DigiTimber cPanel Integration Security & Risk Analysis

wordpress.org/plugins/digitimber-cpanel-integration

DigiTimber cPanel Integration allows users to access basic cPanel functionality from within WordPress. This plugin was created initially for our own u …

100 active installs v1.4.8 PHP 7.2+ WP 6.0+ Updated Jan 27, 2025
cpanelemailmailmanage
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2025
Safety Verdict

Is DigiTimber cPanel Integration Safe to Use in 2026?

Generally Safe

Score 91/100

DigiTimber cPanel Integration has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 31, 2025Updated 1yr ago
Risk Assessment

The digitimber-cpanel-integration plugin, version 1.4.8, exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and a lack of critical or high severity taint flows are positive indicators. The presence of nonce checks, even with a limited number of total flows, is also a good practice. However, a significant concern arises from the low percentage of properly escaped output (17%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress environment.

The plugin's vulnerability history reveals a single medium severity CVE, which has since been patched. While this is a positive sign that vulnerabilities are addressed, the historical presence of a CVE, even a medium one, coupled with the identified output escaping issues, suggests a need for continued vigilance. The current lack of unpatched vulnerabilities is reassuring, but the static analysis findings highlight potential weaknesses that could be exploited if not addressed.

In conclusion, the plugin demonstrates strengths in its limited attack surface and secure handling of core functionalities like SQL and file operations. However, the prevalent issue of unescaped output presents a substantial risk that warrants immediate attention to prevent potential XSS attacks. While the vulnerability history is not alarming, it serves as a reminder that proactive security measures are crucial.

Key Concerns

  • Low percentage of properly escaped output
  • Past medium severity CVE
Vulnerabilities
1

DigiTimber cPanel Integration Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22690medium · 6.1Cross-Site Request Forgery (CSRF)

DigiTimber cPanel Integration <= 1.4.6 - Cross-Site Request Forgery to Stored Cross-site Scripting

Jan 31, 2025 Patched in 1.4.8 (4d)
Code Analysis
Analyzed Mar 16, 2026

DigiTimber cPanel Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
4 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

17% escaped23 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
dt_cpanel_email (digitimber-cpanel.php:229)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DigiTimber cPanel Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menudigitimber-cpanel.php:21
Maintenance & Trust

DigiTimber cPanel Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 27, 2025
PHP min version7.2
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

DigiTimber cPanel Integration Developer Profile

DigiTimber

1 plugin · 100 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect DigiTimber cPanel Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/digitimber-cpanel-integration/css/style.css/wp-content/plugins/digitimber-cpanel-integration/js/dt-cpanel.js
Script Paths
/wp-content/plugins/digitimber-cpanel-integration/js/dt-cpanel.js
Version Parameters
digitimber-cpanel-integration/css/style.css?ver=digitimber-cpanel-integration/js/dt-cpanel.js?ver=

HTML / DOM Fingerprints

CSS Classes
dt-cpanel-settings-pagedt-cpanel-emaildt-top-level-handle
Data Attributes
data-cpanel-usernamedata-cpanel-password
JS Globals
dtcpaneldt_cpanel_js_vars
FAQ

Frequently Asked Questions about DigiTimber cPanel Integration