+254725682556 +254725052660 info@ziprof.co.ke
Client Area

cPanel - Control Panel

How to Use cPanel's Security Advisor to Check Your Website's Security Settings

cPanel's Security Advisor is a built-in tool that checks your hosting account for common security weaknesses and lists them with a plain explanation of what's wrong and why it matters. You don't need to install anything. It's available in every cPanel account and runs its checks automatically each time you open it.

What Security Advisor Checks

Security Advisor looks at a fixed set of server and account-level settings rather than scanning your website's files. Typical checks include:

  • Whether an SSL certificate is installed and active on your domains
  • Whether outdated or insecure PHP settings are in use
  • Whether Apache's ModSecurity firewall is enabled
  • Whether your account allows weak FTP or shell access settings
  • Whether two-factor authentication is set up for your cPanel login

Each check comes back as Good, Info, or Warn, so you can quickly see what needs attention.

How to Open Security Advisor

  1. Log in to your cPanel account.
  2. In the search box at the top left, type Security Advisor, or scroll down to the Security section of the dashboard.
  3. Click Security Advisor to open it.
  4. Wait a few seconds while cPanel runs its checks. The results appear as a list, grouped by severity.

You can return to this page at any time to re-run the checks, for example after making a change you expect to fix a warning.

Understanding the Results

Each item in the list shows a short title, a status icon, and a "More Information" link with a longer explanation. Focus on anything marked Warn first, since those are the issues Security Advisor considers most important. Items marked Info are usually optional hardening steps rather than urgent problems.

Fixing Common Warnings

No SSL certificate detected

If Security Advisor flags a domain without SSL, install a free certificate through AutoSSL on cPanel's SSL/TLS Status page. See how to install a free SSL certificate with AutoSSL for the steps.

ModSecurity is disabled

ModSecurity is a firewall that filters malicious requests before they reach your website. If it shows as disabled and you did not turn it off deliberately, contact your hosting provider's support team before re-enabling it, since some websites need specific rules excluded to keep working normally.

Two-factor authentication is not configured

Setting up two-factor authentication adds a second step to your cPanel login beyond your password. This makes it much harder for someone to break in even if they guess or steal your password.

Security Advisor checks configuration settings, not the files already on your account. It will not detect malware or hacked files. For that, run a scan with cPanel's malware scanning tool.

Run Security Advisor periodically, especially after making changes to your hosting account, so you catch new warnings early instead of finding out something is wrong later.