Plesk Security Review
A Plesk server holds every role, extension and API key ever granted, not just the sites it hosts. We test what each account, extension and credential can actually reach on that server. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Restricted Mode is the setting that decides whether an additional administrator account has the same privileges as the default Administrator, or only the specific tasks you switch on for it.
Why Plesk security comes down to account roles and installed extensions
Plesk separates administration into an Administrator account, any additional administrator accounts, Reseller accounts and Customer accounts, and each sits at a different depth in the server. Plesk’s own documentation is direct about the risk here: an unrestricted additional administrator account, in its own words, ‘effectively has the same level of privileges and access to the server as the default administrator account’, which is why it recommends an individual account per person with Restricted Mode applied wherever full access is not actually needed. Underneath that sit Customer accounts and their own additional users, each assigned a role that Plesk’s role utility can restrict down to individual permissions such as managing websites and domains. We test what every account in that hierarchy can actually reach, not what its label implies it should be able to do.
Every entry in the Plesk Extensions Catalog is written by a party outside Plesk itself, and Plesk’s own extensions guide describes an extension as simply third-party software that adds new functionality to Plesk. Once installed, an extension gets its own access into Plesk’s entities and data to do its job, the same third-party risk we test on any platform built around an open extension model. WP Toolkit is one such extension, Plesk’s own tool for installing and managing WordPress sites from the panel, and it has to be installed from that same catalog before it appears. We review every installed extension’s access directly, and where WP Toolkit is managing live WordPress sites we can extend the review into our dedicated WordPress penetration testing scope.
Plesk also exposes a REST API, an XML API and command-line utilities, and access to all three is granted per role rather than assumed. Plesk’s documentation confirms that session-token creation is scoped by role: an administrator can create a token for anyone, a reseller only for themselves and their own customers, and a customer only for themselves, and an additional administrator needs the Ability to use remote API permission switched on before the API works at all. The XML API can authenticate with a secret key instead of a password, and Plesk stores only the key’s hash once it has been created. We test whether those role and permission boundaries actually hold when we call the API and CLI directly, not just what the panel’s own interface prevents.
SCOPE
What we review on a Plesk server
User Roles: Administrator, Reseller and Customer Accounts
The default Administrator account can manage the whole server and every hosted website, and Plesk’s own guidance recommends an individual additional administrator account for each person who needs that level of access. Resellers create and manage the Customer accounts beneath them, and each Customer manages only their own subscriptions, so we test what each role can actually reach once granted.
Additional Administrator Accounts: Restricted and Unrestricted Mode
An additional administrator account can be created as restricted or unrestricted, and Plesk’s documentation states plainly that an unrestricted account has the same level of privileges as the default Administrator. Restricted accounts are reliably tracked in the Action Log, while unrestricted ones can edit that log themselves, so we test which additional administrator accounts exist and whether Restricted Mode is actually switched on.
Additional Users, Custom Roles and Subscription-Scoped Access
Additional users are created under a Customer account with a specific user role, and Plesk’s role utility grants each role individual permission flags, such as the ability to manage websites and domains, rather than one all-or-nothing switch. Access can also be limited to a single subscription or extended to every subscription the customer owns, and we test whether an additional user’s real access matches the role and subscription scope it was given.
REST API, XML API and CLI Authentication
Plesk’s REST API scopes session-token creation by role: an administrator can create tokens for anyone, a reseller only for their own customers, and a customer only for themselves, with remote API access itself gated behind a separate permission for additional administrators and resellers. The XML API can also authenticate with a secret key that Plesk stores only as a hash, and we test whether those role boundaries and key permissions hold when we call the API and CLI directly.
The Extensions Catalog: Third-Party Code Inside Plesk
Every extension in the Plesk Extensions Catalog is built by a party outside Plesk itself, and once installed it gets its own access into Plesk’s entities and data to do its job. We review each installed extension’s access and behaviour directly, the same third-party risk we test on any platform built around an open extension model.
WP Toolkit: Managing WordPress Sites From the Panel
WP Toolkit is Plesk’s own extension for installing, updating and managing WordPress sites from the panel, and it must itself be installed from the Extensions Catalog before it appears in the interface. We test what WP Toolkit’s own management access adds on top of a site’s security, and can extend the review into our dedicated WordPress scope where the sites themselves also need testing.
Firewall Policies, Rules and Fail2Ban IP Banning
The Plesk Firewall manages the server’s iptables rules through broad policies and narrower rules, and Plesk’s documentation is explicit that rules override policies, so one permissive rule can quietly undo a restrictive policy. The same extension also drives Fail2Ban-based IP banning, with a configurable ban period, detection window and trusted-IP allowlist, and we test the rule set and banning configuration together rather than either one alone.
SSL/TLS Certificates and the ACME Extension
Plesk’s free ACME SSL extension automatically reissues and reinstalls SSL/TLS certificates so coverage does not lapse across hosted websites, replacing the manual reissue process Plesk’s own documentation describes as a chore. We test which certificates are actually current, how each website’s TLS configuration is set, and whether the underlying web server configuration handles both consistently.
File Manager Permissions on Hosted Websites
File Manager’s Change Permissions control lets an account set file and directory permissions per hosted website, and Plesk’s documentation notes the control will not even appear for files owned outside the subscription, such as by root or the web server user. We test what permissions are actually set on each website’s files and directories, and whether a recursive change has left more exposed than intended.
Backup Manager: Encryption, Storage and Access Restrictions
Backup Manager lets an administrator cap simultaneous backup processes, set server-wide compression and encryption, and centrally restrict whether customers and resellers can create backups at all or only to specific storage. We test how backup archives are stored and encrypted, and who, across every role on the server, can actually reach a completed backup.
OUR PROCESS
Plesk Security Review: From Scope to Attestation
Scope and Access
We agree the server, subscriptions, and Administrator, Reseller or Customer accounts included, plus any API or CLI access we need.
Role and Extension Mapping
We map every administrator, reseller, customer and additional user account against its actual permissions, and list every installed extension including WP Toolkit.
Manual Testing
A CREST-certified tester manually tests role boundaries, extension behaviour, firewall and Fail2Ban configuration, and API or CLI authentication.
Attestation and Retest
You get a technical report with CVSS scores, a walkthrough call, a free retest, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Plesk pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Plesk Security Review Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 5 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Plesk For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Plesk Security Review
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test a Plesk server?
We typically need an Administrator account plus at least one Reseller and one Customer account, so we can test what each role can actually reach, alongside SSH or RDP access to the underlying server where the scope includes it.
Does testing touch live customer data on the server?
We scope this with you before testing starts. Where the server hosts live customer sites and data, we agree which subscriptions are in scope and avoid destructive actions on production data unless you ask us to test recovery paths such as Backup Manager restores.
How long does a Plesk security review take?
A single Plesk server sits in our 2-day single-server scope, with a report typically landing around 5 working days after kickoff.
Do you test self-hosted Plesk differently from a managed hosting provider’s Plesk?
Yes. On a server you manage yourself, the Administrator account and every Reseller and Customer account underneath it are in scope. On managed or shared hosting, you may only hold a Reseller or Customer account, and we scope the review to what that account and its own additional users can reach.
What’s out of scope for a Plesk security review?
We test the Plesk installation, its configured roles, installed extensions, firewall and API access. We do not test the code of individual hosted applications such as a WordPress site unless you also scope a dedicated WordPress penetration test, or the underlying operating system beyond what Plesk itself configures.
Does Plesk’s vendor have a customer penetration-testing policy?
Plesk is licensed software you install and run on your own server, and its vendor, WebPros, publishes a coordinated vulnerability disclosure contact rather than a published customer testing policy for self-managed installations. If your server sits on shared or managed hosting, that provider’s own testing terms may apply, and we confirm current terms during scoping.
Can you test the WP Toolkit extension and the WordPress sites it manages?
Yes. We test what WP Toolkit itself exposes as part of this Plesk scope, and can extend testing to the WordPress sites it manages under our dedicated WordPress scope if you need the sites themselves covered too.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Plesk server
A Plesk server holds every role, extension and API key ever granted, not just the sites it hosts. We test what each account, extension and credential can actually reach on that server. CREST-certified testers, fixed price from £2,060 for a 2-day single-server scope, quoted within 24 hours.



