Even if you are monitoring, why would you want to open an interface with root privileges that is open to the world? Wouldn't it make more sense to have some off-server system poll whatever WHM APIs you wanted to make publicly available and then make that data public? You could technically downgrade your permissions within the WHM API call but it's then likely that you wouldn't have the right data available. Maybe if you could provide more context about what you're trying to accomplish, we could provide a more accurate answer.