was never open-sourced, no fork exists, and no successor was named. The vendor’s own closure FAQ, in the 31 August 2025 version of the announcement page , answers the questions that matter, verbatim:
Will you continue to update the cxs fingerprint database? No, there will be no further updates to the cxs fingerprints after 31st August.
Will the cxs reputation system continue to work? No, the cxs reputation system will no longer work because the server running it will shut down.
Can I move the software to another server after 31 August? No, because changing the license IP will not be possible after 31 August, and you will not be able to download the software to install it on another server.
I have licenses I am not currently using. Will I be able to install or activate them after the 31st of August? No, after that date there will be no downloads available or any license manager system to activate or move licenses.
Refunds were limited to software that had not yet been installed and had been purchased less than fourteen days before the request; otherwise the standard ordering and refund policy applied. And the vendor recommended no replacement product.
That combination — frozen signatures, a dead reputation backend, and licences that cannot follow a server rebuild — is the whole factual case for migrating off cxs. It needs no exaggeration.
The price everyone remembers
cxs was $60 per server, one time, with lifetime updates, excluding UK VAT, from February 2015 until closure; it had been $50 from 2012 until mid-2014. Volume purchases discounted the base price by 5% (2–4 additional licences), 10% (5–9), 20% (10–19), 30% (20–49) and 40% (50 or more), an effective floor of $36 per server. Those figures come from the archived cxs product page , snapshot of 29 August 2025.
Two corrections while we are here. There was never an “unlimited” cxs tier — no archived ConfigServer page from 2009 to 2025 mentions one. And the monthly cxs prices that still circulate online are third-party reseller prices, not vendor pricing.
We mention the $60 because it is the number every CXS refugee is silently comparing against, and pretending otherwise would be dishonest. The category that replaced cxs is priced per server per month. We cover what that means in detail in our comparison of Imunify360 and Shelltrap for CyberPanel .
What is measurably left of the infrastructure
Measured by Panomity Security Research from our own host on 4 September 2026, against both Cloudflare’s 1.1.1.1 and Google’s 8.8.8.8 resolvers:
configserver.comstill resolves (66.165.246.164, NOERROR), but refuses TCP on ports 80 and 443. The archived homepage has returned 404 since 30 November 2025. The domain registration itself runs until 18 January 2027.download.configserver.comreturns NXDOMAIN from both resolvers. A fetch of a file under that host fails at name resolution, before any HTTP request is made.forum.configserver.comis dead.
NXDOMAIN from two independent resolvers indicates a deleted record rather than a transient outage.
Two things this does not establish, and we will not assert them: that download.configserver.com was in fact the update host for csf and cxs (widely believed and consistent with the historic install instructions, but unverified here because the host is gone), and that csf or cxs updates are therefore broken (that is an inference; a maintained fork uses its own infrastructure). When the removal happened is also unknown — a single NXDOMAIN observation gives no date.
The stock CyberPanel situation
CyberPanel operators are in a narrower spot than cPanel or DirectAdmin operators, for reasons that are provable from two vendors’ own documentation.
CyberPanel ships no first-party malware scanner. Its own knowledge base article on Imunify360 states, verbatim:
Imunify360 is available with CyberPanel v2.0.0, but before using it you need to convert your operating system to CloudLinux OS.
(CyberPanel knowledge base , published 24 November 2023.) So the documented route is a paid licence and a commercial OS conversion — two purchases and a disruptive migration for anyone on stock AlmaLinux or Ubuntu.
The free tier does not close the gap either: ImunifyAV’s own documentation lists the supported panels as cPanel, Plesk and DirectAdmin. CyberPanel is not among them, and the same page confirms that free ImunifyAV is detection only, with cleanup marked as an ImunifyAV+ feature.
The honest, checkable formulation is therefore: there is no officially supported, real-time malware scanner for a stock CyberPanel server today. Not “Imunify does not work on CyberPanel” — people do run it unofficially. Not supported is a different claim from not functional, and only the first one is provable.
One more item belongs on your list rather than in an accusation. CyberPanel ships a built-in Security → CSF menu with a one-click install button, documented in a knowledge base article from 15 December 2023
that contains no acknowledgement of the ConfigServer wind-down. Since csf remains maintained under GPLv3, the useful question is not whether csf is safe — it is a firewall, and it is fine — but where that installer fetches its payload from today. That is a supply-chain question worth verifying on your own box before your next rebuild.
For context on how the rest of the field reacted: CloudLinux published a dedicated ConfigServer end-of-life landing page positioning Imunify360 and its email add-on as the replacements, and cPanel published a blog post on 18 September 2025. Both are competitor marketing and are useful only as evidence of how the market positioned itself.
Migration checklist
Work through this in order. Nothing here requires buying anything.
1. Inventory what you actually run. On each host, establish whether cxs is installed and when its fingerprints last changed.
# Is cxs present, and what does it think its version is?
command -v cxs && cxs --version
# When did the signature files last change?
ls -l --time-style=long-iso /etc/cxs/ 2>/dev/null
Any modification date at or before 31 August 2025 is expected — that is the freeze, not a fault on your server.
2. Record your licence position. Note which servers hold a cxs licence and which do not. Because licence IPs can no longer be changed and the licence manager is gone, a rebuild of any licensed server is a one-way door. Plan rebuilds accordingly.
3. Keep csf, but move it to a maintained source. csf is a firewall, not a scanner, and it is not the thing you lost. Point it at a maintained GPLv3 fork rather than at any remaining vendor URL, and verify that the panel’s one-click installer is not still reaching for a host that no longer exists.
4. Extract your operational knowledge before you decommission anything. Your cxs ignore rules, quarantine history and per-domain exceptions encode years of knowing which of your customers’ files are false positives. Export them as plain text now, while the installation still runs.
# Illustrative only — adjust paths to your installation.
tar -czf /root/cxs-config-backup-$(date +%F).tgz /etc/cxs/ 2>/dev/null
5. Decide what “real-time” has to mean for you. A scanner that sweeps nightly and a scanner that reacts to a file write are different products with different failure modes. We set out the architectural argument, with kernel documentation and neutral authorities rather than vendor claims, in why webshell detection belongs on the server, not in the site .
What this means for CyberPanel operators
- Stop treating your cxs installation as a control. It still runs, and it still catches what it knew on 31 August 2025. Its fingerprint database has not moved since, and its reputation backend is off. Both facts come from the vendor’s own closure FAQ, not from us.
- Do not rebuild a licensed server without a plan. Licence IP changes and reactivation ended with the licence server. Sequence any migration so that the replacement control is in place before the old host is touched.
- Keep csf, from a maintained fork. It was released under GPLv3 and it is actively maintained. Check what your panel’s one-click installer downloads today.
- Write down what “supported” means to you before you shop. On a stock CyberPanel host, the two Imunify routes each carry a documented blocker — an OS conversion, or a panel that is not on the supported list. Ask every vendor for the sentence in their documentation that names CyberPanel.
- Set a re-check date. Prices, forks and vendor documentation in this field move quickly, and much of what is confidently repeated about the ConfigServer wind-down is wrong. Verify anything you read — including this — against the archived pages linked above.
Shelltrap is Panomity’s answer to the specific gap cxs left on CyberPanel hosts: a real-time, server-side webshell and exploit scanner that processes files locally. If you want to see what installing it looks like before you think about budget, start with the installation documentation , and the commercial terms are on the pricing page .
Frequently asked
Is csf abandoned?
No. csf was released under GPLv3 on 28 August 2025 and is maintained in community forks, including Aetherinox/csf-firewall and a cPanel-maintained mirror. Only the original vendor stopped.
Can I still buy or re-license cxs?
No. Way to the Web closed on 31 August 2025. Its own FAQ states there is no licence manager to activate or move licences after that date, and no downloads.
Does my installed cxs still detect new webshells?
It runs, but its fingerprint database has had no updates since 31 August 2025 and the IP reputation system was switched off, per the vendor’s own closure FAQ.
Was there ever an unlimited cxs licence?
No. No such SKU appears on any archived ConfigServer page. Monthly cxs prices circulating online come from third-party licence resellers, not from the vendor.
Sources
Every number, date and vendor claim in this article links to one of these.
- Way to the Web closure announcement, archived 30 July 2025 (first version) — accessed 2026-09-04
- Way to the Web closure announcement, archived 31 August 2025 (final version, with FAQ) — accessed 2026-09-04
- ConfigServer eXploit Scanner product page, Internet Archive snapshot 29 August 2025 — accessed 2026-09-04
- ConfigServer ordering and refund policy, Internet Archive snapshot 29 August 2025 — accessed 2026-09-04
- cpanel/cpanel-csf — csf under GPLv3 — accessed 2026-09-04
- cPanel: cPanel will provide its own fork of CSF starting Feb 25th 2026 — accessed 2026-09-04
- Aetherinox/csf-firewall — community fork of csf — accessed 2026-09-04
- Companies House register — Way to the Web Limited, company no. 03829549 — accessed 2026-09-04
- CyberPanel knowledge base: how to install and use Imunify360 on CyberPanel — accessed 2026-09-04
- ImunifyAV documentation — supported control panels — accessed 2026-09-04
- CyberPanel knowledge base: CSF in CyberPanel — accessed 2026-09-04
- CloudLinux: ConfigServer end-of-life landing page — accessed 2026-09-04
- cPanel blog: The end of ConfigServer — accessed 2026-09-04
More from the research desk
CXS alternatives in 2026: the honest field guide
ConfigServer closed on 31 August 2025. What replaced cxs, what the options cost as at 4 September 2026, and what runs on …
GuidesCyberPanel malware scanner setup with Shelltrap
Install a host-level malware scanner on a stock CyberPanel server: requirements, signed packages, report-only first, and …
AnalysisCyberPanel's security history, and what it teaches operators
Three pre-auth RCEs, a ransomware wave, a quiet 2025 and a busy 2026. What is verified about CyberPanel's incidents, and …
Shelltrap watches the files this article is about
Real-time detection, an upload gate in front of your PHP, explainable verdicts, and nothing leaving your server.