More Options, Greater Value: Introducing Flexible cPGuard Pricing & Plans Built for Every Scale

More Options, Greater Value: Introducing Flexible cPGuard Pricing & Plans Built for Every Scale

More Options, Greater Value: Introducing Flexible cPGuard Pricing & Plans Built for Every Scale

At OPSSHIELD, our goal has always been to provide enterprise-grade web security that is both robust and accessible. As hosting environments evolve, server administrators need flexibility—paying only for what they actually use without sacrificing security features.

To better support every stage of your growth, we are introducing an updated plan structure with lower entry pricing and more options for right-sizing licenses as your hosting environment grows.

Important Notes for Our Clients:

  • Effective Date: The new plan structure will go into effect on September 16, 2026.
  • Existing Customers: All active subscriptions remain 100% untouched.
    Your current pricing and plan limits are fully grandfathered for your existing active services. They will retain their current pricing and license limits for as long as those subscriptions remain active.

What’s New?

We listened to your feedback. Many smaller hosting providers and admins needed an entry-level tier for lightweight VPS setups, while growing hosts wanted a dedicated step between mid-tier and unlimited limits.

To give you greater control over your security budget, we are introducing two brand-new plan tiers alongside our restructured options for new licenses:

Plan Level User Limit Monthly Subscription Annual Subscription (Billed Yearly)
Starter (New!) Up to 10 Users $3.50 / month $36/year ($3/month)
Growth Up to 50 Users $7.00 / month $72/year ($6/month)
Business (New!) Up to 250 Users $11.00 / month $108/year ($9/month)
Pro Unlimited Users $14.00 / month $132/year ($11/month)

 

Why This Delivers More Value

  • Unlocks Access at Just $3/Month: Running smaller VPS instances? You no longer have to pay for capacity you don’t need. The new 10-User Starter Plan lowers the entry point to just $3/month with annual billing.
  • Granular Scaling: Previously, crossing the 50-user threshold meant jumping directly to the Unlimited plan. The new 250-User Business Plan bridges that gap, giving growing hosting providers a more cost-effective option before they need an Unlimited license.
  • Legacy Rates Available with Annual Billing: For the 50-User and Unlimited plans, annual billing retains the same effective monthly rates as our previous pricing—$6/month for 50 Users and $11/month for Unlimited. This gives new licenses the option to maintain those established rates with an annual commitment.

Right-Sizing Security for Your Fleet

With more plan options and lower entry pricing, new deployments can choose the license that best matches the size of their server and scale as they grow.

Importantly, there are no feature compromises between tiers. Every cPGuard plan includes the same core security features, updates, and support—the only difference is the number of server users covered.

Built to Grow, Priced to Stay Accessible

Since its launch, cPGuard has continuously evolved alongside the needs of web hosting providers and server administrators. What began as a focused server security solution has grown into a comprehensive security suite, with advanced malware detection and automated cleanup, WAF integration, intelligent firewall protection, and continued developments such as our native LFD integration.

As cPGuard has expanded, our core philosophy has remained the same: powerful server security should remain accessible and cost-effective at every scale. Rather than simply increasing prices as the platform grows, our new plan structure gives customers more choice—allowing smaller deployments to start at a lower cost while providing clear, affordable steps as their infrastructure grows.

Whether you’re securing a small VPS or hundreds of hosting servers, you get the same cPGuard security features, updates, and support—the plan you choose simply reflects the size of the server you’re protecting.

For all existing active subscriptions, your current pricing and plan limits remain unchanged.

Moving Beyond Fail2ban with cPGuard’s Native LFD

Moving Beyond Fail2ban with cPGuard’s Native LFD

Next-Gen Brute-Force Protection: Why You Should Switch from Fail2ban to cPGuard LFD

Securing your servers against relentless brute-force and web-based attacks requires agility, speed, and deep integration. For years, Fail2ban has been the standard tool for monitoring logs and banning malicious IPs in cPGuard. However, as modern attack vectors evolve, standard tools can sometimes struggle under heavy load, consuming precious CPU and memory.

To solve this, we are thrilled to introduce CPG LFD—our brand-new, ultra-lightweight Login Failure Daemon designed specifically for cPGuard.

If you are currently running Fail2ban, here is why switching to cpglfd is the single best upgrade you can make for your server’s performance and security today.

What is cPGuard LFD ( cpglfd)?

cPGuard LFD is a proprietary, high-performance log-parsing and login-failure daemon built from the ground up to replace Fail2ban within the cPGuard ecosystem. It monitors system and application logs in real-time, detects malicious authentication attempts, and instantly mitigates brute-force attacks before they can overwhelm your applications, websites or control panels.

Why cpglfd eclipses traditional Fail2ban

While Fail2ban is a versatile tool, it is built as a generic solution. cpglfd, on the other hand, is purpose-built for web hosting environments running cPGuard.

1. Ultra-Lightweight & High Efficiency

Fail2ban can become resource-heavy, especially on busy servers with massive log files. It frequently spikes CPU usage when parsing logs under a heavy distributed brute-force attack. cpglfd has been engineered for maximum efficiency, boasting a microscopic resource footprint. It processes logs with minimal overhead, leaving your RAM and CPU free to serve your actual website traffic.

2. Native cPGuard firewall integration

Fail2ban relies on generic external wrappers to manipulate system firewalls, which can occasionally cause synchronization delays. The cpglfd features native, deep integration with the cPGuard firewall layer. When an IP is flagged for abuse, the block is injected directly and seamlessly into your cPGuard firewall rules instantly, ensuring zero-lag mitigation. When you enable Captcha protection in the firewall settings, the cpglfd block enabled Captcha verification for the blocked IPs and let the genuine users to unblock themselves.

3. Smarter web & Brute-Force defense

Because it is deeply embedded into our ecosystem, cpglfd possesses a contextual understanding of web attacks that generic tools lack. It works hand-in-hand with cPGuard’s existing threat intelligence, allowing it to differentiate between a genuinely malicious botnet and an accidental user typo much more effectively.

4. No need for third-party dependencies

Since cpglfd is developed inhouse, it does not need to install third-party packages and maintaining them.

The Verdict: cpglfd is the new recommended standard

To ensure our customers get the absolute best performance out of their infrastructure, cPGuard now officially recommends cpglfd over Fail2ban for all deployments.

By making the switch, you immediately unlock:

  • Better server response times under attack.
  • Drastically reduced CPU and memory overhead.
  • Tighter, unified security orchestration.

How to Switch

Transitioning from Fail2ban to the new LFD module is completely seamless. We have automated the process to ensure your server remains fully protected during the swap.

You can enable the new cpglfd module directly through your cPGuard’s Firewall settings page

Select server > Go to Firewall settings >  Turn on Intrusion Defence (lfd)

Fail2ban will be automatically turned off when lfd is turned ON

and using CLI, you can run the following command

 cpgcli lfd --enable

cPGuard Firewall: Enhanced Performance with iptables & new features

cPGuard Firewall: Enhanced Performance with iptables & new features

Announcing cPGuard Firewall 5.83.00: Enhanced Performance with iptables & New Features

We are excited to announce a major update to the cPGuard system firewall. Since our initial NFT-based launch in late 2025, we have been listening closely to your feedback and monitoring performance across diverse environments.
In version 5.83.00, we are introducing a revamped firewall architecture designed for stability, speed, and better user control.

The Shift: Returning to iptables/ipset

When we first introduced the NFT-based firewall, the goal was to leverage modern netfilter tools for a lighter, faster experience. However, real-world deployments presented unexpected challenges, including:

  • Stalled firewall rules and slow rule checks.
  • Unexpected rule failures.
  • Performance bottlenecks under heavy loads.

After extensive internal testing and consultation with our customers, we have decided to revamp the system using iptables/ipset as the primary provider. This ensures the reliability you expect from cPGuard, while still keeping nftables available as an option for those who prefer it.

What’s New in Version 5.83.00?

The latest version is more than just a provider shift; it includes several functional enhancements:

  • Optimized Performance: The iptables-based system is significantly faster and maintains a low system load, even when managing tens of thousands of IP addresses.
  • Advanced DoS Mitigation: New rules allow you to set connection limits per port/IP. The updated logic also resolves excessive logging issues during active attacks.
  • IP & Country Ignore Lists: Entries in the ignore list will now bypass deny rules and the IPDB, ensuring your trusted connections are never interrupted.
  • Flexible Providers: While iptables is now the default for new installations, you can switch between iptables and nftables at any time via the UI or CLI.

Introducing the New Grey List & Captcha Unlock

To reduce support tickets and improve the end-user experience, we’ve introduced a 24-hour Grey List.
If an IP is temporarily blocked, users can now use a Captcha-based unlock option to delist themselves (similar to CSF messenger).

Note: Currently available for cPanel and DirectAdmin, with support for more panels coming soon.

How to Switch to the iptables Firewall

To ensure stability, we are not enforcing the new iptables ruleset on existing installations automatically. If you wish to migrate your current server to the new firewall, you can do so via:

1. Command Line Interface (CLI): Run the following command:

cpgcli fw --provider iptables

2. App Portal: Navigate to Protection > Firewall and update your settings.

Looking Ahead: The New LFD Module

Our work doesn’t stop here. We are currently developing a new LFD (Log Failure Daemon) module to replace the existing Fail2ban-based monitoring. This new system will be:

  • Lighter and Faster: Built specifically for the cPGuard ecosystem.
  • Tightly Integrated: Allowing the Grey List to be fully utilized so genuine clients can easily unlock themselves after a block.

Stay tuned for these upcoming changes as we continue to evolve cPGuard to meet your security needs!

cPGuard Elevates Webuzo Security with New User-Level Plugin Integration

cPGuard Elevates Webuzo Security with New User-Level Plugin Integration

We are thrilled to announce a significant enhancement to the cPGuard ecosystem: the immediate availability of a user-level plugin for the Webuzo control panel.

In our latest release, we have bridged the gap between server-side security and end-user control. This elevated integration empowers hosting providers using Webuzo to offer premium, self-service security tools directly to their customers, fostering a safer and more transparent hosting environment.

Empowering the End-User

Security is no longer just the administrator’s responsibility; it is a collaborative effort. With this new integration, Webuzo users gain full visibility into their account’s security status.

Key capabilities now available to end-users include:

Detailed Malware Visibility: Users can view specific malware files detected within their account.

On-Demand Scanning: Users can initiate manual file scans instantly, ensuring peace of mind after site updates or uploads.

Real-Time Analytics: Access to comprehensive statistics regarding web attacks targeting their specific websites.

We believe this deeper integration is a game-changer for hosting providers. It allows you to deliver premium security tools that build trust with every client while reducing the support volume related to security queries.

A Quick Preface: What is cPGuard?

For those new to our platform, cPGuard is an all-in-one automated security suite specifically engineered for Linux web hosting servers. It acts as far more than a simple firewall; it provides a multi-layered defense system designed to catch threats that traditional antivirus software often misses.

Our architecture is built on robust pillars of protection:

Smart Malware Scanner: Detects and remediates threats automatically.

Web Application Firewall (WAF): Blocks exploits before they reach applications.

Proactive Attack Blocking (IPDB): A distributed firewall module that leverages global threat intelligence.

CMS Toolkit: Features auto-patching to secure WordPress and other CMS installations proactively.

Why cPGuard is the Strategic Choice

Choosing cPGuard is a strategic decision for server administrators who demand high-level security without the “performance tax” often associated with heavy security suites.

Here is why cPGuard stands out:

Superior Resource Efficiency: Designed to be lightweight, ensuring your server resources are dedicated to serving websites, not running security scans.

Surgical Malware Cleanup: Our intelligent engine cleans malicious injections from core files rather than simply deleting the file, keeping sites online and functional.

Collective IP Intelligence (IPDB): Our distributed firewall module instantly blocks abusive IPs detected anywhere in our global network.

Reduced Management Overhead: Automated tools and a unified dashboard make managing security across multiple servers effortless.

Get Started

Ready to upgrade your Webuzo server’s security posture? The new integration is available now.

Click here for the Installation Guide and Documentation

CSF Retired – Meet the new cPGuard Firewall

CSF Retired – Meet the new cPGuard Firewall

For many years, ConfigServer Firewall (CSF) was the go-to solution for Linux server security. It provided simple firewall management and IPS/IDS features that became staples in server hardening guides across the industry.

In the early days, cPGuard also relied on CSF as its firewall backend, later enhancing it with IPDB and Fail2ban integrations to provide brute-force protection. CSF’s flexibility made it a favourite among administrators.

But times have changed. CSF is now officially retired and unsupported on new servers. Manual firewall management is no longer practical in modern hosting environments, and administrators need something faster, smarter, and future-ready.

With the release of cPGuard v5.61, we’re proud to announce a fully rewritten, standalone firewall module — a drop-in replacement for CSF with far greater performance, efficiency, and usability.

Key Features

🔹 NFT at the Core

We moved away from the legacy iptables and ipset. The firewall is now built entirely on nftables, delivering better performance, a cleaner ruleset, and full compatibility with modern Linux distributions.

🔹 Easy Port Management

Effortlessly configure open TCP/UDP ports (incoming and outgoing) directly from the cPGuard dashboard or CLI.

🔹 Blocklist & Allowlist Controls

Quickly add or remove IP addresses — permanently or temporarily — with a single click.

🔹 Enhanced Protections

  • SYN flood defense
  • DoS mitigation
  • Country-based allow/deny rules
  • AI-powered bot blocking
  • And more, all built-in

Migration from CSF

Worried about losing your CSF configuration? Don’t be.
We provide a migration tool that automatically imports your existing CSF settings into the new firewall, including:

  • Port configurations (TCP_IN, TCP_OUT, UDP_IN, UDP_OUT)
  • Whitelisted IPs (csf.allow, csf.ignore)
  • Blacklisted IPs (csf.deny)
  • Country rules (CC_ALLOW, CC_DENY)

Run the import in one step:

/opt/cpguard/app/scripts/csf_migration.php

Future Roadmap

We’re not stopping here. Upcoming releases will introduce:

  • Port flood protection
  • Extended IDS/IPS features
  • More CSF-like enhancements — based on your feedback

If you relied on a specific CSF feature and would like to see it in cPGuard, let us know. Your input will help shape the evolution of the firewall.

Final Thoughts

The end of CSF may feel like the close of a chapter, but with the cPGuard Firewall, administrators gain a modern, NFT-driven, fully integrated security solution.

It doesn’t just replace CSF — it surpasses it, offering performance, simplicity, and scalability designed for today’s hosting environments.

We remain committed to continuously improving cPGuard’s firewall and security modules to keep your servers safe — now and into the future.