Skip to content

Whitelist files, folders and signatures

In cPFence v4+, use Threat & Malware Detection to manage malware exceptions and recover quarantined files. Administrators can use these controls; support users need access to the server and the relevant exclusions, preview, restore, or file-action permissions.

  1. Open Advanced Tools and check the sidebar’s target servers. These controls use bulk targets, separately from the page’s history selector.
  2. Choose Whitelist a Path or File Name, enter Path or File Name, and click Whitelist.
  3. Check the confirmation and each server’s result.
  4. To reverse it, choose Remove from Whitelist, enter the same value, and click Remove.

Whitelist a Path or File Name form with the Path or File Name field and Whitelist button.

Enter the intended path expression in the whitelist form. Select the image for full size; use browser Back to return.

The path input is a regular expression. A filename or broad expression can skip files across many sites. Anchor a file-specific expression and escape regex punctuation: ^/var/www/example\.com/public_html/known-clean\.php$ is an example, not a path to copy unchanged.

For an exact file or directory-tree exception, a root administrator can instead use one of these actions with the actual absolute path:

Action Command
Add exact-path exception cpfence --exclude-exact-path /var/www/example.com/public_html/known-clean.php
Remove exact-path exception cpfence --del-exclude-exact-path /var/www/example.com/public_html/known-clean.php

For a pattern, use quoted regular expressions so the shell does not expand them:

Scope Example expression
Files with one basename across sites /error_log$
One specific file ^/var/www/example\.com/public_html/known-clean\.php$
Paths containing a directory component /trusted-backup/

Add with cpfence --exclude-path 'EXPRESSION' and remove with cpfence --del-exclude-path 'EXPRESSION', substituting the actual expression. Exact-path controls are preferable when you mean one file or one tree.

Remove from Whitelist form with the Path or File Name field and Remove button.

To remove an exception, enter the same expression in Remove from Whitelist. Select the image for full size; use browser Back to return.

For a signature exception, choose Manage signature exclusions, copy the finding’s Signature name, then Add exclusion or Remove exclusion. This suppresses that signature across the server’s eligible scans. Other signatures remain active; ClamAV signature exceptions belong to email scanning.

Signature Exclusions form with Signature name, Add exclusion and Remove exclusion controls.

Use the finding’s actual signature name. The input is blank and the existing configured entry is concealed; no exclusion was added or removed. Select the image for full size; use browser Back to return.

Root CLI equivalents are cpfence --exclude-sig SIGNATURE_NAME and cpfence --del-exclude-sig SIGNATURE_NAME. Copy the actual finding identifier. Legacy file-hash exclusions are not a website scanning policy in cPFence v4+; use an exact-path or narrow signature/path exception.

A signature-specific allowlist permits one signature at a full or suffix path and still checks other signatures. It is separate from Trust this exact file, which suppresses future malware detections at that original path. Ask your root administrator for a narrow allowlist entry when a server-wide signature exception would be too broad.

Exceptions do not clean or restore files. Quick scans bypass configured operator exclusions. WP-AutoShield Exclusions and Integrity Check Exclusions affect their named WordPress features, not malware scans.

An exception does not recover a file already moved. Follow identify and restore quarantined files to preview stored bytes and choose recovery deliberately. Trust this exact file creates a path exception; leave it unchecked unless that is intended.

See automatic quarantine to choose isolation or reporting, and change retention before delaying recovery.

For a suspected false positive, choose Report False Positive, fill Subject and Details, attach the flagged file in an accepted type, and include detection logs. Click Send. Submission requests review; it does not create an exception. Omit credentials and unrelated private data.

Report Malware False Positive form with detection-log guidance, Subject, Details, Attachment and Send controls.

The report needs detection logs and the flagged file. This form has no attachment or entered values. Select the image for full size; use browser Back to return.