If cPanel allows weak passwords then I don't think Blesta should be stepping in and creating arbitrary restrictions. The client could just as easily log in to cpanel and change their password to a weak one. One thing we could be though is to make the password generator on the page which will let users automatically generate strong passwords. https://dev.blesta.com/browse/CORE-3946