Skip to main content

How to Install and Load Monarx Protect on All PHP-FPM Versions

Written by Salvador Aguilar

Overview

On servers that run several PHP-FPM versions side by side, Monarx Protect may load into only one of them, and the hosting partner needs to manually copy and enable the extension in every PHP-FPM version. This guide walks hosting partners through confirming the extension files are installed, enabling them per PHP-FPM version, and restarting every PHP-FPM service so Protect loads everywhere.

Monarx Protect is our PHP RASP extension that powers ThreatShield. It loads independently into each PHP handler, and each PHP-FPM version has its own configuration and scan directory. The monarx-protect-autodetect package covers common setups (standard Apache, LiteSpeed, cPanel, Plesk), but custom or multi-version PHP-FPM environments — custom FPM pools, Remi or alt-PHP builds, non-default extension directories — often need this manual customization.

Who this is for: server administrators and hosting partners with root access.

Before you start: make sure the Monarx repository is added and reachable. If you're not sure, follow the repository checks in Troubleshooting: Monarx Protect Extension Not Installed or Not Loading first.

Symptoms

  • In the Monarx web app, Agents > [your agent] > Extensions shows Protect loaded for only one PHP version (or only the CLI).

  • php -m | grep monarxprotect returns monarxprotect for the default PHP, but returns nothing for other PHP-FPM binaries on the same server.

  • Sites served by one PHP version are protected while sites on other versions are not.

Step 1: Check that every Monarx Protect extension file is installed

The monarx-protect package ships one .so file per supported PHP version. Confirm the full set is on the server before enabling anything.

RHEL / CentOS / CloudLinux / AlmaLinux / Rocky:

repoquery -l monarx-protect

repoquery is part of yum-utils (or dnf-utils). If the command isn't found, install it with sudo yum install yum-utils, or on dnf-based systems run dnf repoquery -l monarx-protect.

You should see a file for every PHP version, similar to:

/usr/lib64/monarx-protect/monarxprotect-php53.so 
/usr/lib64/monarx-protect/monarxprotect-php54.so
/usr/lib64/monarx-protect/monarxprotect-php55.so
[...]
/usr/lib64/monarx-protect/monarxprotect-php72.so
[...]
/usr/lib64/monarx-protect/monarxprotect-php82.so
/usr/lib64/monarx-protect/monarxprotect-php83.so
/usr/lib64/monarx-protect/monarxprotect-php84.so

Note: repoquery lists the files the package contains in the repository. To confirm the files are actually present on disk, also run one of these:

# Files installed by the package (RPM-based systems) 
rpm -ql monarx-protect

# Files installed by the package (Ubuntu / Debian)
dpkg -L monarx-protect | grep '\.so$'

# Direct check of the extension directory
ls -1 /usr/lib64/monarx-protect/

If the list matches the full range of PHP versions, skip to Step 3. If files are missing, or the directory doesn't exist, continue with Step 2.

Step 2: Install (or reinstall) the monarx-protect package

If any extension files are missing, install the base monarx-protect package with your package manager. Use the base package here, not monarx-protect-autodetect, since you'll enable the extension manually in the next steps.

RHEL / CentOS / CloudLinux / AlmaLinux / Rocky:

sudo yum install monarx-protect  

# If the package is already installed but files are missing:
sudo yum reinstall monarx-protect

Ubuntu / Debian:

sudo apt-get update sudo apt-get install monarx-protect  

# If the package is already installed but files are missing:
sudo apt-get install --reinstall monarx-protect

Then re-run the check from Step 1 to confirm every .so file is now present:

# RPM-based systems 
rpm -ql monarx-protect

# Ubuntu / Debian
dpkg -L monarx-protect | grep '\.so$'

If files are still missing after installing, the Monarx repository is likely unreachable or not enabled. Follow the repository checks in the troubleshooting guide before continuing.

Step 3: List every PHP-FPM version installed on the server

Each PHP-FPM version needs the extension enabled separately, so first build the full list. These commands work on most systemd-based servers:

# All PHP-FPM services, running or not 
systemctl list-unit-files --type=service | grep -i fpm

# PHP-FPM master processes currently running
ps aux | grep 'php-fpm: master' | grep -v grep

You can also list versions by control panel or distribution:

Environment

Command

Service name pattern

cPanel / EasyApache 4

ls -d /opt/cpanel/ea-php*

ea-php84-php-fpm

Plesk

plesk bin php_handler --list | grep -i fpm

plesk-php84-fpm

Ubuntu / Debian

ls /etc/php/

php8.4-fpm

Remi (RHEL-based)

ls -d /etc/opt/remi/php*

php84-php-fpm

For each version, find the configuration scan directory that its FPM binary reads. Don't rely on the default php CLI binary — it may use a different version and a different config than your PHP-FPM pools. For example:

# cPanel example for PHP 8.4 
/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -i | grep -E 'Scan this dir|extension_dir'

# Ubuntu / Debian example for PHP 8.4
php-fpm8.4 -i | grep -E 'Scan this dir|extension_dir'

Note the Scan this dir for additional .ini files path for each version. You'll add the Monarx configuration there in Step 4.

Step 4: Enable Monarx Protect in each PHP-FPM version

For every PHP-FPM version from Step 3, add the extension line that matches that PHP version. The example below is for PHP 8.4:

extension=monarxprotect-php84.so

Use monarxprotect-php83.so for PHP 8.3, monarxprotect-php82.so for PHP 8.2, and so on. Loading a .so built for a different PHP version will fail.

1. Make the .so file available to that PHP version. Either copy or symlink it into the version's extension_dir:

# cPanel example for PHP 8.4 
ln -s /usr/lib64/monarx-protect/monarxprotect-php84.so \ "$(/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -i | awk -F'=> ' '/^extension_dir/{print $2}' | awk '{print $1}')/"

Or reference the full path directly in the .ini file instead of copying:

extension=/usr/lib64/monarx-protect/monarxprotect-php84.so

2. Create a .ini file in that version's scan directory. For example:

Environment

Example file (PHP 8.4)

cPanel / EasyApache 4

/opt/cpanel/ea-php84/root/etc/php.d/monarxprotect.ini

Plesk

/opt/plesk/php/8.4/etc/php.d/monarxprotect.ini

Ubuntu / Debian

/etc/php/8.4/fpm/conf.d/monarxprotect.ini

Remi (RHEL-based)

/etc/opt/remi/php84/php.d/monarxprotect.ini

echo 'extension=monarxprotect-php84.so' | sudo tee /opt/cpanel/ea-php84/root/etc/php.d/monarxprotect.ini

3. Repeat for every PHP-FPM version, changing both the version in the file path and the .so filename.

Tip: Before adding the line, check that the version doesn't already load Protect, for example with grep -r monarxprotect <scan dir>. Loading the extension twice produces a "Module already loaded" warning.

Tip: Control panels can overwrite PHP configuration during updates or rebuilds. After adding a new PHP version or a panel update, re-check that the Monarx .ini file is still in place.

Step 5: Restart all PHP-FPM versions

PHP-FPM keeps the previously loaded extensions in memory until it is fully restarted. A reload, or restarting only Apache/Nginx, will not load Monarx Protect into PHP-FPM.

Restart every PHP-FPM service on the server in one command:

systemctl list-units --type=service --all --no-legend '*fpm*' | awk '{print $1}' | xargs -r sudo systemctl restart

Or restart each version individually:

# cPanel / EasyApache 4 systemctl restart ea-php84-php-fpm 

# or restart all cPanel PHP-FPM versions at once
/scripts/restartsrv_apache_php_fpm

# Plesk systemctl restart plesk-php84-fpm

# Ubuntu / Debian
systemctl restart php8.4-fpm

# Remi
systemctl restart php84-php-fpm

Then confirm every PHP-FPM service came back up:

systemctl list-units --type=service --all '*fpm*'

💡 CloudLinux with CageFS: after restarting, also remount all cages so caged users pick up the change:

cagefsctl --remount-all

Verify it worked

Check each PHP-FPM binary directly — not just the default php CLI:

# cPanel example 
/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -m | grep monarxprotect

# Ubuntu / Debian example
php-fpm8.4 -m | grep monarxprotect

Each should return monarxprotect. Then, in the Monarx web app, go to Agents, select the agent, and open the Extensions tab. Every PHP-FPM version should now list Monarx Protect, all on the same Protect version. If you see two different versions, see Why Do I See Two Versions of Monarx Protect on My Server?

Still having issues?

If Protect still doesn't load on one or more PHP-FPM versions, contact Monarx support and include:

  • The output of -i | grep -E 'Scan this dir|extension_dir' for each affected PHP-FPM binary

  • The output of rpm -ql monarx-protect or dpkg -L monarx-protect

  • Your control panel (cPanel, Plesk, none) and the PHP-FPM versions in use

Related articles

Did this answer your question?