Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WHMCS

WHMCS Vendor Cyber Rating & Cyber Score

whmcs.com

Founded in early 2017, WebPros brings together some widely used web hosting, billing automation, infrastructure, server management, and online marketing software solutions. Constantly adding new brands and products to its portfolio, in its current formula, WebPros comprises WHMCS, Plesk, cPanel, SiteJet, WP Squared, WHMCS, XOVI, SocialBee, and SolusVM. Overall, we power more than 85 million websites on more than 900,000 servers worldwide. WHMCS is the world's leading online billing and automation platform for web hosts and domain registrars. Our integrated platform enables web hosting providers to automate their operations, reduce costs and improve customer support as well as providing customers with self service access to manage their


WHMCS A.I CyberSecurity Scoring

WHMCS
Company Information
Website:https://www.whmcs.com/
Employees number:29
Number of followers:2,946
NAICS:5112
Industry Type:Software Development
Homepage:whmcs.com
WHMCS Risk Score (AI oriented)
Between 700 and 749
logo
WHMCSSoftware Development
Updated:
23/07/2026
732/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WHMCS Global Score (TPRM)
xxxx
logo
WHMCSSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WHMCS
WHMCSModerate
Current Score
732Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
733Before Incident
AUGUST 2026
732Before Incident
JULY 2026
750Before Incident
Cyber Attack
12 Jul 2026WHMCS
Packagist, WHM, cPanel and GitHub: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers

732After Incident
CRITICAL-18
WHMPACGITCPA1784816835
Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers A sophisticated cyber campaign is exploiting GitHub Actions to weaponize trusted open-source projects, turning them into tools for scanning and compromising web hosting servers. The attack, uncovered by analysts at Socket.dev, abuses free GitHub compute resources to target cPanel and WHM servers critical infrastructure for managing websites, email accounts, and databases. Between July 12 and 13, 2026, attackers compromised a legitimate PHP developer’s Packagist account, injecting malicious GitHub Actions workflow files into ten development versions of their packages. These workflows, containing 55–62 malicious files each, launch temporary Ubuntu runners that download Linux payloads and scan the internet for vulnerable hosts. The campaign extends beyond the initial compromise, with thousands of matching workflow files discovered across unrelated repositories, indicating a broad effort to hijack automation pipelines. The attack chain begins when a compromised repository triggers a workflow, spinning up an ephemeral GitHub runner. The runner fetches a processor-specific payload from a threat actor-controlled server (43.228.157.68) and exploits CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. Successful breaches expose cloud credentials, payment data, and source control tokens including AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, and SSH material. The malware exfiltrates stolen data in small chunks via HTTP POST requests, with heartbeats sent every 30 seconds. While installing the affected PHP packages does not directly execute the malware, root-level GitHub Actions in compromised repositories serve as the attack engine. A single WHM compromise can jeopardize multiple customer accounts, databases, and application secrets. The campaign remains active despite the suspension of one GitHub account, underscoring its persistence. Indicators of compromise include the C2 server IP (43.228.157.68), payload delivery URLs, and the compromised maintainer account (dinushchathurya). Affected Packagist packages span multiple repositories, all tied to the same developer. Defensive measures include disabling suspicious workflows, rotating credentials, and patching cPanel/WHM systems. The incident highlights the risks of untrusted automation in CI/CD pipelines, echoing past supply chain attacks where stolen credentials enabled further breaches.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Data exfiltration, credential theft, financial gain
IMPACT
Data Compromised: Cloud credentials, payment data, source control tokens (AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, SSH material)Systems Affected: cPanel and WHM servers, web hosting infrastructureOperational Impact: Compromise of multiple customer accounts, databases, and application secretsIdentity Theft Risk: High (exposure of personally identifiable information and credentials)Payment Information Risk: High (Stripe credentials and payment data compromised)
DATA BREACH
Type Of Data Compromised: Credentials, payment data, API keys, SSH materialSensitivity Of Data: High (personally identifiable information, financial data, authentication tokens)Data Exfiltration: Yes (via HTTP POST requests in small chunks)Personally Identifiable Information: Yes (cloud credentials, source control tokens, payment information)
JUNE 2026
750Before Incident
MAY 2026
750Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WHMCS ?
?
What was WHMCS's A.I Rankiteo Cyber Score in August 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in July 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WHMCS's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on WHMCS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WHMCS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WHMCS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?