Overview
On servers that run several PHP-FPM versions side by side, Monarx Protect may load into only one of them, and the hosting partner needs to manually copy and enable the extension in every PHP-FPM version. This guide walks hosting partners through confirming the extension files are installed, enabling them per PHP-FPM version, and restarting every PHP-FPM service so Protect loads everywhere.
Monarx Protect is our PHP RASP extension that powers ThreatShield. It loads independently into each PHP handler, and each PHP-FPM version has its own configuration and scan directory. The monarx-protect-autodetect package covers common setups (standard Apache, LiteSpeed, cPanel, Plesk), but custom or multi-version PHP-FPM environments — custom FPM pools, Remi or alt-PHP builds, non-default extension directories — often need this manual customization.
Who this is for: server administrators and hosting partners with root access.
Before you start: make sure the Monarx repository is added and reachable. If you're not sure, follow the repository checks in Troubleshooting: Monarx Protect Extension Not Installed or Not Loading first.
Symptoms
In the Monarx web app, Agents > [your agent] > Extensions shows Protect loaded for only one PHP version (or only the CLI).
php -m | grep monarxprotectreturnsmonarxprotectfor the default PHP, but returns nothing for other PHP-FPM binaries on the same server.Sites served by one PHP version are protected while sites on other versions are not.
Step 1: Check that every Monarx Protect extension file is installed
The monarx-protect package ships one .so file per supported PHP version. Confirm the full set is on the server before enabling anything.
RHEL / CentOS / CloudLinux / AlmaLinux / Rocky:
repoquery -l monarx-protect
repoquery is part of yum-utils (or dnf-utils). If the command isn't found, install it with sudo yum install yum-utils, or on dnf-based systems run dnf repoquery -l monarx-protect.
You should see a file for every PHP version, similar to:
/usr/lib64/monarx-protect/monarxprotect-php53.so
/usr/lib64/monarx-protect/monarxprotect-php54.so
/usr/lib64/monarx-protect/monarxprotect-php55.so
[...]
/usr/lib64/monarx-protect/monarxprotect-php72.so
[...]
/usr/lib64/monarx-protect/monarxprotect-php82.so
/usr/lib64/monarx-protect/monarxprotect-php83.so
/usr/lib64/monarx-protect/monarxprotect-php84.so
Note: repoquery lists the files the package contains in the repository. To confirm the files are actually present on disk, also run one of these:
# Files installed by the package (RPM-based systems)
rpm -ql monarx-protect
# Files installed by the package (Ubuntu / Debian)
dpkg -L monarx-protect | grep '\.so$'
# Direct check of the extension directory
ls -1 /usr/lib64/monarx-protect/
If the list matches the full range of PHP versions, skip to Step 3. If files are missing, or the directory doesn't exist, continue with Step 2.
Step 2: Install (or reinstall) the monarx-protect package
If any extension files are missing, install the base monarx-protect package with your package manager. Use the base package here, not monarx-protect-autodetect, since you'll enable the extension manually in the next steps.
RHEL / CentOS / CloudLinux / AlmaLinux / Rocky:
sudo yum install monarx-protect
# If the package is already installed but files are missing:
sudo yum reinstall monarx-protect
Ubuntu / Debian:
sudo apt-get update sudo apt-get install monarx-protect
# If the package is already installed but files are missing:
sudo apt-get install --reinstall monarx-protect
Then re-run the check from Step 1 to confirm every .so file is now present:
# RPM-based systems
rpm -ql monarx-protect
# Ubuntu / Debian
dpkg -L monarx-protect | grep '\.so$'
If files are still missing after installing, the Monarx repository is likely unreachable or not enabled. Follow the repository checks in the troubleshooting guide before continuing.
Step 3: List every PHP-FPM version installed on the server
Each PHP-FPM version needs the extension enabled separately, so first build the full list. These commands work on most systemd-based servers:
# All PHP-FPM services, running or not
systemctl list-unit-files --type=service | grep -i fpm
# PHP-FPM master processes currently running
ps aux | grep 'php-fpm: master' | grep -v grep
You can also list versions by control panel or distribution:
Environment | Command | Service name pattern |
cPanel / EasyApache 4 |
|
|
Plesk |
|
|
Ubuntu / Debian |
|
|
Remi (RHEL-based) |
|
|
For each version, find the configuration scan directory that its FPM binary reads. Don't rely on the default php CLI binary — it may use a different version and a different config than your PHP-FPM pools. For example:
# cPanel example for PHP 8.4
/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -i | grep -E 'Scan this dir|extension_dir'
# Ubuntu / Debian example for PHP 8.4
php-fpm8.4 -i | grep -E 'Scan this dir|extension_dir'
Note the Scan this dir for additional .ini files path for each version. You'll add the Monarx configuration there in Step 4.
Step 4: Enable Monarx Protect in each PHP-FPM version
For every PHP-FPM version from Step 3, add the extension line that matches that PHP version. The example below is for PHP 8.4:
extension=monarxprotect-php84.so
Use monarxprotect-php83.so for PHP 8.3, monarxprotect-php82.so for PHP 8.2, and so on. Loading a .so built for a different PHP version will fail.
1. Make the .so file available to that PHP version. Either copy or symlink it into the version's extension_dir:
# cPanel example for PHP 8.4
ln -s /usr/lib64/monarx-protect/monarxprotect-php84.so \ "$(/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -i | awk -F'=> ' '/^extension_dir/{print $2}' | awk '{print $1}')/"
Or reference the full path directly in the .ini file instead of copying:
extension=/usr/lib64/monarx-protect/monarxprotect-php84.so
2. Create a .ini file in that version's scan directory. For example:
Environment | Example file (PHP 8.4) |
cPanel / EasyApache 4 |
|
Plesk |
|
Ubuntu / Debian |
|
Remi (RHEL-based) |
|
echo 'extension=monarxprotect-php84.so' | sudo tee /opt/cpanel/ea-php84/root/etc/php.d/monarxprotect.ini
3. Repeat for every PHP-FPM version, changing both the version in the file path and the .so filename.
Tip: Before adding the line, check that the version doesn't already load Protect, for example with grep -r monarxprotect <scan dir>. Loading the extension twice produces a "Module already loaded" warning.
Tip: Control panels can overwrite PHP configuration during updates or rebuilds. After adding a new PHP version or a panel update, re-check that the Monarx .ini file is still in place.
Step 5: Restart all PHP-FPM versions
PHP-FPM keeps the previously loaded extensions in memory until it is fully restarted. A reload, or restarting only Apache/Nginx, will not load Monarx Protect into PHP-FPM.
Restart every PHP-FPM service on the server in one command:
systemctl list-units --type=service --all --no-legend '*fpm*' | awk '{print $1}' | xargs -r sudo systemctl restart
Or restart each version individually:
# cPanel / EasyApache 4 systemctl restart ea-php84-php-fpm
# or restart all cPanel PHP-FPM versions at once
/scripts/restartsrv_apache_php_fpm
# Plesk systemctl restart plesk-php84-fpm
# Ubuntu / Debian
systemctl restart php8.4-fpm
# Remi
systemctl restart php84-php-fpm
Then confirm every PHP-FPM service came back up:
systemctl list-units --type=service --all '*fpm*'
💡 CloudLinux with CageFS: after restarting, also remount all cages so caged users pick up the change:
cagefsctl --remount-all
Verify it worked
Check each PHP-FPM binary directly — not just the default php CLI:
# cPanel example
/opt/cpanel/ea-php84/root/usr/sbin/php-fpm -m | grep monarxprotect
# Ubuntu / Debian example
php-fpm8.4 -m | grep monarxprotect
Each should return monarxprotect. Then, in the Monarx web app, go to Agents, select the agent, and open the Extensions tab. Every PHP-FPM version should now list Monarx Protect, all on the same Protect version. If you see two different versions, see Why Do I See Two Versions of Monarx Protect on My Server?
Still having issues?
If Protect still doesn't load on one or more PHP-FPM versions, contact Monarx support and include:
The output of
-i | grep -E 'Scan this dir|extension_dir'for each affected PHP-FPM binaryThe output of
rpm -ql monarx-protectordpkg -L monarx-protectYour control panel (cPanel, Plesk, none) and the PHP-FPM versions in use


