WebFacing™ – Email Accounts management for cPanel® Security & Risk Analysis

wordpress.org/plugins/wf-cpanel-email-accounts

WebFacing™ - Email Accounts management for cPanel®

200 active installs v5.3.6 PHP 8.1+ WP 6.5+ Updated Jan 10, 2025
auto-replybackupcpanelemailmembership
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WebFacing™ – Email Accounts management for cPanel® Safe to Use in 2026?

Generally Safe

Score 92/100

WebFacing™ – Email Accounts management for cPanel® has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "wf-cpanel-email-accounts" v5.3.6 exhibits a generally positive security posture with no known historical vulnerabilities or critical code signals. The absence of known CVEs and a lack of critical taint flows are significant strengths. However, the static analysis reveals concerning areas that temper this otherwise good impression. A major weakness is the complete lack of output escaping for all 147 identified outputs, presenting a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, while SQL queries are prepared, the presence of three file operations and zero nonce or capability checks on any entry points, despite having a zero attack surface, raises questions about how data might be manipulated or accessed without proper validation. The vulnerability history is clean, which is excellent, but the code analysis suggests that if vulnerabilities were to arise, they could be impactful due to the unescaped outputs and potential for insecure file operations.

Key Concerns

  • 0% output escaping on 147 outputs
  • 0 capability checks on entry points
  • 0 nonce checks on entry points
  • 3 file operations without context
Vulnerabilities
None known

WebFacing™ – Email Accounts management for cPanel® Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WebFacing™ – Email Accounts management for cPanel® Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
147
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

0% escaped147 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

12 flows3 with unsanitized paths
admin (includes\NewEmail.php:21)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WebFacing™ – Email Accounts management for cPanel® Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

WebFacing™ – Email Accounts management for cPanel® Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 10, 2025
PHP min version8.1
Downloads23K

Community Trust

Rating100/100
Number of ratings8
Active installs200
Developer Profile

WebFacing™ – Email Accounts management for cPanel® Developer Profile

Knut Sparhell

1 plugin · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WebFacing™ – Email Accounts management for cPanel®

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wf-cpanel-email-accounts/assets/cpanel.js
Script Paths
/wp-content/plugins/wf-cpanel-email-accounts/assets/cpanel.js
Version Parameters
wf-cpanel-email-accounts/assets/cpanel.js?ver=

HTML / DOM Fingerprints

CSS Classes
wf-cpanel-email-accounts
Data Attributes
data-chartiddata-adminuridata-datauridata-secretdata-tokendata-host+2 more
JS Globals
wFcPanelSettings
Shortcode Output
<form method="post" action="https://:2096//login" target="" class="
FAQ

Frequently Asked Questions about WebFacing™ – Email Accounts management for cPanel®