Back to plugin

Security audit

ISPConfig

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently exposes ISPConfig administration tools and includes clear default safeguards, but users should configure it with least-privilege API credentials and a narrow allowlist.

Install only if you intend to let OpenClaw manage an ISPConfig server. Use a dedicated ISPConfig Remote User with the minimum API permissions needed, keep readOnly enabled by default, set allowedOperations to a small explicit list, and enable write tools only for deliberate administrative sessions.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.