Loading…
What each plan gives your customers. These limits are set by the administrator.
| Package | Disk | Bandwidth | Websites | Databases |
|---|---|---|---|---|
| Loading… | ||||
| Username | Domain | Package | Status |
|---|
Set how your customers see the panel after they log in — your name, logo and accent colour (both light & dark). It applies only to your own customers. The shared login page is unchanged.
Where you are emailed if something goes wrong with your own domain on this server — today, if your nameserver domain ends up with no DNS zone here and stops resolving, which takes your panel, your site and your email down with it. The same alert also appears as a red banner in your panel. An outage alert repeats once a day until it is fixed, and you get a note when it clears. Leave this empty and the alert goes to the server's administrator instead — it is never simply dropped.
This is optional and for advanced users — your customers already work under the provider's brand. Set this up only if you own a domain and want everything under your own name. Run everything under your OWN brand on this shared server: your customers log in at panel.<yourdomain> and their DNS is served by your nameservers — they never see the provider. All records below point to server IP ….
…
Open
HTTPS issues automatically once panel.<yourdomain> points to the server IP above.
Checked against public DNS — what the rest of the internet sees, not this server's own resolver. A nameserver only starts working once you create its A record at your registrar and register it as a child nameserver (glue), so the registry can hand the name out.
Protect your reseller login with a second factor from your phone's authenticator app. It applies only to your own login.
A few steps and customers can buy from you. This card disappears once you're ready.
Point your domain and email at this server. These are live checks — nothing here changes your server.
Give the panel its own address (e.g. panel.yourdomain.com). Point that name at this server's IP, then HTTPS is issued automatically.
| Account | Plan | Over by |
|---|
Nimbopanel does not suspend anyone on its own — decide each case yourself.
| Username | Domain | Package | Status | ||
|---|---|---|---|---|---|
| Loading… | |||||
A package is a hosting plan — it sets what each account on it may use: disk, bandwidth, databases, and per-account CPU, memory and database limits. Leave a field at 0 for unlimited. Saving a package applies the new limits to every account already using it.
| Name | Disk | Bandwidth | Domains | DBs | CPU cap | RAM cap | DB conns | |
|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||
Create a reseller and choose what they may sell. They log in to their own limited panel and see only their own accounts.
| Username | Packages | Max accounts | Used | Status | |
|---|---|---|---|---|---|
| Loading… | |||||
Named bearer tokens for automation (API/CLI). The secret is shown once — store it safely. A token can do exactly what your account can; revoke any time.
| Name | Prefix | Created | Last used | |
|---|---|---|---|---|
| Loading… | ||||
Sell hosting to your own customers: enter your gateway credentials, turn a gateway on, and create plans. Secrets are stored server-side and never shown again.
…
Open
Customers pick a plan and pay here; their account is created automatically once payment is verified. It needs at least one active plan and one enabled gateway (below).
Enter your PayPal REST app credentials (from the PayPal Developer site) and/or your Stripe keys (from the Stripe Dashboard) — no coding. Leave a secret blank to keep the saved one. Once saved, that gateway shows as configured and you can switch it on above. PayPal keys ↗ · Stripe keys ↗
| Plan | Package | Price | Cycle | Status | |
|---|---|---|---|---|---|
| Loading… | |||||
Applied to every invoice — checkout and renewals alike. Leave the rate at 0 for no tax.
Charge a different rate per country — for example EU VAT that differs by member state. A country listed here overrides the global rate above; the global rate stays the fallback for every other country. The rate applies once the customer enters their country at signup. Set a rule inactive to stop applying it without losing it.
| Country | Label | Rate | Status | |
|---|---|---|---|---|
| Loading… | ||||
The billing clock uses these to invoice ahead of renewal, remind, then suspend and terminate for non-payment. All day counts are relative to the renewal due date; reminder offsets are negative before the due date, positive after.
Extra text printed on every invoice. Notes appear under the total (e.g. payment terms or transfer instructions); the footer is small print at the very bottom (e.g. a thank-you or business registration number). Leave either blank to hide it.
Percentage discount codes your customers enter at checkout.
| Code | Discount | Uses | Status | |
|---|---|---|---|---|
| Loading… | ||||
Moving from WHMCS? Export your clients and services to CSV from the WHMCS admin, then map each row onto one of your packages here. This creates matching plans and subscriptions (billing records only — it does not create hosting accounts or take any payment). Preview first to see exactly what will happen, then import.
The CSV needs a header row with these columns (in any order): email, domain, plan, price, cycle, status, first_name, last_name, currency. Only email and domain are required.
| Line | Problem |
|---|
| Line | Domain | Plan | Price | Cycle | Status |
|---|
Reward partners who send you customers. Give each a referral code; a buyer who signs up via /signup?ref=CODE is attributed to them, and when their payment lands a commission accrues to the partner's balance. A payout only marks earnings as paid — you send the money out yourself, as with a refund.
| Code | Name | Commission | Balance | Status | |
|---|---|---|---|---|---|
| Loading… | |||||
| Invoice | Amount | Status | Recorded | Paid |
|---|---|---|---|---|
| Loading… | ||||
Score every signup for likely fraud and act on the result: hold risky orders for your review, or block the worst outright. Screening runs locally at no cost; the optional MaxMind minFraud lookup adds a remote risk score. Leave the block and review scores at 0 to turn screening off — that is the default, and no order is ever held or refused until you set them.
MaxMind minFraud (optional): a remote risk score folded into the total. Enter your credentials in Payment settings above. Leave blank to screen on the local heuristics alone.
Signups held for review or blocked by screening. Review each and follow up as you would any suspicious order; the account is only ever created once payment is verified.
| Username | Domain | Country | Score | Action | IP | Created | |
|---|---|---|---|---|---|---|---|
| Loading… | |||||||
Sell and register domain names for your customers. Enter your registrar credentials, set the retail price of each TLD you sell, then search a name and register it on a customer's behalf. Registration and renewal reach the live registrar and cost money, so they are done by you (the operator), not self-service. Contact/EPP management, transfers and auto-renew are planned follow-ups.
Namecheap only for now. A live call also needs this server's IP whitelisted on your Namecheap account. Leave a secret blank to keep the saved one; secrets are stored server-side and never shown again.
Search a name across the TLDs you have priced below. Availability is shown only when a registrar is configured; the retail price is always shown.
The retail price you charge, in the currency's minor units (for example 1200 = $12.00; for zero-decimal currencies like IDR or JPY, the whole amount). Only enabled TLDs appear in search.
| TLD | Register | Renew | Transfer | Currency | Enabled | |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Every domain registered or renewed through the panel. A pending row is an order recorded but not yet completed (for example when no registrar was configured at the time).
| Domain | Account | Registrar | Status | Registered | Expires |
|---|---|---|---|---|---|
| Loading… | |||||
Customise the subject and message your customers receive at each billing step. Leave a field empty to use the built-in default (shown as a hint). You can insert these placeholders anywhere in the text — they are replaced with the customer's real values when the email is sent:
Loading…
Your business name, logo and accent on the public signup page (/signup) — so customers buy under YOUR brand, not "Nimbopanel".
Self-service help articles your customers can read before opening a ticket. Only published articles are shown publicly; drafts stay hidden. The body is plain text — line breaks are kept, but HTML is not rendered.
| Title | Slug | Category | Status | |
|---|---|---|---|---|
| Loading… | ||||
Route incoming tickets to a team. Customers pick a department when they open a ticket; the label is kept on the ticket even if you later remove the department. Deactivate one to stop offering it without losing its history.
| Name | Status | |
|---|---|---|
| Loading… | ||
Saved answers your staff can drop into a ticket reply. Only staff see these — customers never do.
| Title | Preview | |
|---|---|---|
| Loading… | ||
Whether email from this server can actually reach the outside world. Delivery to a recipient's mail server always uses port 25 — that is the SMTP standard, not a setting — and many hosting providers block it to stop spam. When they do, messages sit in the queue for days and then bounce, which looks exactly like “sent but never arrived”. If that is your situation, point outgoing mail at a relay below and it starts working immediately.
Where this server emails you when something needs you — today, when a domain pointed at your nameservers has no DNS zone here and goes offline. Alerts also appear in the panel and in the server log; email is the one that reaches you when you are not looking at the panel. An outage alert repeats once a day until it is fixed, and you get a note when it clears. Leave this empty to turn alert email off. Mail is handed to this server's own mail service — send a test to confirm it actually leaves the machine.
Automated checks of the panel's configuration and accounts, with a score and fixes. Re-run any time.
Lock out an IP after too many failed logins. Whitelisted IPs are never locked. Changes apply immediately.
| Time | IP | Username | Outcome |
|---|---|---|---|
| Loading… | |||
The hostname mail clients are told to connect to, and whose certificate they check. Applied automatically once HTTPS is issued for the panel; re-apply here if you have just changed the panel's domain.
Messages waiting in the Postfix queue and why. "Flush" retries delivery of all; "Delete" removes a stuck message.
Check this server's outbound IP against common blocklists, and send a test email to confirm delivery.
Every active account is backed up on this schedule (files + databases). Retention keeps the newest N backups per account.
A changed interval takes effect after the next panel restart; retention and “Run now” apply immediately.
Copy each backup to remote storage automatically after every run. Keys are sent to the server and stored only in a root-only file — never saved in the panel and never shown again.
Replicate every hosted zone to a second nameserver (ns2) so DNS survives one box failing. New zones auto-replicate. You provide a small VPS as ns2 and run the setup command below on it.
Then set the ns2 IP as the ns2 glue record at your registrar.
Enter a license key to activate a paid plan — no reinstall needed. Get one from your Nimbopanel provider portal.
Applies the latest signed release and restarts the panel — accounts, data and hosted sites are untouched. Updates also apply automatically each day.
Upload a cPanel account backup (cpmove-*.tar.gz) — no SSH needed. Preflight shows what will be imported; Import recreates the account (isolated user, files, databases, mail, DNS, domains, PHP version). The archive is treated as untrusted — only the account's own space is written.
We connect to the old server over SSH, have it build the backup, and stream it here. Building a backup needs root on that server, exactly as cPanel's own transfer tool does. For Plesk, DirectAdmin or anything else: create the backup with that panel first, then choose an archive that already exists.
Is this the right server? Its fingerprint is . Compare it with what the old host shows you before continuing — this is the only check that the machine you are about to hand a password to is really theirs.
Maximum file size for phpMyAdmin → Import, server-wide (phpMyAdmin runs one shared pool for every account on this server). For any-size restores, point customers at Databases → “Import / Restore” instead — it streams straight to MySQL with no size limit and bypasses phpMyAdmin entirely.
Choose which optional PHP extensions your customers may see and toggle for their own accounts. Visible shows it in the customer's PHP panel; Locked forces it on (customers can't turn it off). An extension is installed per PHP version — pick the version below, then Install the ones your customers need; it stays off until each account switches it on. Always on means PHP already loads it for every account on that version (built into PHP, or enabled server-wide by its package), so it cannot be toggled per account. ionCube Loader and SourceGuardian are fetched from their vendors for that exact PHP version; like every Zend extension (OPcache, Xdebug) they can only be enabled for the whole version — PHP itself offers no way to load a Zend extension for one account — so installing one turns it on for every account on that version.
| Extension | Group | State | Visible | Locked | |
|---|---|---|---|---|---|
| Loading… | |||||
Install additional PHP versions for the customers on this server. A newly installed version appears automatically in the PHP switcher of every customer hosted here — nothing else to configure. (Each server is managed separately: if you run more than one server, install the version on each where you want it available.) Installing runs in the background and takes about 1–2 minutes; the row flips to installed when it finishes. Versions come from the official ondrej/php repository; each adds roughly 30–60 MB of disk plus a running FPM process. A version can only be removed once no account still uses it. PHP 5.6 is offered for legacy apps only — it is end-of-life (no upstream security fixes), so use it only when an old site truly needs it.
| Version | State | Accounts | |
|---|---|---|---|
| Loading… | |||
Install optional software and services on this server — the tools your customers ask for: FFmpeg & ImageMagick (media), Redis/Memcached (caching), ClamAV (the antivirus behind the Virus Scan tool), plus Git, Composer, Ghostscript, wkhtmltopdf, rclone, Python, Go, Ruby, LibreOffice and ExifTool. Installing runs the server's own package manager (apt/dnf) and takes from a few seconds to a couple of minutes; large items like LibreOffice can be a few hundred MB. Items marked Managed ship with the panel (nginx, PHP, MariaDB) or are handled elsewhere (Node under App Servers) and can't be changed here. Once a tool is installed it is available to every account on this server.
| Software | Tier | State | |
|---|---|---|---|
| Loading… | |||
| Name | Size | Modified |
|---|
| Name | Original location | Deleted |
|---|
Most apps (like WordPress) need one database plus one database user. Create the database first, then add a user below — you'll get the host, database name, username and password to paste into your app (shown only once). Use the database user's name and password to log in to phpMyAdmin.
| Name | Full name |
|---|
| User | Full username |
|---|
| Name | Full name |
|---|
| User | Full username |
|---|
The account holder signs into this panel with username and the password you set here.
A backup is one archive containing the account's website files and its databases. Stored on this server. You can download it to keep an off-server copy. Restoring overwrites the current files and databases with the backup's contents — you'll be asked to confirm first.
| Backup file | Size | Created | |
|---|---|---|---|
| Loading… | |||
| Address | Quota (MB) | |
|---|---|---|
| Loading… | ||
| Line | Address | Result |
|---|
Each rule: if the chosen header contains your text, do the action. Rules run in order.
| From | Forwards to | |
|---|---|---|
| Loading… | ||
Choose whether this server delivers mail for your domain, or whether your email lives somewhere else (e.g. Google Workspace). Pick Remote when your email is hosted elsewhere — otherwise messages your site sends to your own domain get trapped here instead of being delivered.
| Time | From | To | Status | Detail |
|---|---|---|---|---|
| Press Refresh to load recent delivery events. | ||||
Store a mailbox's PGP public key and every message that arrives for it is encrypted before it is stored on the server. Only the matching private key — which you keep — can read it. You never give the server your private key.
BoxTrapper holds mail from senders you've never heard from and emails them a one-time link to confirm they're a real person. Only confirmed senders reach your inbox.
Heads-up: the confirmation emails go to whatever address the sender used, which spammers often forge — so this can bounce mail to strangers and, in the worst case, hurt your server's mail reputation. Most people are better off with the spam filter. Off by default.
| From | Subject | Date | |
|---|---|---|---|
| No held messages. | |||
Install a web app with one click. Files are placed as the account's own user, and an isolated database is created automatically. Leave the password blank to have a strong one generated (shown once).
For any app that is not in the list — a Laravel/Symfony project, a package on Packagist, or a public Git repository. The code is placed as the account's own user; a framework then finishes its own setup. Optionally we hand you an isolated database to wire into the app's config.
Clone a public or token-in-URL Git repository into your site and re-deploy it (pull + build) whenever you push. The code runs as your account; the repository's .git is never served (blocked by the web server).
| Repository | Location | Commit | |
|---|---|---|---|
| No repositories connected yet. | |||
| App | Location | Admin | |
|---|---|---|---|
| Loading… | |||
Mount your hosting space as a network drive over WebDAV (HTTPS) — in Windows Explorer (Map network drive), macOS Finder (Connect to Server), or a phone. Files you add stay owned by this account. Web Disk has its own password, separate from your SFTP/FTP and panel logins.
Every WordPress site in this account, with the updates it needs. Keeping WordPress, plugins and themes current is the single biggest thing you can do to stay secure. Updates run as your account.
| Site | Version | Updates | |
|---|---|---|---|
| Scanning… | |||
A read-only scan of your website files for the problems that most often lead to a hacked or leaking site — world-writable files, database dumps or config backups left in the web root, and PHP hidden in upload folders. Nothing is changed; fix each item yourself using the advice shown.
Connect your own Cloudflare account to purge the cache and toggle Development Mode for the domains you host here. Your API token is verified, encrypted, and never shown again — create one at Cloudflare → My Profile → API Tokens with the Zone.Cache Purge + Zone.Settings permissions.
| Domain (zone) | Status | Development mode | |
|---|---|---|---|
| Loading… | |||
A shell running as this account's own user — the same access it has over SSH. Nothing here can reach another account or the system.
A mailing list lets people email one address to reach everyone subscribed to it — for announcements or discussion.
| List address | Subscribers | |
|---|---|---|
| Loading… | ||
| Address | |
|---|---|
| Loading… | |
A Web Application Firewall (ModSecurity with the OWASP Core Rule Set) inspects incoming requests and stops common attacks — SQL injection, cross-site scripting, path traversal and more — before they reach your site.
If a firewall rule blocks something legitimate, add its rule ID here to switch that one rule off. One ID per line or comma-separated.
Compression makes pages load faster and use less bandwidth by shrinking text responses (HTML, CSS, JavaScript) before sending them.
gzip is already on for every site on this server — you don't need to do anything for it to work.
These rules are written to your site's .htaccess. Set which MIME type an extension serves, run a handler on chosen extensions, and control your directory index files and folder listing.
Look up a domain's live DNS records (from public resolvers) or its registration. Read-only — useful to check whether your DNS or delegation is set up correctly.
For developers. Run a Node.js, Python or Ruby app on your account. It runs as your own user behind an nginx reverse proxy on the domain you choose (point that domain's DNS at this server). Put your code under your home directory first, then create the app and “Install deps” if it uses npm/pip/bundler packages. Python apps are served by gunicorn — the entry point is module:callable (e.g. app:app). Ruby (Rack) apps are served by puma — the startup file is your rackup config (e.g. config.ru), and a Gemfile is bundle-installed automatically.
| App | Status | |
|---|---|---|
| Loading… | ||
For developers. Install CPAN modules into your account's own Perl library (~/perl5) — nothing is installed system-wide. Use them from your scripts with use local::lib '~/perl5';, or add ~/perl5/lib/perl5 to PERL5LIB. Installing a module also pulls its dependencies (tests skipped).
| Installed module | |
|---|---|
| Loading… | |
The account moves to the new plan and its disk quota, CPU/RAM caps and database limits are re-applied right away. Files and data are untouched.
| Invoice | Amount | Status | Due | Actions |
|---|---|---|---|---|
| Loading… | ||||
| Date | Reason | Amount |
|---|---|---|
| Loading… | ||
| Subject | Department | Status | Updated |
|---|---|---|---|
| Loading… | |||
Answers to common questions — you may find what you need here.
Loading…
Scheduled tasks that run as your account. Schedule = cron format (minute hour day month weekday), e.g. */15 * * * *, or a keyword like @daily.
| Schedule | Command | |
|---|---|---|
| Loading… | ||
Choose the PHP version this site runs on. Only versions installed on this server are offered. The default for new sites is PHP 8.3 (stable, widely compatible); a newer version is available if an app needs it. The site keeps running as your own account user.
Common php.ini directives for this account only — applied to its own PHP-FPM pool. Each value is capped by your plan's ceiling. Changes take effect immediately.
Optional PHP extensions for this account only — each is enabled in your own PHP-FPM pool, never for other accounts. Only extensions installed for your PHP version are shown; greyed-out ones are always on and cannot be switched off. Need one that isn't listed? Ask your provider to install it for your PHP version. Changes take effect immediately.
The most recent entries from this site's own access log (every request) and error log (nginx + PHP errors). These are private to this account. Log lines contain visitor-supplied text and are shown exactly as recorded.
A summary of this site's own access log, generated with GoAccess and accumulated across log rotations — so the numbers are all-time history, not just the current log. Page URLs, referrers and browser strings come from visitors and are shown exactly as recorded.
A shell login lets this account run commands on the server over SSH — git, composer, wp-cli, npm — as its own Linux user, so it can only touch its own files, just like its website does. It is off by default and only the account's provider can turn it on.
Granting a shell lifts this account's SFTP chroot: SFTP and SCP keep working over the same login, but the account is no longer confined to its home folder by SSH. Turning shell access off puts the chroot back.
Shell access is granted by your hosting provider — contact them if you need it.
Upload/download your website files with any client (FileZilla, WinSCP, Cyberduck). The login is this account's own user, locked to its own files — it cannot reach any other account. SFTP & FTP share the same username and password; setting a password on either updates both.
Turn this on if your FTP program only offers plain "FTP". Prefer FTPS (explicit TLS) — same port, encrypted. Plain FTP works too but sends your password unencrypted.
Password-protect a folder in your site. Visitors must sign in (HTTP Basic authentication) before they can open anything inside it. Leech protection caps how fast one login can be reused, so a shared or leaked password cannot be hammered from many machines.
| Folder | Username | Leech cap | |
|---|---|---|---|
| Loading… | |||
Deny access to your site from specific addresses. One entry per line — an IPv4/IPv6 address or a CIDR range (e.g. 203.0.113.4 or 10.0.0.0/8). Saving replaces the whole list.
Stop other websites from embedding your files. Requests for the protected file types are only served when the referer is your own site or one of the allowed domains.
Add SSH public keys for password-less, key-based SFTP login (ssh-ed25519 / ssh-rsa / ecdsa). Keys take effect once SFTP is enabled for this account.
| Type | Label | Key | |
|---|---|---|---|
| Loading… | |||
Scans this account's home directory with ClamAV and reports anything suspicious. Nothing is deleted or quarantined automatically — review findings and remove files yourself via the File Manager. Large sites can take a few minutes.
| File | Signature |
|---|
Shows which folders and databases use your disk. Sizes are measured live and shown relative to your largest item, so you can see at a glance where space is going. Nothing is changed or deleted — to free space, remove files in the File Manager or drop unused databases.
| Location | Size | Usage |
|---|
| Line | Directive | What to do |
|---|
Incoming mail is scored by the server's spam filter (rspamd); messages at or above the threshold are tagged and moved to Junk. Mail is never rejected — turning filtering off simply delivers everything to the Inbox. Changes apply to all mailboxes on this account's domains, for new incoming mail.
Customize the page visitors see for each error (e.g. a branded 404). Leave a code blank to use the server default — it's plain HTML served from your own site.
Add extra sites to this account: an addon domain or a subdomain (each gets its own folder in your account, served as your user), or a redirect to another URL.
| Domain | Type | Location / target | |
|---|---|---|---|
| Loading… | |||
Advanced: most customers never need to change these. Records here control where your domain points (website, email, verification). If you're not sure, leave them as they are.
| Name | Type | Value | TTL | |
|---|---|---|---|---|
| Loading… | ||||
Cryptographically signs this zone so resolvers can detect tampering with your DNS answers.
Add this DS record at your domain registrar to complete DNSSEC. Until the registrar publishes it, signing has no effect at the parent zone.
Point a hostname at a changing IP (home/office router). Create a token, then have your router or a cron script call the update URL — it sets that host's record to the caller's current IP.
Paste a certificate you already own (PEM format). It must match the domain and its private key.
Type below to confirm.