AdminBolt Security Audited by RACK911 Labs
Over the past months AdminBolt has been audited several times by RACK911 Labs. The fixes shipped in regular public releases.
We commissioned the audits early for a simple reason. The established control panels have years of public advisories and patches behind them, so a hosting provider knows what kind of issues turned up and how fast they were fixed. A panel that is a year or two old has no such record. An independent audit is the fastest way to build one.
Who RACK911 Labs are
RACK911 Labs is the security research division of RACK911, a Linux server management and security company operating since 2003. The division was set up in 2013 to look for vulnerabilities in the software hosting companies depend on. It has since reported hundreds of security issues, many of them in control panels and other hosting applications. Its bug bounty work includes cPanel and Plesk. They test software outside hosting as well, but hosting security remains their main field.
Their researchers test the software manually and provide a working proof of concept for each finding.
How the audits went
There were several rounds, spread across a number of AdminBolt releases. Each round covered the whole panel. After we shipped the fixes, RACK911 checked them before moving on to the next round.
The reports and the findings stay private, which is how security audits are normally handled. What a hosting provider gets is the outcome: the current version of AdminBolt has been examined repeatedly by a firm that has spent over a decade doing this for hosting software.
What it means for a hosting provider
A trial shows you the interface. It does not show you what the panel does on the server. If you are comparing panels, ask each vendor who audits their software and how often. For AdminBolt the answer is RACK911 Labs, several times so far, with further rounds planned as the panel develops.
You will find the RACK911 Labs badge on our homepage. To try the panel, start a free trial on a fresh server.
If you are a security researcher and you find something, write to [email protected].