cPanel and WHM Security Review
A cPanel and WHM server’s risk is the reseller privileges, account permissions and exposed services your team configured, not cPanel’s own code. We test the accounts, ACLs and settings you control. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
WHM lets root delegate specific ACL privileges to a reseller account, or grant a Root Access ACL that carries the same privileges as root itself, rather than sharing full server access by default.
Why cPanel and WHM security comes down to reseller ACLs and account permissions
WHM’s root user does not have to hand every reseller full control of the server. cPanel’s own reseller privileges documentation splits access into Basic, Standard, Package, Global and Super Privileges categories, plus a separate Root Access ACL that grants a reseller root-level privileges on the server. We test which ACLs a reseller account actually holds against what that reseller’s role requires.
API tokens let an account or a reseller run functions without ever logging in to cPanel or WHM, and cPanel’s own documentation states plainly that ACL restriction on WHM-level API tokens is still an experimental feature. A cPanel-level token can carry Unrestricted access to any function with no associated feature, while a WHM-level token currently only works against WHM API functions, DNS clusters and configuration clusters. We test every token in scope for what it can actually reach, not what it was meant to reach.
Controls such as cPHulk brute force blocking, two-factor authentication and ModSecurity rules only work if they are switched on and correctly scoped to the accounts on your server. cPHulk covers cPanel, WHM, mail and SSH logins by default, but it does not affect public key authentication or API tokens, so a server can look protected on its login pages while a token or key-based route stays wide open. We test each control as configured on your server, not against a generic checklist, alongside the wider Linux server configuration WHM sits on.
SCOPE
What we review on a cPanel and WHM server
WHM Root Access and Reseller ACL Delegation
WHM’s root user can delegate specific privileges to reseller accounts through Access Control Lists, or grant a Root Access ACL that gives the reseller the same privileges as root itself. We test which ACLs each reseller actually holds and whether any exceed what the account needs.
cPanel API Tokens (UAPI-Level, Per Account)
Each cPanel account can issue its own API tokens to run UAPI and cPanel API 2 functions without a password, including Unrestricted tokens that reach any function with no associated feature. We test which tokens exist, what they can reach, and whether a leaked token exposes more than intended.
WHM API Tokens (Root and Reseller Level)
WHM API tokens authenticate against the server’s remote API, DNS clusters and configuration clusters, and cPanel’s own documentation flags ACL restriction on these tokens as an experimental feature. We test what a leaked WHM-level token can actually do against your server.
Two-Factor Authentication for cPanel and WHM Logins
cPanel and WHM’s built-in 2FA secures both login interfaces with a time-based one-time password app, and a hosting provider controls whether a reseller can even reach the 2FA configuration screen. We check whether 2FA is enforced for every account that can reach a cPanel or WHM login, not only root.
cPHulk Brute Force Protection Configuration
cPHulk monitors cPanel, WHM, mail and SSH login attempts and blocks an IP address once it passes a set number of failures, but it does not affect public key authentication or API tokens. We test whether cPHulk is active, correctly tuned and covers every exposed login service on the server.
ModSecurity Rule Management in WHM
WHM’s ModSecurity Tools interface lets an administrator add, edit, disable or delete web application firewall rules across every hosted domain, and a hosting provider can grant or withhold this ability from a reseller by ACL. We review which rules are active, which have been disabled, and what that leaves exposed.
Feature Manager: Package and Account Feature Restrictions
Feature lists assigned to a package control which cPanel features an account can reach, and the disabled feature list overrides every other list’s settings for whatever it defines. We test whether the feature lists in use actually restrict accounts the way the hosting plan intends.
AutoSSL and the SSL/TLS Manager
AutoSSL automatically issues domain-validated certificates for Apache, Dovecot, Exim, Web Disk and the cPanel service itself, running nightly and after every new account for any user whose feature list enables it. We check certificate coverage, renewal behaviour and the manually managed certificates in the SSL/TLS Manager alongside it.
File Manager Permissions on Hosted Applications
cPanel’s File Manager changes file and folder permissions from a default of 0644, and a misapplied permission on a hosted application’s files is a change your team made, not a cPanel default. We review permissions across the accounts in scope for anything that exposes application code or data.
Cron Job Scheduling and Script Execution
Cron Jobs run on a schedule an account holder defines, and a hosting provider can disable the feature entirely through Feature Manager if it is not required. We review what each scheduled job executes and whether it runs with more access than the task needs.
OUR PROCESS
cPanel and WHM Security Review: From Scope to Attestation
Scope and Access
We agree which cPanel accounts, WHM access level and reseller accounts sit in scope.
ACL and Token Mapping
We map every reseller ACL, package feature list and API token against what each account actually needs.
Manual Testing
A CREST-certified tester manually tests account permissions, exposed services and server-level controls for exploitable weaknesses.
Attestation and Retest
You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST cPanel and WHM pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent cPanel and WHM Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test cPanel and WHM For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From cPanel and WHM Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test a cPanel and WHM server?
We ask for a WHM login with the relevant reseller or root-level ACLs for the accounts in scope, plus SSH access where server configuration is part of the engagement. We agree the exact access and account list with you before testing starts.
Will testing touch the live data on my hosted accounts?
We test the accounts, permissions and configuration you nominate in scope, and we agree with you upfront which live services we can interact with. Where a test could affect live mail, databases or websites, we scope a maintenance window or a staging copy instead.
How long does a cPanel and WHM security review take?
A single server sits in our 2-day single-server scope, with a report typically landing around 5 working days after kickoff. A server running many cPanel accounts or several resellers may need a larger scope, which we agree during scoping.
Does this apply if my server is with a managed hosting provider?
Yes. Whether you run the server yourself or a provider manages it for you, we test the WHM and cPanel configuration, accounts and permissions in place. If a managed provider controls root access, we agree with you and them what access we need before testing starts.
What’s out of scope for a cPanel and WHM review?
We test the server’s cPanel and WHM configuration, accounts, ACLs and exposed services, not cPanel and WHM’s own underlying source code. Applications hosted on the accounts, such as a WordPress or Joomla site, are scoped and quoted separately.
Does cPanel have a customer penetration-testing policy we need to follow?
cPanel and WHM is licensed software that runs on a server you or your hosting provider controls, so there is no cPanel vendor authorisation process for testing your own installation. cPanel’s own security.txt file points reports about the product itself to a HackerOne-listed vulnerability disclosure programme; if your server sits with a hosting or cloud provider, their own penetration-testing policy still applies, and we confirm current terms during scoping.
Do you test at root level, reseller level, or both?
We scope the test to the access level relevant to your engagement: a single reseller’s ACLs and accounts, or full root-level WHM access across every account on the server. We agree which level applies during scoping.
Are you testing cPanel and WHM for vulnerabilities in the software itself?
No. We test how your server’s accounts, ACLs, feature lists and exposed services are configured, not cPanel and WHM’s own code. If we identify a suspected flaw in the product itself, we report it through the vulnerability disclosure programme listed in cPanel’s own security.txt file, rather than in your test scope.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your cPanel server
A cPanel and WHM server’s risk is the reseller privileges, account permissions and exposed services your team configured, not cPanel’s own code. We test the accounts, ACLs and settings you control. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.



