TECHNOLOGIES: CPANEL AND WHM

cPanel and WHM Security Review

A cPanel and WHM server’s risk is the reseller privileges, account permissions and exposed services your team configured, not cPanel’s own code. We test the accounts, ACLs and settings you control. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
cPanel and WHM Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Delegated

WHM lets root delegate specific ACL privileges to a reseller account, or grant a Root Access ACL that carries the same privileges as root itself, rather than sharing full server access by default.

Why cPanel and WHM security comes down to reseller ACLs and account permissions

WHM’s root user does not have to hand every reseller full control of the server. cPanel’s own reseller privileges documentation splits access into Basic, Standard, Package, Global and Super Privileges categories, plus a separate Root Access ACL that grants a reseller root-level privileges on the server. We test which ACLs a reseller account actually holds against what that reseller’s role requires.

API tokens let an account or a reseller run functions without ever logging in to cPanel or WHM, and cPanel’s own documentation states plainly that ACL restriction on WHM-level API tokens is still an experimental feature. A cPanel-level token can carry Unrestricted access to any function with no associated feature, while a WHM-level token currently only works against WHM API functions, DNS clusters and configuration clusters. We test every token in scope for what it can actually reach, not what it was meant to reach.

Controls such as cPHulk brute force blocking, two-factor authentication and ModSecurity rules only work if they are switched on and correctly scoped to the accounts on your server. cPHulk covers cPanel, WHM, mail and SSH logins by default, but it does not affect public key authentication or API tokens, so a server can look protected on its login pages while a token or key-based route stays wide open. We test each control as configured on your server, not against a generic checklist, alongside the wider Linux server configuration WHM sits on.

SCOPE

What we review on a cPanel and WHM server

CP-01

WHM Root Access and Reseller ACL Delegation

WHM’s root user can delegate specific privileges to reseller accounts through Access Control Lists, or grant a Root Access ACL that gives the reseller the same privileges as root itself. We test which ACLs each reseller actually holds and whether any exceed what the account needs.

CP-02

cPanel API Tokens (UAPI-Level, Per Account)

Each cPanel account can issue its own API tokens to run UAPI and cPanel API 2 functions without a password, including Unrestricted tokens that reach any function with no associated feature. We test which tokens exist, what they can reach, and whether a leaked token exposes more than intended.

CP-03

WHM API Tokens (Root and Reseller Level)

WHM API tokens authenticate against the server’s remote API, DNS clusters and configuration clusters, and cPanel’s own documentation flags ACL restriction on these tokens as an experimental feature. We test what a leaked WHM-level token can actually do against your server.

CP-04

Two-Factor Authentication for cPanel and WHM Logins

cPanel and WHM’s built-in 2FA secures both login interfaces with a time-based one-time password app, and a hosting provider controls whether a reseller can even reach the 2FA configuration screen. We check whether 2FA is enforced for every account that can reach a cPanel or WHM login, not only root.

CP-05

cPHulk Brute Force Protection Configuration

cPHulk monitors cPanel, WHM, mail and SSH login attempts and blocks an IP address once it passes a set number of failures, but it does not affect public key authentication or API tokens. We test whether cPHulk is active, correctly tuned and covers every exposed login service on the server.

CP-06

ModSecurity Rule Management in WHM

WHM’s ModSecurity Tools interface lets an administrator add, edit, disable or delete web application firewall rules across every hosted domain, and a hosting provider can grant or withhold this ability from a reseller by ACL. We review which rules are active, which have been disabled, and what that leaves exposed.

CP-07

Feature Manager: Package and Account Feature Restrictions

Feature lists assigned to a package control which cPanel features an account can reach, and the disabled feature list overrides every other list’s settings for whatever it defines. We test whether the feature lists in use actually restrict accounts the way the hosting plan intends.

CP-08

AutoSSL and the SSL/TLS Manager

AutoSSL automatically issues domain-validated certificates for Apache, Dovecot, Exim, Web Disk and the cPanel service itself, running nightly and after every new account for any user whose feature list enables it. We check certificate coverage, renewal behaviour and the manually managed certificates in the SSL/TLS Manager alongside it.

CP-09

File Manager Permissions on Hosted Applications

cPanel’s File Manager changes file and folder permissions from a default of 0644, and a misapplied permission on a hosted application’s files is a change your team made, not a cPanel default. We review permissions across the accounts in scope for anything that exposes application code or data.

CP-10

Cron Job Scheduling and Script Execution

Cron Jobs run on a schedule an account holder defines, and a hosting provider can disable the feature entirely through Feature Manager if it is not required. We review what each scheduled job executes and whether it runs with more access than the task needs.

OUR PROCESS

cPanel and WHM Security Review: From Scope to Attestation

01

Scope and Access

We agree which cPanel accounts, WHM access level and reseller accounts sit in scope.

02

ACL and Token Mapping

We map every reseller ACL, package feature list and API token against what each account actually needs.

03

Manual Testing

A CREST-certified tester manually tests account permissions, exposed services and server-level controls for exploitable weaknesses.

04

Attestation and Retest

You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST cPanel and WHM pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent cPanel and WHM Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,060–£3,030
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£4,840–£7,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From cPanel and WHM Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test a cPanel and WHM server?

We ask for a WHM login with the relevant reseller or root-level ACLs for the accounts in scope, plus SSH access where server configuration is part of the engagement. We agree the exact access and account list with you before testing starts.

Will testing touch the live data on my hosted accounts?

We test the accounts, permissions and configuration you nominate in scope, and we agree with you upfront which live services we can interact with. Where a test could affect live mail, databases or websites, we scope a maintenance window or a staging copy instead.

How long does a cPanel and WHM security review take?

A single server sits in our 2-day single-server scope, with a report typically landing around 5 working days after kickoff. A server running many cPanel accounts or several resellers may need a larger scope, which we agree during scoping.

Does this apply if my server is with a managed hosting provider?

Yes. Whether you run the server yourself or a provider manages it for you, we test the WHM and cPanel configuration, accounts and permissions in place. If a managed provider controls root access, we agree with you and them what access we need before testing starts.

What’s out of scope for a cPanel and WHM review?

We test the server’s cPanel and WHM configuration, accounts, ACLs and exposed services, not cPanel and WHM’s own underlying source code. Applications hosted on the accounts, such as a WordPress or Joomla site, are scoped and quoted separately.

Does cPanel have a customer penetration-testing policy we need to follow?

cPanel and WHM is licensed software that runs on a server you or your hosting provider controls, so there is no cPanel vendor authorisation process for testing your own installation. cPanel’s own security.txt file points reports about the product itself to a HackerOne-listed vulnerability disclosure programme; if your server sits with a hosting or cloud provider, their own penetration-testing policy still applies, and we confirm current terms during scoping.

Do you test at root level, reseller level, or both?

We scope the test to the access level relevant to your engagement: a single reseller’s ACLs and accounts, or full root-level WHM access across every account on the server. We agree which level applies during scoping.

Are you testing cPanel and WHM for vulnerabilities in the software itself?

No. We test how your server’s accounts, ACLs, feature lists and exposed services are configured, not cPanel and WHM’s own code. If we identify a suspected flaw in the product itself, we report it through the vulnerability disclosure programme listed in cPanel’s own security.txt file, rather than in your test scope.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your cPanel server

A cPanel and WHM server’s risk is the reseller privileges, account permissions and exposed services your team configured, not cPanel’s own code. We test the accounts, ACLs and settings you control. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.