TECHNOLOGIES: PLESK

Plesk Security Review

A Plesk server holds every role, extension and API key ever granted, not just the sites it hosts. We test what each account, extension and credential can actually reach on that server. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Plesk Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Restricted

Restricted Mode is the setting that decides whether an additional administrator account has the same privileges as the default Administrator, or only the specific tasks you switch on for it.

Why Plesk security comes down to account roles and installed extensions

Plesk separates administration into an Administrator account, any additional administrator accounts, Reseller accounts and Customer accounts, and each sits at a different depth in the server. Plesk’s own documentation is direct about the risk here: an unrestricted additional administrator account, in its own words, ‘effectively has the same level of privileges and access to the server as the default administrator account’, which is why it recommends an individual account per person with Restricted Mode applied wherever full access is not actually needed. Underneath that sit Customer accounts and their own additional users, each assigned a role that Plesk’s role utility can restrict down to individual permissions such as managing websites and domains. We test what every account in that hierarchy can actually reach, not what its label implies it should be able to do.

Every entry in the Plesk Extensions Catalog is written by a party outside Plesk itself, and Plesk’s own extensions guide describes an extension as simply third-party software that adds new functionality to Plesk. Once installed, an extension gets its own access into Plesk’s entities and data to do its job, the same third-party risk we test on any platform built around an open extension model. WP Toolkit is one such extension, Plesk’s own tool for installing and managing WordPress sites from the panel, and it has to be installed from that same catalog before it appears. We review every installed extension’s access directly, and where WP Toolkit is managing live WordPress sites we can extend the review into our dedicated WordPress penetration testing scope.

Plesk also exposes a REST API, an XML API and command-line utilities, and access to all three is granted per role rather than assumed. Plesk’s documentation confirms that session-token creation is scoped by role: an administrator can create a token for anyone, a reseller only for themselves and their own customers, and a customer only for themselves, and an additional administrator needs the Ability to use remote API permission switched on before the API works at all. The XML API can authenticate with a secret key instead of a password, and Plesk stores only the key’s hash once it has been created. We test whether those role and permission boundaries actually hold when we call the API and CLI directly, not just what the panel’s own interface prevents.

SCOPE

What we review on a Plesk server

PL-01

User Roles: Administrator, Reseller and Customer Accounts

The default Administrator account can manage the whole server and every hosted website, and Plesk’s own guidance recommends an individual additional administrator account for each person who needs that level of access. Resellers create and manage the Customer accounts beneath them, and each Customer manages only their own subscriptions, so we test what each role can actually reach once granted.

PL-02

Additional Administrator Accounts: Restricted and Unrestricted Mode

An additional administrator account can be created as restricted or unrestricted, and Plesk’s documentation states plainly that an unrestricted account has the same level of privileges as the default Administrator. Restricted accounts are reliably tracked in the Action Log, while unrestricted ones can edit that log themselves, so we test which additional administrator accounts exist and whether Restricted Mode is actually switched on.

PL-03

Additional Users, Custom Roles and Subscription-Scoped Access

Additional users are created under a Customer account with a specific user role, and Plesk’s role utility grants each role individual permission flags, such as the ability to manage websites and domains, rather than one all-or-nothing switch. Access can also be limited to a single subscription or extended to every subscription the customer owns, and we test whether an additional user’s real access matches the role and subscription scope it was given.

PL-04

REST API, XML API and CLI Authentication

Plesk’s REST API scopes session-token creation by role: an administrator can create tokens for anyone, a reseller only for their own customers, and a customer only for themselves, with remote API access itself gated behind a separate permission for additional administrators and resellers. The XML API can also authenticate with a secret key that Plesk stores only as a hash, and we test whether those role boundaries and key permissions hold when we call the API and CLI directly.

PL-05

The Extensions Catalog: Third-Party Code Inside Plesk

Every extension in the Plesk Extensions Catalog is built by a party outside Plesk itself, and once installed it gets its own access into Plesk’s entities and data to do its job. We review each installed extension’s access and behaviour directly, the same third-party risk we test on any platform built around an open extension model.

PL-06

WP Toolkit: Managing WordPress Sites From the Panel

WP Toolkit is Plesk’s own extension for installing, updating and managing WordPress sites from the panel, and it must itself be installed from the Extensions Catalog before it appears in the interface. We test what WP Toolkit’s own management access adds on top of a site’s security, and can extend the review into our dedicated WordPress scope where the sites themselves also need testing.

PL-07

Firewall Policies, Rules and Fail2Ban IP Banning

The Plesk Firewall manages the server’s iptables rules through broad policies and narrower rules, and Plesk’s documentation is explicit that rules override policies, so one permissive rule can quietly undo a restrictive policy. The same extension also drives Fail2Ban-based IP banning, with a configurable ban period, detection window and trusted-IP allowlist, and we test the rule set and banning configuration together rather than either one alone.

PL-08

SSL/TLS Certificates and the ACME Extension

Plesk’s free ACME SSL extension automatically reissues and reinstalls SSL/TLS certificates so coverage does not lapse across hosted websites, replacing the manual reissue process Plesk’s own documentation describes as a chore. We test which certificates are actually current, how each website’s TLS configuration is set, and whether the underlying web server configuration handles both consistently.

PL-09

File Manager Permissions on Hosted Websites

File Manager’s Change Permissions control lets an account set file and directory permissions per hosted website, and Plesk’s documentation notes the control will not even appear for files owned outside the subscription, such as by root or the web server user. We test what permissions are actually set on each website’s files and directories, and whether a recursive change has left more exposed than intended.

PL-10

Backup Manager: Encryption, Storage and Access Restrictions

Backup Manager lets an administrator cap simultaneous backup processes, set server-wide compression and encryption, and centrally restrict whether customers and resellers can create backups at all or only to specific storage. We test how backup archives are stored and encrypted, and who, across every role on the server, can actually reach a completed backup.

OUR PROCESS

Plesk Security Review: From Scope to Attestation

01

Scope and Access

We agree the server, subscriptions, and Administrator, Reseller or Customer accounts included, plus any API or CLI access we need.

02

Role and Extension Mapping

We map every administrator, reseller, customer and additional user account against its actual permissions, and list every installed extension including WP Toolkit.

03

Manual Testing

A CREST-certified tester manually tests role boundaries, extension behaviour, firewall and Fail2Ban configuration, and API or CLI authentication.

04

Attestation and Retest

You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Plesk pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Plesk Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,060–£3,030
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£4,840–£7,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Plesk Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test a Plesk server?

We typically need an Administrator account plus at least one Reseller and one Customer account, so we can test what each role can actually reach, alongside SSH or RDP access to the underlying server where the scope includes it.

Does testing touch live customer data on the server?

We scope this with you before testing starts. Where the server hosts live customer sites and data, we agree which subscriptions are in scope and avoid destructive actions on production data unless you ask us to test recovery paths such as Backup Manager restores.

How long does a Plesk security review take?

A single Plesk server sits in our 2-day single-server scope, with a report typically landing around 5 working days after kickoff.

Do you test self-hosted Plesk differently from a managed hosting provider’s Plesk?

Yes. On a server you manage yourself, the Administrator account and every Reseller and Customer account underneath it are in scope. On managed or shared hosting, you may only hold a Reseller or Customer account, and we scope the review to what that account and its own additional users can reach.

What’s out of scope for a Plesk security review?

We test the Plesk installation, its configured roles, installed extensions, firewall and API access. We do not test the code of individual hosted applications such as a WordPress site unless you also scope a dedicated WordPress penetration test, or the underlying operating system beyond what Plesk itself configures.

Does Plesk’s vendor have a customer penetration-testing policy?

Plesk is licensed software you install and run on your own server, and its vendor, WebPros, publishes a coordinated vulnerability disclosure contact rather than a published customer testing policy for self-managed installations. If your server sits on shared or managed hosting, that provider’s own testing terms may apply, and we confirm current terms during scoping.

Can you test the WP Toolkit extension and the WordPress sites it manages?

Yes. We test what WP Toolkit itself exposes as part of this Plesk scope, and can extend testing to the WordPress sites it manages under our dedicated WordPress scope if you need the sites themselves covered too.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Plesk server

A Plesk server holds every role, extension and API key ever granted, not just the sites it hosts. We test what each account, extension and credential can actually reach on that server. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.