
In late August, the vendor behind Softaculous suffered a serious security incident: traffic to their infrastructure was hijacked for roughly 33 hours, and a malicious update was pushed through their update systems to installations of a sister product.
Because Softaculous runs with elevated privileges and pulls its own updates from that same infrastructure, and because AI-assisted tools are making it dramatically faster for attackers to find and exploit vulnerabilities in widely deployed software, we determined the risk to client data was too high to keep it on our platform.
As a result, we have made a decision to permanently remove Softaculous from all FullHost shared servers as a proactive security decision.
We would like to additionally confirm that the security incident referenced has not impacted us, but that the incident itself was severe enough for us to review whether Softaculous should be removed.
Information on the incident itself can be found here: https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html
The good news: your existing sites and applications are completely unaffected. Softaculous only handled installation and management, so everything installed through it continues to run normally. If you used it for WordPress, the WordPress Toolkit in cPanel is a stronger replacement: installs, Smart Updates, staging, security hardening, and backups.
One heads-up: any auto-update or backup schedules configured inside Softaculous stopped running when it was removed, so please recreate those in WordPress Toolkit.