DocsWebsite tools

Website tools

Redirects, password-protected directories, hotlink protection, custom error pages, per-site PHP settings and the web application firewall, all from the website's Tools tab.

The Tools tab of a website (Websites → Manage → Tools) groups the settings you would otherwise write by hand in .htaccess or nginx files. Every change is validated and the nginx configuration is tested before it goes live; if a change is rejected, the previous settings are kept.

Redirects

Send visitors from an old address to a new one.

  1. In Redirects, click Add redirect.
  2. Fill in From path (for example /old-page) and To URL or path (for example https://example.com/new-page or /new-page).
  3. Choose the status code: 301 (permanent, the default), 302, 307 or 308.
  4. Optionally turn on Whole folder to redirect everything under the path, and Keep rest of path to append the rest of the requested path to the target.
  5. Click Save.
From path Whole folder Keep rest of path Result
/old-page off – Only /old-page is redirected.
/blog on off /blog and everything under it go to the same target.
/blog on on /blog/post-1 → <target>/post-1 (query string kept).
/ on on The whole site moves to a new domain, keeping paths.

Redirecting the whole site with / and Whole folder keeps SSL renewal working, because the certificate validation path is never redirected. A website can have up to 500 redirects.

Password-protected directories

Visitors must log in (HTTP basic authentication) to open these folders. PHP keeps running inside them, so you can protect an admin area of an application.

  1. In Password-protected directories, click Protect a directory.
  2. Enter the Directory as a URL path, for example /admin (use / for the whole site).
  3. Change the Prompt text if you like (default Restricted).
  4. Add one or more users with a User name and password (8 to 128 characters). Use Add user for more.
  5. Click Save.

When you edit a directory later, leave Password (empty = keep) blank to keep a user's current password. Passwords are stored as SHA-512 crypt hashes, never in plain text. Limits: 50 protected directories per website and 100 users per directory.

Stop other websites from embedding your images, videos and downloads and using your bandwidth.

  1. In Hotlink protection, turn on Enabled.
  2. In Also allow these domains, list partner sites or CDNs, separated by commas (for example partner.com, cdn.example.com). Their subdomains are allowed too.
  3. In File types, list the extensions to protect, or leave it empty for the defaults: jpg, jpeg, png, gif, webp, avif, svg, bmp, mp4, webm, mp3, ogg, pdf, zip.
  4. Click Save.

Requests from your own domain, its aliases and their subdomains are always allowed, as are direct visits (no referrer). Other referrers get HTTP 403. Page and code files (php, html, htm, js, css, json, xml, txt) cannot be hotlink-protected, so you cannot break your own site by accident. This card is not shown for proxy websites.

Custom error pages

Show your own page instead of the default error page. Enter a path inside the document root for any of the codes 403, 404, 500, 502 and 503, for example:

404  →  /errors/404.html
503  →  /errors/maintenance.html

Leave a field empty to keep the default page. Upload the files with the File Manager first. Custom error pages are not available for proxy websites; your application answers its own errors there.

PHP settings for this website

PHP websites show PHP settings for this website. The card reminds you of the limits that come from the package (memory limit and maximum execution time) and the upload limit of 256 MB.

Setting Accepted values Example
upload_max_filesize 1M to 256M 128M
post_max_size 1M to 256M 128M
max_input_vars 100 to 999999 5000
max_input_time -1 or 0 to 9999 seconds 60
session.gc_maxlifetime seconds 1440
date.timezone a valid time zone Asia/Ho_Chi_Minh
short_open_tag default, On or Off
output_buffering default, Off or 4096

Empty fields keep PHP's default. ZoPanel writes the values to .user.ini in the document root, inside a block marked ; BEGIN ZoPanel … ; END ZoPanel; lines you added to that file yourself are kept. The account's PHP-FPM pool is reloaded so the change applies at once. .user.ini cannot be downloaded by visitors.

In Apache mode, php_value and php_flag lines in .htaccess are ignored: use this card instead.

Web application firewall

If the administrator has installed the firewall, each website shows a Web application firewall card. It uses ModSecurity with the OWASP Core Rule Set to stop SQL injection, XSS, file inclusion, remote code execution and vulnerability scanners.

Mode Effect
On (block attacks) Matching requests are blocked.
Detect only (log) Matching requests are logged but allowed.
Off The firewall does not inspect this website.

Recommended rollout:

  1. Set Detect only (log) for a few days.
  2. Review the events table (time, IP, request and reason). Each event is marked blocked or logged.
  3. If a legitimate request was flagged (a page builder or an import, for example), click Allow this. The matching rule IDs are added to Allowed rules for this website only. Click a rule in that list to Remove the exception.
  4. Switch to On (block attacks).

Static files such as images, CSS and JavaScript skip the firewall, which saves CPU.

For administrators: install the firewall in Security → Web application firewall → Install firewall, or from Components. It is loaded only while at least one website uses it (about 25 MB of RAM per nginx worker). Apply to all websites sets one mode on every website at once, and the card shows how many websites block, only log, or have it off.

.htaccess support (Apache mode)

The .htaccess support (Apache mode) card on the Tools tab switches the website to Apache mode, so .htaccess rules work as on cPanel or DirectAdmin. What is supported and what is ignored is described in Websites and PHP.


← Node.js and Python apps Email →