cPanel Manager (from iControlWP) Security & Risk Analysis

wordpress.org/plugins/cpanel-manager-from-worpit

The cPanel Manager plugin from iControlWP: Secure Multiple WordPress Management

200 active installs v1.8.2 PHP + WP 3.2.0+ Updated Jun 16, 2017
cpanelmanage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is cPanel Manager (from iControlWP) Safe to Use in 2026?

Generally Safe

Score 85/100

cPanel Manager (from iControlWP) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'cpanel-manager-from-worpit' plugin v1.8.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, performing capability checks for sensitive operations, and implementing nonce checks. Furthermore, its vulnerability history is clear, with no recorded CVEs, which suggests a history of stable and secure development or infrequent discovery of vulnerabilities.

However, there are significant concerns highlighted by the static analysis. The presence of the `exec` function is a critical red flag, as it allows for the execution of arbitrary system commands, which can lead to severe security compromises if not handled with extreme caution and robust input validation. The taint analysis revealing two flows with unsanitized paths, even if not classified as critical or high severity, indicates potential weaknesses in how external data is processed and could be exploited in conjunction with the `exec` function. The low percentage of properly escaped output (5%) is also a concern, increasing the risk of cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin has a clean vulnerability history and good adherence to some security best practices like prepared statements and capability checks, the presence of `exec` and unsanitized taint flows, coupled with poor output escaping, represents a substantial risk. The potential for command injection and XSS vulnerabilities necessitates careful review and remediation of these specific code issues.

Key Concerns

  • Dangerous function exec found
  • Taint flows with unsanitized paths (2)
  • Low percentage of output escaping (5%)
Vulnerabilities
None known

cPanel Manager (from iControlWP) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

cPanel Manager (from iControlWP) Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
108
6 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

execif ( !@exec( 'ls ./', $outaOutput, $nReturn ) ) {src\common\icwp-data.php:185

Output Escaping

5% escaped114 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handleSubmit_security (cpanel-manager-worpit.php:173)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

cPanel Manager (from iControlWP) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedsrc\worpit-plugins-base.php:33
actioninitsrc\worpit-plugins-base.php:34
actionadmin_initsrc\worpit-plugins-base.php:36
actionadmin_noticessrc\worpit-plugins-base.php:37
actionadmin_menusrc\worpit-plugins-base.php:38
actionplugin_action_linkssrc\worpit-plugins-base.php:39
actionadmin_enqueue_scriptssrc\worpit-plugins-base.php:117
Maintenance & Trust

cPanel Manager (from iControlWP) Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJun 16, 2017
PHP min version
Downloads33K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

cPanel Manager (from iControlWP) Developer Profile

Paul

5 plugins · 141K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
125 days
View full developer profile
Detection Fingerprints

How We Detect cPanel Manager (from iControlWP)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cpanel-manager-from-worpit/css/cpanel-manager-worpit.css/wp-content/plugins/cpanel-manager-from-worpit/js/cpanel-manager-worpit.js
Script Paths
/wp-content/plugins/cpanel-manager-from-worpit/js/cpanel-manager-worpit.js
Version Parameters
cpanel-manager-from-worpit/css/cpanel-manager-worpit.css?ver=cpanel-manager-from-worpit/js/cpanel-manager-worpit.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about cPanel Manager (from iControlWP)