Skip to main content

How to Manage Security for Your Cloudways Velocity Application

Learn how to review security alerts, manage suspicious IP addresses, check domain reputation, configure firewall rules, and enable malware protection for your Cloudways Velocity application.

Written by Syed Abuzar Mehdi

The Security section in Cloudways Velocity provides tools to review suspicious activity and protect your application from unwanted access, harmful files, and unsafe traffic.

From this section, you can:

  • Review a summary of recorded security alerts.

  • Inspect individual security incidents.

  • Allow or block specific IP addresses.

  • Check whether your application domain has been reported as unsafe.

  • Create firewall rules for IP addresses, IP ranges, and countries.

  • Enable Malware Protection for your application.

These security tools use Imunify360 technology to help identify suspicious activity, control access, and protect applications from malicious files and requests.

Important:
Security tools reduce risk but do not replace secure passwords, safe application code, updated dependencies, controlled access, and regular backups.


Prerequisites

Before you begin, make sure that:

  • You have an active Cloudways Velocity application.

  • You can access the application through the Cloudways Platform.

  • You know the IP address, country, or security event you want to review before changing a firewall rule.


How to Manage Security for Your Cloudways Velocity Application

The Velocity Security section gives you a single location to review security alerts, investigate suspicious requests, manage access rules, check domain reputation, and enable Malware Protection.

Review each event before taking action. Careful use of IP rules, country blocking, and malware protection can improve security without interrupting legitimate users or connected services.

Access the Security Section

  • Log in to the Cloudways Platform.

  • From the left navigation menu, select Velocity.

  • Select My Applications.

  • Choose the application you want to manage.

  • From the application management menu, select Security.

  • The Security section contains the following pages:

    • Overview

    • Incidents

    • Domain Reputation

    • Firewall

    • Malware Protection


Review the Security Overview

  • Navigate to: Velocity → My Applications → Select Application → Security → Overview

  • The Overview page summarizes security activity recorded during the selected period.

  • Use the time-period dropdown to choose the period you want to review, such as the Last 30 Days. Select Refresh to retrieve the latest available information.

  • The dashboard displays the following items.

Total Alerts

Shows the total number of security alerts recorded during the selected period.

An alert means that the security system detected an event that may require review. An alert does not always mean that the application was successfully attacked.

SplashScreen Events

Shows events in which suspicious visitors were presented with a security verification screen before they could continue.

This check helps distinguish normal visitors from automated or suspicious requests.

Files Cleaned

Shows the number of harmful or infected files cleaned by the security system.

Malware Detected

Shows how many malware threats were found during the selected period.

Malware is harmful code or a file designed to damage, change, misuse, or gain unauthorized access to an application.

OSSEC: Network-Level Attacks

Shows suspicious activity detected at the network or server access level.

This can include repeated unauthorized access attempts or other activity that matches known attack patterns.

WAF Alerts

  • Shows alerts generated by the Web Application Firewall.

  • A Web Application Firewall, or WAF, checks incoming requests and blocks requests that appear harmful before they reach the application.

Note:

A value of zero means that no matching event was recorded during the selected period. It does not guarantee that an application has no security risk.


Review Security Incidents

  • Navigate to: Velocity → My Applications → Select Application → Security → Incidents

  • An incident is suspicious activity detected by the security system. The Incidents page is updated regularly and helps you review what happened, where the request came from, and how serious the event may be.

  • You can use Search by IP to locate incidents connected to a specific IP address. Select Refresh to load the latest incidents.

  • Click on the 3 dots menu to move to whitelist or move to block list.

Understand the Incident Details

The table displays the following information:

Date & Time

Shows when the incident was recorded.

The displayed time may use UTC. Consider the time difference when comparing an incident with your local records.

IP

Shows the IP address connected to the detected activity.

An IP address identifies the device, service, or network that sent the request.

Count

Shows how many related events were recorded.

Event

Provides a brief description of the suspicious activity detected by the security system.

Severity

Shows the estimated importance of the event, such as Medium.

Severity helps you prioritize incidents, but it should be reviewed together with the event details, frequency, and source IP.

Actions

Provides options to add the IP address to the allow list or block list.

Allow or Block an IP Address from an Incident (Shown in the Image above)

  1. Open Security → Incidents.

  2. Locate the required incident.

  3. Select the three-dot menu in the Actions column.

  4. Choose one of the following:

Move to White List

  • Allows requests from the IP address.

  • Use this only when you recognize the IP and trust the person, service, integration, or monitoring system using it.

Move to Black List

  • Blocks requests from the IP address.

  • Use this when you confirm that the address is sending harmful, abusive, or unwanted requests.

Confirm the action when prompted. Cloudways security controls also allow IP addresses to be moved between allowed and blocked states directly from recorded incidents.

Warning:

Do not allow an unfamiliar IP only because a legitimate request failed. Confirm the IP owner and purpose first. Similarly, blocking an IP used by your team or a trusted service may interrupt access or application functions.


Check Domain Reputation

  • Navigate to: Velocity → My Applications → Select Application → Security → Domain Reputation

  • Domain Reputation checks whether a domain connected to your application has been reported as unsafe or blocked by supported reputation services.

If an issue is detected, the table may display:

  • App Name: The affected Velocity application.

  • Domain: The domain reported by a reputation service.

  • Threat Type: The type of security concern detected.

  • Vendor: The service that reported the issue.

  • Detection Time: When the issue was identified.

  • Actions: Available options for reviewing or managing the result.

  • Use the search icon to locate a particular domain and select Refresh to retrieve the latest status.

  • When no issue is detected, the page displays No domains affected.

  • A domain may receive a poor reputation after malware, phishing pages, spam activity, unsafe redirects, compromised application code, or other suspicious behavior is detected.

Important:

Removing harmful content does not always remove a domain from an external block list immediately. The reporting provider may need to scan the domain again or review a removal request.


Manage Firewall Rules

  • Navigate to: Velocity → My Applications → Select Application → Security → Firewall

  • A firewall controls which network requests are allowed to reach your application.

From this page, you can:

  • Search for an existing IP address.

  • Review allowed and blocked rules.

  • Filter the displayed rules.

  • Search by location.

  • Add a custom IP rule.

  • Block incoming traffic from selected countries.

  • Refresh the rule list.

Cloudways firewall controls support custom rules for IP addresses, IP ranges, and country-based blocking.

Understand the Firewall Table

IP

Shows the IP address or IP range covered by the rule.

Purpose

Shows whether the IP is allowed or blocked.

  • White: The IP is allowed.

  • Black: The IP is blocked.

TTL

TTL means Time to Live. It shows how long a temporary firewall rule remains active.

When the TTL expires, the rule is removed automatically.

Country

Shows the country connected to the IP address.

Event

Explains why or how the rule was added, such as an automatically allowed IP.

Actions

Provides available controls for the selected rule, such as deleting it.

Search Existing Firewall Rules

You can locate an existing rule in two ways.

Search by IP Address

Enter the IP address in the Search by IP field.

Search by Location

  1. Open the Location dropdown.

  2. Enter the country name in the search field or scroll through the list.

  3. Select the required country.

Select Refresh to retrieve the latest rules.

Add a Custom IP Rule

Use a custom IP rule to allow or block a particular IP address or IP range.

  1. Open Security → Firewall.

  2. Select Add Custom Rule.

  3. Keep the IP Address tab selected.

  4. Enter an IP address or an IP range in CIDR format.

CIDR is a standard way to define a group of IP addresses. For example, a CIDR range can apply one rule to an entire network instead of a single address.

  1. Optional: Enter a TTL value and select its time unit.

Leave the TTL empty when the rule should remain active until it is manually removed.

  1. Select one of the following:

White List

Allows the entered IP address or range.

Black List

Blocks the entered IP address or range.

Optional: Enter a clear description in Add Comment.

For example:

Office IP — allowed for application administration

  • Select Add IP Address.

Tip: Add a comment that explains who owns the IP and why the rule was created. This makes it easier to review or remove the rule later.

Block Traffic from a Country

Country blocking prevents incoming requests from selected countries from reaching your application.

  • Open Security → Firewall.

  • Select Add Custom Rule.

  • Select the Country tab.

  • Open the Select Countries to block dropdown.

  • Search for or select one or more countries.

  • Select Apply.

  • Optional: Enter a reason in Add Comment.

  • Select Block.

Warning:

Blocking a country blocks incoming connections from that region. This may also block legitimate users, team members, search services, payment systems, external APIs, or monitoring tools. Test your application after applying the rule.


Enable Malware Protection

  • Navigate to: Velocity → My Applications → Select Application → Security → Malware Protection

  • Malware Protection scans your application for harmful code and helps clean detected threats. It is powered by Imunify360 and provides automated scanning and cleanup features.

  • The page shows whether Malware Protection is currently active. When it is available with your Velocity plan but not enabled, select Enable Protection.

Enable Protection

  1. Open Security → Malware Protection.

  2. Review the displayed protection information.

  3. Select Enable Protection.

  4. Wait for activation to complete.

  5. Return to the page and confirm that protection is active.

The protection shown in the Platform may include:

Phishing Protection

Helps detect and block harmful pages or code designed to steal passwords or other private information.

System Protection

Helps protect the application environment from harmful activity.

Database Protection

Checks for harmful content inserted into the application database and cleans supported threats.

Malware Cleanup

Automatically cleans supported infected files after malware is detected.

Proactive Defense

Checks application activity while it runs and blocks supported malware actions before they complete.

Other Protection

  • Provides additional protection against supported online attacks and suspicious activity.

  • Malware Protection uses real-time and scheduled scanning, detection, and automated cleanup to protect supported applications.

Note:

Malware Protection is displayed as included in the plan in the current Velocity interface. Availability may depend on your active Velocity plan and application status.


Recommended Security Practices

  • Review the Overview and Incidents pages regularly, especially after unusual traffic or an application error.

  • Allow an IP address only after confirming that it belongs to a trusted user or service.

  • Use temporary TTL values when access is needed only for a limited period.

  • Avoid blocking an entire country when blocking a specific harmful IP address is sufficient.

  • Enable Malware Protection when it is available but inactive.

  • Keep application dependencies and packages current. Security tools can block many threats, but they cannot correct unsafe or outdated application code.

  • Review security alerts together with the application access, error, and runtime logs before making major changes.

  • Maintain current backups so the application can be restored if files or data are damaged.


Frequently Asked Questions

Does a security incident mean that my application was compromised?

No. An incident means that suspicious activity was detected. The security system may have blocked the request before it affected the application.

What is the difference between allowing and blocking an IP?

Allowing an IP permits its requests to reach the application. Blocking an IP prevents its requests from reaching the application.

Should I block every IP shown in the Incidents section?

No. Some incidents may be caused by automated scans, shared networks, trusted services, or incorrectly identified requests. Review the event before blocking the IP.

What happens when a firewall TTL expires?

A rule with a TTL is removed automatically when the selected time ends.

Can I block several countries at the same time?

Yes. The country rule allows you to select more than one country before applying the block.

What should I do when my domain is reported as unsafe?

Review your Malware Protection results and application logs, remove harmful content, change exposed credentials, and inspect recent application changes. You may also need to request another review from the service that reported the domain.

Does Malware Protection replace application security practices?

No. Continue using strong passwords, secure authentication, restricted access, safe application code, current dependencies, and regular backups.

What should I do if trusted users cannot access the application?

Check the Incidents and Firewall sections to confirm that their IP address or country was not blocked. Remove or update the incorrect rule after confirming that the access is legitimate.


That's it! We hope this article was helpful.

Did this answer your question?