Changelog

What changed in ZoPanel, release by release: security hardening, performance under load, safer updates, backups and day-to-day operations.

Updates are installed from the panel or with zopanel update. Every update is signed, checked again by the root agent, and rolled back automatically if the new version is not healthy.

2026-10 — Security and operations release

The largest release so far. It went through several rounds of internal security audit and was measured on real VPS servers under heavy load.

Performance and capacity

  • Sized to the server automatically, from a 2 GB VPS to large machines. Settings shows the memory plan: the limit for customers and the reserve kept for the system.
  • PHP on demand. A website's PHP pool starts with its first request and stops when idle, so quiet accounts use no PHP memory. Restarts and PHP version changes happen without dropping requests.
  • Faster wake-up: compiled PHP code is cached on disk, and pools stay ready under an "always on" policy where you choose it.
  • Memory compression in RAM. On Linux 6.8 and newer, customers' idle memory is compressed in RAM instead of hitting the limit, and it is never swapped to disk.
  • Overload recovery in minutes. Short request queues make overload fail fast instead of collapsing; when memory is badly short, requests that have waited too long are dropped and their visitors see a "busy" page, so the server recovers soon after the load stops. Measured on our test servers: back to normal in 2 to 5 minutes after a heavy overload.
  • Page cache: expired pages are refreshed in the background and kept for a day; cached pages are also served to visitors arriving from ad campaigns; a WordPress site's cached pages are cleared when its content changes; cache entries are keyed by site, not only by host name.
  • Scheduled work and account creation stay fast with hundreds of accounts; settings are applied to web server configurations in batches after updates.
  • Fixed: on servers with several hundred sites, nginx could keep an old configuration after a change.
  • Database sizes in the list are read from the files on disk, so the list loads quickly.

WordPress

  • Scheduled tasks run by the server. For new installs, WordPress's visitor-driven wp-cron is switched off and a timer runs due tasks every 5 minutes, as the account, at low priority. Scheduled posts and shop e-mails run on time on quiet sites, and busy sites lose an extra request per visit. It follows the site's PHP version, pauses while the account is suspended and can be switched off per site.
  • New WordPress and PHP apps are warmed up right after installation, before the first visitor.
  • Installations retry the WordPress download after a network hiccup, and wp-cli's download is no longer left in the account.

Security

  • Docker apps isolated with user namespaces; app data is closed to hosting accounts.
  • Mail sending limits cannot be bypassed from account processes: PHP command line, cron jobs, forwards, catch-alls, plus-addresses and Bcc headers all count.
  • No root file access through customers' links. Backups, dumps, restores, ownership changes and scans read customer files as the customer or one path step at a time, never following an account's symlinks.
  • Resellers cannot grant more than their own plan: packages, disk and website totals stay within it unless overselling is allowed.
  • Two-factor authentication: attempts are throttled before the code is checked, codes cannot be reused, recovery codes are available, and 2FA can be required for administrators or for everyone.
  • IP allowlist applies to connections from the server itself too.
  • API tokens are revoked on password and 2FA changes, created only with the password, and cannot change security settings, backups, hooks or administrator logins, or read secrets. Single sign-on from a billing system opens customer sessions only.
  • Shared Redis denies scripts to account users.
  • Secrets encrypted at rest: panel settings, 2FA secrets, external database passwords, app environments.
  • Tamper-evident activity log (hash chain, visible in the Security Center), with a copy in the system journal and optional remote syslog.
  • Malware quarantine moved to a root-only folder.
  • Custom nginx directives are checked against an allowlist; proxying to the server's own addresses is refused.
  • Websites that are subdomains of another account's domain need an administrator.

Updates and disaster recovery

  • Safe updates: a database snapshot is taken first, the new version is health-checked, and the binary and database are rolled back automatically if it is not healthy. zopanel rollback undoes an update by hand.
  • Disaster recovery: the configuration backup now carries the whole panel database and its keys, encrypted; zopanel ctl dr-restore rebuilds the panel on a new server. Daily local database snapshots are kept for 7 days. A disaster-recovery runbook is in the documentation.
  • Installer: brings a fresh server up to date first, installs a newer kernel where supported (asking once, with a single restart), and accepts a license key with --license.

Backups

  • Remote backups are encrypted before upload, with checksums checked after downloads and before every restore, and a weekly repository check.
  • Nightly full and incremental backups cut short by a restart are resumed or caught up, without false alerts.
  • No backup starts on a nearly full disk.

Operations

  • Service watchdog: installed services are probed every minute and restarted when stopped or hung, with an alert for each event.
  • Suspension stops everything: mail logins, FTP, cron jobs, Node.js and Python apps, Docker apps and Redis. Incoming mail is kept, and websites answer 503.
  • Terminated accounts are kept for a grace period (7 days by default): files and mailboxes moved aside, databases dumped first. Interrupted terminations resume where they stopped.
  • New alerts: mail queue growth, the server's IP on a blocklist, accounts without a recent backup, expiring certificates, update failures and new versions.
  • Usage history per account (CPU, memory, disk I/O) and hourly website uptime, with graphs.
  • zopanel ctl doctor and zopanel ctl support-bundle for troubleshooting; the advisor reports memory compression.
  • The panel's own certificate renews itself, and mail and webmail pick it up.
  • Docker image pulls and object-storage setup retry after registry or network failures.

Migration

  • cPanel imports carry DNS zones (including www CNAME records), FTP accounts with their existing passwords, and SSL certificates.

Licensing

  • Plans and prices are managed on the license server; licenses carry a database limit. The Free plan allows 10 websites and 10 databases per server.

Fixes

  • The PHP idle policy picker shows the saved value at once on servers with hundreds of sites.
  • The website Tools tab no longer fails when a site has no redirects, error pages or PHP settings.
  • The Hooks page loads when no webhook is configured.
  • Customers can open the activity log and App Store, and one-click webmail login is no longer blocked by the browser.
  • Removing an account also removes its Docker apps.
  • Limits are applied when a username is re-created; database users can connect over 127.0.0.1.