
cPanel Manager (from iControlWP) Security & Risk Analysis
wordpress.org/plugins/cpanel-manager-from-worpitThe cPanel Manager plugin from iControlWP: Secure Multiple WordPress Management
Is cPanel Manager (from iControlWP) Safe to Use in 2026?
Generally Safe
Score 85/100cPanel Manager (from iControlWP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cpanel-manager-from-worpit' plugin v1.8.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, performing capability checks for sensitive operations, and implementing nonce checks. Furthermore, its vulnerability history is clear, with no recorded CVEs, which suggests a history of stable and secure development or infrequent discovery of vulnerabilities.
However, there are significant concerns highlighted by the static analysis. The presence of the `exec` function is a critical red flag, as it allows for the execution of arbitrary system commands, which can lead to severe security compromises if not handled with extreme caution and robust input validation. The taint analysis revealing two flows with unsanitized paths, even if not classified as critical or high severity, indicates potential weaknesses in how external data is processed and could be exploited in conjunction with the `exec` function. The low percentage of properly escaped output (5%) is also a concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.
In conclusion, while the plugin has a clean vulnerability history and good adherence to some security best practices like prepared statements and capability checks, the presence of `exec` and unsanitized taint flows, coupled with poor output escaping, represents a substantial risk. The potential for command injection and XSS vulnerabilities necessitates careful review and remediation of these specific code issues.
Key Concerns
- Dangerous function exec found
- Taint flows with unsanitized paths (2)
- Low percentage of output escaping (5%)
cPanel Manager (from iControlWP) Security Vulnerabilities
cPanel Manager (from iControlWP) Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
cPanel Manager (from iControlWP) Attack Surface
WordPress Hooks 7
Maintenance & Trust
cPanel Manager (from iControlWP) Maintenance & Trust
Maintenance Signals
Community Trust
cPanel Manager (from iControlWP) Alternatives
DigiTimber cPanel Integration
digitimber-cpanel-integration
DigiTimber cPanel Integration allows users to access basic cPanel functionality from within WordPress. This plugin was created initially for our own u …
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
File Manager
wp-file-manager
file manager provides you ability to edit, delete, upload, download, copy and paste files and folders.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
cPanel Manager (from iControlWP) Developer Profile
5 plugins · 141K total installs
How We Detect cPanel Manager (from iControlWP)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cpanel-manager-from-worpit/css/cpanel-manager-worpit.css/wp-content/plugins/cpanel-manager-from-worpit/js/cpanel-manager-worpit.js/wp-content/plugins/cpanel-manager-from-worpit/js/cpanel-manager-worpit.jscpanel-manager-from-worpit/css/cpanel-manager-worpit.css?ver=cpanel-manager-from-worpit/js/cpanel-manager-worpit.js?ver=