Loading…
| Username | Domain | Package | Status |
|---|
Set how your customers see the panel after they log in — your name, logo and accent colour (both light & dark). It applies only to your own customers. The shared login page is unchanged.
Protect your reseller login with a second factor from your phone's authenticator app. It applies only to your own login.
| Username | Domain | Package | Status | |
|---|---|---|---|---|
| Loading… | ||||
A package is a hosting plan — it sets what each account on it may use: disk, bandwidth, databases, and per-account CPU, memory and database limits. Leave a field at 0 for unlimited. Saving a package applies the new limits to every account already using it.
| Name | Disk | Bandwidth | Domains | DBs | CPU cap | RAM cap | DB conns | |
|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||
Create a reseller and choose what they may sell. They log in to their own limited panel and see only their own accounts.
| Username | Packages | Max accounts | Used | Status | |
|---|---|---|---|---|---|
| Loading… | |||||
Sell hosting to your own customers: turn on a payment gateway and create plans. Gateway credentials live only in the server config — never here. Customers pay at /signup.
| Plan | Package | Price | Cycle | Status | |
|---|---|---|---|---|---|
| Loading… | |||||
Enter a license key to activate a paid plan — no reinstall needed. Get one from your ExtraCP provider portal.
Applies the latest signed release and restarts the panel — accounts, data and hosted sites are untouched. Updates also apply automatically each day.
Place a cPanel account backup (cpmove-*.tar.gz) in the server's /var/lib/extracp/imports folder, then enter its file name. Preflight shows what will be imported; Import recreates the account (isolated user, files, databases, mail, DNS, domains, PHP version). The archive is treated as untrusted — only the account's own space is written.
Choose which optional PHP extensions your customers may see and toggle for their own accounts. Visible shows it in the customer's PHP panel; Locked forces it on (customers can't turn it off). Install-state reflects the server. Extensions are always applied per-account only — never server-wide.
| Extension | Group | Installed | Visible | Locked |
|---|---|---|---|---|
| Loading… | ||||
Install additional PHP versions for your customers. A newly installed version appears automatically in every customer's PHP switcher — nothing else to configure. Versions come from the official ondrej/php repository; each adds roughly 30–60 MB of disk plus a running FPM process. A version can only be removed once no account still uses it. PHP 5.6 is not offered — it is end-of-life and not installable on modern Ubuntu (container-only).
| Version | State | Accounts | |
|---|---|---|---|
| Loading… | |||
| Name | Size | Modified |
|---|
| Name | Original location | Deleted |
|---|
| Name | Full name |
|---|
| User | Full username |
|---|
The customer logs in at this same panel with username and the password you set here.
A backup is one archive containing the account's website files and its databases. Stored on this server. You can download it to keep an off-server copy. Restoring overwrites the current files and databases with the backup's contents — you'll be asked to confirm first.
| Backup file | Size | Created | |
|---|---|---|---|
| Loading… | |||
| Address | Quota (MB) | |
|---|---|---|
| Loading… | ||
Each rule: if the chosen header contains your text, do the action. Rules run in order.
| From | Forwards to | |
|---|---|---|
| Loading… | ||
Install a web app with one click. Files are placed as the account's own user, and an isolated database is created automatically. Leave the password blank to have a strong one generated (shown once).
| App | Location | Admin | |
|---|---|---|---|
| Loading… | |||
Run a Node.js app on your account. It runs as your own user behind an nginx reverse proxy on the domain you choose (point that domain's DNS at this server). Put your code under your home directory first, then create the app and “Install deps” if it uses npm packages.
| App | Status | |
|---|---|---|
| Loading… | ||
| Amount | Status | Method | Issued |
|---|---|---|---|
| Loading… | |||
Scheduled tasks that run as your account. Schedule = cron format (minute hour day month weekday), e.g. */15 * * * *, or a keyword like @daily.
| Schedule | Command | |
|---|---|---|
| Loading… | ||
Choose the PHP version this site runs on. Only versions installed on this server are offered. The default for new sites is PHP 8.3 (stable, widely compatible); a newer version is available if an app needs it. The site keeps running as your own account user.
Common php.ini directives for this account only — applied to its own PHP-FPM pool. Each value is capped by your plan's ceiling. Changes take effect immediately.
Optional PHP extensions for this account only — each is enabled in your own PHP-FPM pool, never for other accounts. Only extensions installed for your PHP version are shown. Changes take effect immediately.
The most recent entries from this site's own access log (every request) and error log (nginx + PHP errors). These are private to this account. Log lines contain visitor-supplied text and are shown exactly as recorded.
A summary of this site's own access log, generated with GoAccess. Numbers cover the whole retained log. Page URLs, referrers and browser strings come from visitors and are shown exactly as recorded.
Secure file transfer (SFTP). The login is this account's own user, chrooted to its own files — no shell, and it cannot reach any other account. Plain FTP is not enabled. Use any SFTP client (FileZilla, WinSCP) with the details below.
Password-protect a folder in your site. Visitors must sign in (HTTP Basic authentication) before they can open anything inside it.
| Folder | Username | |
|---|---|---|
| Loading… | ||
Deny access to your site from specific addresses. One entry per line — an IPv4/IPv6 address or a CIDR range (e.g. 203.0.113.4 or 10.0.0.0/8). Saving replaces the whole list.
Stop other websites from embedding your files. Requests for the protected file types are only served when the referer is your own site or one of the allowed domains.
Add SSH public keys for password-less, key-based SFTP login (ssh-ed25519 / ssh-rsa / ecdsa). Keys take effect once SFTP is enabled for this account.
| Type | Label | Key | |
|---|---|---|---|
| Loading… | |||
Scans this account's home directory with ClamAV and reports anything suspicious. Nothing is deleted or quarantined automatically — review findings and remove files yourself via the File Manager. Large sites can take a few minutes.
| File | Signature |
|---|
ExtraCP serves your sites with nginx. This reads your site's .htaccess files and translates the common rules — rewrites, redirects, protected files, basic-auth and headers — into nginx automatically. It runs on its own right after a cPanel import; run it again here whenever you change an .htaccess. Anything that can't be translated is listed below, with what to do instead.
| Line | Directive | What to do |
|---|
Incoming mail is scored by the server's spam filter (rspamd); messages at or above the threshold are tagged and moved to Junk. Mail is never rejected — turning filtering off simply delivers everything to the Inbox. Changes apply to all mailboxes on this account's domains, for new incoming mail.
Customize the page visitors see for each error (e.g. a branded 404). Leave a code blank to use the server default — it's plain HTML served from your own site.
Add extra sites to this account: an addon domain or a subdomain (each gets its own folder in your account, served as your user), or a redirect to another URL.
| Domain | Type | Location / target | |
|---|---|---|---|
| Loading… | |||
| Name | Type | Value | TTL | |
|---|---|---|---|---|
| Loading… | ||||
Cryptographically signs this zone so resolvers can detect tampering with your DNS answers.
Add this DS record at your domain registrar to complete DNSSEC. Until the registrar publishes it, signing has no effect at the parent zone.
Paste a certificate you already own (PEM format). It must match the domain and its private key.
Type below to confirm.