Home Shield Postmaster Firewall Guardian Contact Get Guardian
The modern ConfigServer ModSecurity Control (cmc) alternative

See what your WAF blocks — and tune it without breaking sites.

MegaWit Guardian (MWG) manages your server's real ModSecurity web application firewall from a WHM dashboard: install it in one click, watch every blocked attack, fix false positives per-site instead of turning the WAF off, auto-block repeat attackers and keep sites patched with MegaWit's maintained rule packs — everything ConfigServer ModSecurity Control (cmc) did, rebuilt and actively maintained.

15-day free trial 1 server · unlimited accounts CentOS 7+ · CloudLinux · Alma · Rocky · Ubuntu · Debian
MegaWit Guardian
cmc replacement Still using ConfigServer ModSecurity Control (cmc)? It's discontinued. MWG is a modern, actively-maintained way to manage cPanel's ModSecurity — with visibility, one-click tuning and maintained rule packs cmc never had.

Everything cmc did — plus the intelligence it never had

Guardian doesn't run a second firewall. It manages cPanel's own ModSecurity through the same WHM APIs you already trust — then adds the visibility, tuning and automation that make a WAF safe to actually leave on.

🧩

Manages your real ModSecurity

Not a parallel engine — Guardian drives cPanel's own ModSecurity via WHM's APIs, so what you see is exactly what's protecting your sites. Uninstalling never lowers your protection.

One-click install

No ModSecurity yet? Guardian installs the EA4 mod_security2 module and the OWASP Core Rule Set for you, then manages it — with a live progress view.

🎛️

Engine & rule-set control

Flip the engine between On, Detection-only and Off, enable/disable rule-set vendors (OWASP CRS, Comodo, cPanel) and pull vendor updates — no config files.

🔎

WAF hit explorer

Search and filter every blocked or flagged request by site, IP, rule ID or message — across the whole log, not just the last screen. Click any hit for full request detail.

📊

Attack analytics

Instant top-rules, top source-IPs and most-attacked-sites breakdowns, so you can tell a real attack from an over-eager rule at a glance.

🧠

Tuning advisor

Guardian ranks your noisiest rules and tells you which look like false positives (real visitors) versus genuine attacks — with a one-click fix for each. No more guessing.

🩹

Fix false positives, don't disable the WAF

Disable a rule for one domain, allow-list a trusted IP or URL, or add a custom SecRule — so a single site's quirk never forces you to weaken protection everywhere.

Block attackers at the edge

Turn a WAF hit into a firewall block with one click, or let Guardian auto-block IPs that trip the WAF too many times — handed straight to MegaWit Firewall or csf.

💉

MegaWit virtual-patching packs

Curated rule packs MegaWit maintains — WordPress hardening, common-exploit blocks, fresh-CVE virtual patches — installed in one click and updated automatically over the channel.

🔔

Attack alerts & weekly report

Get notified on attack spikes over Email, Slack, Telegram or webhook, and a branded weekly security report you can forward straight to your clients.

👤

cPanel end-user view

Each account sees the WAF events for its own sites (read-only) — turning "why was my form blocked?" tickets into self-service answers.

📈

Live WHM dashboard

Engine state, 24-hour hits, active rule-sets and license status at a glance — a real control panel, multi-language, with automatic agent updates.

Your WAF, finally visible

See what ModSecurity is blocking, fix a false positive and block an attacker right from WHM — no SSH, no config files.

whm » plugins » megawit guardian
Guardian
Hits · 24h
1,284
Engine
On
Rule-sets
1/1
Auto-blocked
18
Attacks blocked — last 14 days

MegaWit Guardian vs ConfigServer cmc vs Imunify360

ConfigServer ModSecurity Control (cmc) is discontinued, and Imunify360 replaces your WAF with its own bundle. Guardian manages the ModSecurity you already run — and adds the parts cmc never had.

CapabilityMegaWit GuardianConfigServer cmcImunify360
Manages cPanel's own ModSecurityOwn WAF
One-click ModSecurity install
Engine + rule-set vendor controlPartial
WAF hit explorer + analyticsBasic log
False-positive tuning advisorPartial
Per-domain rule disable + allowlistManual
One-click / automatic attacker blocking
Maintained virtual-patching rule packs
Attack alerts + weekly reportPartial
cPanel end-user WAF view
Actively maintainedDiscontinued
Price$14.99/mofree$$$ higher

Install in under 2 minutes

No credit card. The trial activates automatically on first install — one per server. Your existing ModSecurity config is left untouched.

1

Log in to your server as root

SSH into your cPanel/WHM server (CentOS 7+, CloudLinux, AlmaLinux, Rocky, Ubuntu or Debian).

ssh root@your-server-ip
2

Run the one-line installer

This installs the agent and the WHM panel, and starts your 15-day trial automatically. If ModSecurity isn't installed yet, Guardian can set it up for you from the dashboard in one click.

curl -fsSL https://install.megawit.com/mwg.sh | sh
3

Open the dashboard

Go to WHM » Plugins » MegaWit Guardian for live WAF hits, tuning and rule-set management.

4

Activate a license (when ready)

Buy a key, then paste it in WHM » MegaWit Guardian » Settings » License — no SSH required. It binds to this server and unlocks continuous management after the trial.

Get a license

One server, unlimited accounts

No per-account fees. Manage the WAF for the whole server — every cPanel account — for one flat price.

Monthly
$14.99 per month
  • Single server license
  • Unlimited cPanel accounts
  • Full ModSecurity management
  • Virtual-patching rule packs
  • Automatic agent updates
  • Priority support
Buy Monthly
Annual 25% OFF
$149 $111.75 per year
  • Single server license
  • Unlimited cPanel accounts
  • Full ModSecurity management
  • Virtual-patching rule packs
  • Automatic agent updates
  • Priority support
Buy Annual
Lifetime 25% OFF
$299 $224.25 one-time payment
  • Single server license
  • Unlimited cPanel accounts
  • Full ModSecurity management
  • Virtual-patching rule packs
  • Lifetime agent updates
  • Never expires
Buy Lifetime
Best value · save 45%+
Get all four in the MegaWit Suite
Shield · Guardian · Firewall · Postmaster — one key, one server, unlimited accounts. $29.99/mo $54.96 · $299/yr · $599 lifetime.
Get the Suite →

Pair it with MegaWit Shield, MegaWit Postmaster and MegaWit Firewall for full server security.

Questions

Is MegaWit Guardian a ConfigServer ModSecurity Control (cmc) alternative?

Yes. cmc is discontinued. Guardian is a modern, actively-maintained way to manage cPanel's ModSecurity from WHM — with a WAF hit explorer, analytics, a false-positive tuning advisor, one-click fixes, attacker blocking and maintained rule packs that cmc never offered.

Does Guardian run its own firewall/WAF?

No. Guardian manages the ModSecurity that cPanel already ships, through the same WHM APIs WHM » ModSecurity Tools uses. What you see is exactly what's protecting your sites, and uninstalling Guardian never turns your WAF off or lowers protection.

What if ModSecurity isn't installed yet?

Guardian detects that and offers a one-click install of the EA4 mod_security2 module plus the OWASP Core Rule Set, with a live progress view — then manages it for you.

How does it stop false positives from breaking sites?

The tuning advisor ranks your noisiest rules and flags which look like false positives versus real attacks. You can disable a rule for just one domain, allow-list a trusted IP or URL, or add a custom rule — so you fix one site without weakening protection for the rest, instead of turning the WAF off.

What are MegaWit rule packs?

Curated sets of ModSecurity rules MegaWit maintains — WordPress hardening, common-exploit blocks and fresh-CVE virtual patches. Install them in one click; updates arrive automatically over the license channel, so your sites stay patched against new attacks without manual rule-writing.

How does the free trial & licensing work?

Run the one-line installer and a 15-day trial activates automatically — one per server, no credit card. One license = one server with unlimited cPanel accounts; it binds to the server by hardware fingerprint and can be moved from your billing panel anytime.

Which operating systems are supported?

CentOS 7+, CloudLinux, AlmaLinux, Rocky Linux, Ubuntu and Debian — anywhere cPanel/WHM and ModSecurity run. The agent is a single static Go binary with no dependencies.

Stop flying blind on your WAF.

Start a free 15-day trial in minutes, or grab a license and finally see — and safely tune — what ModSecurity is doing on your server.

Start free trial Talk to us