More than a WAF.
A complete PHP security platform.
Inspector Pro protects PHP websites and CMS platforms in real time, connects isolated security events into one incident timeline and explains what happened, why it matters and how to respond.
From the first request to a complete investigation
Each module adds context. Instead of hundreds of disconnected logs, the administrator receives one clear incident story.
Attack
A suspicious request reaches the website.
Adaptive WAF
The request is normalized and the attack technique is identified.
Threat Engine
Risk, source reputation and repeated behavior are evaluated.
Timeline
Related events are linked into one sequence.
Reconstruction
The platform reconstructs the attack stages and verdict.
Response
The source is blocked, evidence is preserved and alerts are sent.
The full attack in one chronological context
Inspector Pro combines requests, WAF decisions, file-system events and administrator actions into one incident timeline.
Scanning activity detected
Service paths and CMS indicators were enumerated from one IP address.
SQL injection attempt
The request matched the waf.sqli.union signature and was stopped.
Web shell upload attempt
A dangerous PHP payload was correlated with the previous activity.
Source blocked
The decision and supporting evidence were preserved.
Essential protection tools in one platform
Adaptive WAF
Detects SQLi, XSS, LFI, RFI, SSRF, command injection, PHP injection and normalization bypasses.
Malware Scanner
Finds web shells, backdoors, loaders, obfuscation and suspicious PHP constructs.
Active File Protection
Monitors file changes and can isolate unknown executable files automatically.
SAST
Finds vulnerable PHP code and dangerous functions before exploitation.
IOC & Reputation
Uses local and managed threat indicators, ASN, PTR and source history.
Correlation Engine
Combines weak signals into confirmed incidents and response scenarios.
Attack Timeline
Shows requests, decisions, blocks, file changes and administrator actions chronologically.
Managed Updates
Receives signed protection updates and threat intelligence without exposing internal infrastructure.
Control every file on your website
Inspector Pro detects file-system changes, analyzes new objects and isolates unknown executable files before they can cause damage.
Integrity monitoring
Tracks created, modified and deleted application files.
Malicious code detection
Identifies web shells, backdoors, loaders and obfuscated PHP.
Automatic quarantine
Unknown executable files can be moved into protected quarantine automatically.
Complete audit trail
Stores file path, time, reason, risk level, action and result.
Safe restoration
Verified files can be restored without losing the original path and incident context.
Trusted change approval
Legitimate website updates can be accepted without disabling protection.
Active File Protection
/public/uploads/cache.phpThe original path and metadata are preserved. The administrator is notified and the event is attached to the incident history.
Website protection and incident investigation in one product
| Capability | Inspector Pro | Typical WAF |
|---|---|---|
| Web attack blocking | Yes | Yes |
| Malware detection | Yes | No |
| File integrity monitoring | Yes | Limited |
| Attack Timeline | Yes | No |
| Attack reconstruction | Yes | No |
| SAST and dangerous functions | Yes | No |
| Automatic quarantine | Yes, with audit logging | No |
Choose the right protection level
The same agent can be upgraded without reinstallation. International pricing is provided individually during the trial stage.
Monitoring
For one website that needs continuous visibility without an active WAF.
- One website and one agent
- Server health and heartbeat
- HTTP request monitoring
- External availability checks
- 30-day event history
Analysis and control
For commercial websites, agencies and managed client projects.
- Everything in Basic
- Malware Scanner
- SAST and dangerous functions
- File integrity monitoring
- Automatic quarantine
- Extended event retention
Active protection
A complete security layer with active prevention and attack investigation.
- Active WAF and firewall
- Attack Timeline
- Attack reconstruction
- IOC and Threat Intelligence
- Correlation and automated response
Enterprise and multi-site licensing is available on request.
Connect your first website and see the real threat picture
After email confirmation and application approval, you will receive a trial agent package and a one-time installation code.
Frequently asked questions
Can the agent be installed above the website root?
Yes. This is the recommended setup: only a minimal entry point remains inside the public directory, while code, configuration and logs stay outside the web root.
Does it work on shared hosting?
Yes, when the hosting plan supports PHP, scheduled tasks and access to the website directory. Available features depend on hosting restrictions such as open_basedir.
Is Inspector Pro self-hosted?
The protection agent runs on your own server. Website files and local security logs remain under your control. Signed protection updates and optional threat intelligence can be delivered without transferring website source code.
Will there be native CMS modules?
Yes. WordPress, Joomla, OpenCart and other platforms can receive dedicated integrations for deeper platform-specific analysis.