What Steel Security checks
Safe non-privileged indicators for cPanel components and cPHulk relevance.
A root-managed cPHulk reporter path when the server administrator chooses to expose current-state telemetry safely.
Status interpretation
Detected means stronger environment signals were found.
Possible means weaker hints exist but the plugin cannot confirm the service confidently.
Not detected means no useful signals were found.
Disabled means a current reporter confirms that cPHulk is present but turned off.
Unable to determine means host restrictions prevented a meaningful check.
Partial telemetry means the reporter is current but one or more safe data sources returned incomplete results.
What you can see when telemetry is healthy
Whether cPHulk is enabled or disabled.
Reporter health and last update freshness.
Current blocked-IP record counts from safe exported data.
Protected service summaries and protection-mode summaries.
- Expected reporter path: `/var/lib/cphulk-json-reporter/status.json`
- Current cPHulk activity visibility is intentionally summarized as safe current-state data, not full attack-history analytics.
Important limitation
The release audit originally validated negative and synthetic positive-path classification before the richer reporting work landed.
Current telemetry is still intentionally conservative: WordPress does not receive WHM root credentials, does not run privileged cPanel commands, and does not manage cPHulk directly.
If no reporter is connected, ask the server administrator to install the Steel cPHulk reporter rather than trying to route WHM privileges through WordPress.