# Shelltrap > Real-time webshell and exploit scanning for CyberPanel servers. Made in Bavaria, hosted in Germany, GDPR-ready: your files never leave your server. Vendor: Panomity GmbH, Seilergasse 34, 85570 Markt Schwaben, Bavaria, Germany. Amtsgericht München HRB 264411. VAT ID DE324810080. Managing director: Sascha Endlicher, M.A. Contact: hallo@panomity.de, +49 8121-7607887. Language of this file: English (en). ## What Shelltrap is Shelltrap is a commercial, proprietary webshell and exploit scanner for CyberPanel servers running OpenLiteSpeed or LiteSpeed Enterprise on Linux. It watches customer document roots in real time with fanotify, scans in an unprivileged worker isolated by namespaces, seccomp and Landlock, and combines ClamAV, YARA 4.5, hash sets and explainable heuristics. A PHP upload gate installed through auto_prepend_file inspects web uploads before application code runs. Findings are recorded with per-signal reasoning; quarantine is a crash-safe transaction with a full restore path. Policies are set per domain, per account or globally. Files never leave the customer's server. The only outbound connections are the licence check and the download of signed signature generations, both to Panomity servers in Germany. ## Pricing - Plan "Server": 14.9 EUR per server and month, or 149 EUR per server and year. Both figures include German VAT at 19 %. Net for business customers: 12.52 / 125.21 EUR. The yearly price equals 2 months free against paying monthly. - One licence covers one server and every domain on it. - A 14-day trial is announced but not bookable yet. - From 5 servers: volume and reseller pricing on request. ## Pages - [Moving from CXS to Shelltrap](https://shelltrap.com/product/cxs-migration/): A practical migration path from ConfigServer eXploit Scanner to Shelltrap on CyberPanel: capability mapping, a cutover checklist that starts in report-only, and a licence calculator. - [Imprint](https://shelltrap.com/legal/imprint/): Legal disclosure for shelltrap.com according to § 5 TMG: Panomity GmbH, Markt Schwaben, register court Munich HRB 264411, VAT ID DE324810080. - [Installation and first run](https://shelltrap.com/docs/installation/): Requirements, signed packages, the capability probe, Full and Lite profiles, systemd units and the report-only start that belongs on any host with customers on it. - [How real-time file detection works](https://shelltrap.com/how-it-works/real-time-detection/): fanotify against inotify, why a scanner needs a privilege split, what happens when the event queue overflows, and why 'not scanned' has to be its own answer. - [Configuration and policies](https://shelltrap.com/docs/configuration/): The per-domain policy model, the keys you can set, the local API and CLI, and the health and metrics you should alert on. - [Privacy statement](https://shelltrap.com/legal/privacy/): What shelltrap.com processes and what the Shelltrap software transmits: cookieless Matomo on German servers, server logs, contact by email, and the ordering process. No customer file ever leaves your machine. - [How a synchronous upload gate works](https://shelltrap.com/how-it-works/upload-gate/): Why PHP's auto_prepend_file is the right hook for scanning uploads on OpenLiteSpeed, what fail-open really costs, and the limitation nobody else prints on the box. - [The CyberPanel plugin](https://shelltrap.com/docs/plugin/): Installing, upgrading and repairing the Shelltrap plugin for CyberPanel, the pages it adds, and the role model for administrators, resellers and customers. - [Terms of business](https://shelltrap.com/legal/terms/): How a contract for Shelltrap comes about, where the binding terms and conditions live, and what applies to subscriptions, invoicing and cancellation. - [Licence terms (extract)](https://shelltrap.com/legal/eula/): An extract of the terms on which Shelltrap is licensed: proprietary software, one licence per server, binaries only, signature feeds tied to an active licence. - [Signature feeds](https://shelltrap.com/docs/feeds/): How rule generations are built, licence-filtered, signed, verified, gated against a corpus and activated — and how a false-positive storm rolls them back automatically. - [Licensing and activation](https://shelltrap.com/docs/licensing/): How a Shelltrap licence key works, what activation binds to, how the offline token is verified, and exactly what the daemon does when a licence is missing or expired. - [Hash sets](https://shelltrap.com/rules/hashes/): SHA-256 hash sets shipped in the signed feed: known-bad hashes trigger a malicious verdict, allow sets mark verified WordPress core files as clean. - [Heuristics engine](https://shelltrap.com/rules/heuristics/): How Shelltrap's built-in heuristics score PHP and script files without signatures: signal groups, weak signals, allowlists and how to tune false positives per domain. - [Known webshell families](https://shelltrap.com/rules/known-shells/): Signature strings of well-known PHP webshells (c99, r57, b374k, WSO, FilesMan, p0wny), spam mailers and back-connect helpers. Every rule requires PHP - [PHP obfuscation rules](https://shelltrap.com/rules/php-obfuscation/): Loader and obfuscation patterns: eval/base64 chains, assert and create_function loaders, preg_replace /e, str_rot13/gzinflate layers, hex and chr esca - [PHP remote code execution patterns](https://shelltrap.com/rules/php-rce/): Direct command execution driven by request data: system/exec/passthru/shell_exec with superglobals, backtick execution, proc_open pipes and similar. - [WordPress-specific droppers](https://shelltrap.com/rules/wordpress/): Backdoors that hide inside WordPress structures: PHP in uploads, fake wp-config includes, mu-plugins backdoors, fake plugin headers with curl/eval, ap - [ClamAV alone is not enough for webshells](https://shelltrap.com/articles/clamav-alone-is-not-enough-for-webshells/): ClamAV says so itself. What the engine covers, where PHP webshell detection actually comes from, and what a layered stack on a hosting server looks like. - [CXS alternatives in 2026: the honest field guide](https://shelltrap.com/articles/cxs-alternatives-2026/): ConfigServer closed on 31 August 2025. What replaced cxs, what the options cost as at 4 September 2026, and what runs on a stock CyberPanel host. - [CXS is gone: what CyberPanel operators should do next](https://shelltrap.com/articles/cxs-end-what-cyberpanel-operators-should-do/): Way to the Web closed on 31 August 2025. csf survived via GPLv3 forks, cxs did not. What that means for a stock CyberPanel host, plus a checklist. - [CyberPanel malware scanner setup with Shelltrap](https://shelltrap.com/articles/cyberpanel-malware-scanner-setup-shelltrap/): Install a host-level malware scanner on a stock CyberPanel server: requirements, signed packages, report-only first, and per-domain policies. - [CyberPanel's security history, and what it teaches operators](https://shelltrap.com/articles/cyberpanel-security-incidents-and-lessons/): Three pre-auth RCEs, a ransomware wave, a quiet 2025 and a busy 2026. What is verified about CyberPanel's incidents, and what host-level defence adds. - [False positives on WordPress core, and what to do](https://shelltrap.com/articles/false-positives-in-malware-scanning-wordpress-core/): Which WordPress files trip generic malware heuristics, why entropy alone is a bad signal, and how to tune a host-level scanner without going blind. - [fanotify vs inotify for file monitoring](https://shelltrap.com/articles/fanotify-vs-inotify-for-file-monitoring/): Two kernel APIs, two very different guarantees. What the man pages actually say about recursion, races, permission events and the caveats nobody quotes. - [Find webshells on a CyberPanel server manually](https://shelltrap.com/articles/find-webshells-on-a-cyberpanel-server-manually/): A root-level triage playbook with find, grep, YARA and clamscan for CyberPanel hosts, including the honest limits of every one of those commands. - [GDPR and data residency in malware scanning](https://shelltrap.com/articles/gdpr-data-residency-malware-scanning/): If your scanner uploads customer files, your vendor is a processor. What Art. 28 and 32 require, what BSI says about cloud detection, and what to ask. - [How the PHP upload gate works (auto_prepend_file)](https://shelltrap.com/articles/php-upload-gate-auto-prepend-file/): Scanning an upload before the application accepts it: the auto_prepend_file adapter, the socket protocol, the decisions it returns and why it fails open. - [How webshells get into WordPress uploads](https://shelltrap.com/articles/how-webshells-get-into-wordpress-uploads/): Arbitrary file upload, polyglots and .htaccess handler abuse: the routes a PHP backdoor takes into wp-content/uploads, and how to close them. - [Imunify360 vs Shelltrap on CyberPanel: a fair comparison](https://shelltrap.com/articles/imunify360-vs-shelltrap-for-cyberpanel/): CloudLinux requirement, panel support, pricing checked 4 September 2026, and the data-handling question every buyer should put to both vendors in writing. - [Linux Malware Detect (maldet) vs Shelltrap](https://shelltrap.com/articles/linux-malware-detect-maldet-vs-shelltrap/): maldet is free, GPL-2.0 and still shipping releases. The real question is the signature feed behind it — measured, with commands to re-check it yourself. - [NIS2, GDPR and malware scanning for hosting providers](https://shelltrap.com/articles/nis2-gdpr-hosting-providers-malware-scanning/): Germany's NIS2 law is in force since 6 December 2025. What it obliges hosters to do, what the BSI requires, and how a local-only scanner answers it. - [Quarantine or delete? Handling malware finds](https://shelltrap.com/articles/quarantine-vs-delete-malware-files/): Deleting a detected file destroys your evidence and your undo button. When quarantine is the right default, and what a usable quarantine record contains. - [Shared hosting: the cross-account risk](https://shelltrap.com/articles/shared-hosting-cross-account-risk/): Isolation and blindness are one property seen from two sides. What CageFS protects, what a per-tenant scanner cannot see, and how to sweep a whole box. - [Shelltrap in report-only mode: the first week](https://shelltrap.com/articles/shelltrap-report-only-mode-first-week/): What a real report-only rollout looks like: the install order, the eight numbers to watch, the abort criteria and what our own first host actually did. - [Signed signature feeds explained](https://shelltrap.com/articles/signed-signature-feeds-explained/): A signature feed is a supply chain into your server. Ed25519 signing, per-rule provenance, activation gates, rollback, and why feed age belongs in health. - [The WordPress webshell wave, 2024–2026: what the data shows](https://shelltrap.com/articles/wordpress-webshell-wave-2024-2026/): Sourced campaigns, CVE chains and file-level indicators from the 2024–2026 WordPress backdoor wave — with the dates, the caveats and the counter-example. - [What is a webshell? A definition for hosting operators](https://shelltrap.com/articles/what-is-a-webshell/): A webshell is a script an attacker leaves behind in your web root to keep access. What they look like on disk, how they persist and what finds them. - [What to ask a security vendor: DPA, EULA, exit](https://shelltrap.com/articles/security-tool-questions-to-ask-vendors-dpa-eula/): Twelve questions for a malware-scanner purchase, mapped to the EU supplier clauses and Art. 28 GDPR, plus the exit questions the cxs wind-down taught us. - [Why webshell detection belongs on the server, not the site](https://shelltrap.com/articles/why-server-level-webshell-detection/): Plugin scanners share the fate of the process they run in. What kernel docs, MITRE, the NSA repo and the BSI say about watching writes below the tenant. - [Wordfence vs a server-level scanner](https://shelltrap.com/articles/wordfence-vs-server-level-scanner/): An in-process PHP scanner shares the fate of the process it runs in. The architectural differences, from both vendors' own docs and Sucuri's casework. - [WordPress backdoor removal: a server-side checklist](https://shelltrap.com/articles/wordpress-backdoor-removal-checklist-server-side/): Cleaning a hacked WordPress site from the host, in order: preserve evidence, contain, inventory, check the neighbours, patch, and prove it stayed clean. - [About Shelltrap and Panomity](https://shelltrap.com/about/): Shelltrap is built by Panomity GmbH in Markt Schwaben near Munich. Why a hosting company built its own scanner, and what 'made in Bavaria' actually commits us to. - [Changelog](https://shelltrap.com/changelog/): Every Shelltrap version with what changed, including the failures found on our own production hosts during the internal test stage. - [Contact](https://shelltrap.com/contact/): Reach Panomity GmbH about Shelltrap: sales and volume pricing, technical questions, security reports and press. Email, phone and the client area for existing customers. - [Download](https://shelltrap.com/download/): Shelltrap packages are signed and served against a valid licence key. Here is what a release contains, how to verify it, and how to fetch it from the licence service. - [Frequently asked questions](https://shelltrap.com/faq/): Straight answers about Shelltrap: what it detects, what it cannot do, how licensing works, what leaves your server and how it behaves when something breaks. - [Pricing](https://shelltrap.com/pricing/): Shelltrap costs 14.90 EUR per server and month or 149.00 EUR per year, VAT included, with every domain on that server covered. No per-account fee, no OS conversion. - [Webshell Signal Explorer](https://shelltrap.com/signal-explorer/): Six shapes a scanner meets on a real hosting server, with the reasoning behind each verdict — including the false positive that must never trigger an action. ## Sections - [Detection rules](https://shelltrap.com/rules/) - [articles](https://shelltrap.com/articles/) - [Documentation](https://shelltrap.com/docs/) - [How it works](https://shelltrap.com/how-it-works/) - [Legal](https://shelltrap.com/legal/) - [Shelltrap for CyberPanel](https://shelltrap.com/product/) ## Ordering and downloads - Order: https://shop.shelltrap.com/cart/shelltrap/ - Client area: https://shop.shelltrap.com/clientarea/ - Licence and download API: https://license.shelltrap.com/v1 (packages require a valid licence key; there are no public package links) ## Rules for reuse The text of this website may be quoted with attribution to Shelltrap / Panomity GmbH and a link to the page quoted. Do not present pricing or technical claims without the qualifiers given on the page they come from. Prices change; re-read this file rather than caching a figure.