# Website tools

> Redirects, password-protected directories, hotlink protection, custom error pages, per-site PHP settings and the web application firewall, all from the website's Tools tab.

Source: https://zopanel.net/docs/website-tools  
Updated: 2026-10-07

The **Tools** tab of a website (**Websites → Manage → Tools**) groups the settings you would otherwise write by hand in `.htaccess` or nginx files. Every change is validated and the nginx configuration is tested before it goes live; if a change is rejected, the previous settings are kept.

## Redirects

Send visitors from an old address to a new one.

1. In **Redirects**, click **Add redirect**.
2. Fill in **From path** (for example `/old-page`) and **To URL or path** (for example `https://example.com/new-page` or `/new-page`).
3. Choose the status code: **301** (permanent, the default), **302**, **307** or **308**.
4. Optionally turn on **Whole folder** to redirect everything under the path, and **Keep rest of path** to append the rest of the requested path to the target.
5. Click **Save**.

| From path | Whole folder | Keep rest of path | Result |
| --- | --- | --- | --- |
| `/old-page` | off | – | Only `/old-page` is redirected. |
| `/blog` | on | off | `/blog` and everything under it go to the same target. |
| `/blog` | on | on | `/blog/post-1` → `<target>/post-1` (query string kept). |
| `/` | on | on | The whole site moves to a new domain, keeping paths. |

Redirecting the whole site with `/` and **Whole folder** keeps SSL renewal working, because the certificate validation path is never redirected. A website can have up to 500 redirects.

## Password-protected directories

Visitors must log in (HTTP basic authentication) to open these folders. PHP keeps running inside them, so you can protect an admin area of an application.

1. In **Password-protected directories**, click **Protect a directory**.
2. Enter the **Directory** as a URL path, for example `/admin` (use `/` for the whole site).
3. Change the **Prompt text** if you like (default `Restricted`).
4. Add one or more users with a **User name** and password (8 to 128 characters). Use **Add user** for more.
5. Click **Save**.

When you edit a directory later, leave **Password (empty = keep)** blank to keep a user's current password. Passwords are stored as SHA-512 crypt hashes, never in plain text. Limits: 50 protected directories per website and 100 users per directory.

## Hotlink protection

Stop other websites from embedding your images, videos and downloads and using your bandwidth.

1. In **Hotlink protection**, turn on **Enabled**.
2. In **Also allow these domains**, list partner sites or CDNs, separated by commas (for example `partner.com, cdn.example.com`). Their subdomains are allowed too.
3. In **File types**, list the extensions to protect, or leave it empty for the defaults: `jpg, jpeg, png, gif, webp, avif, svg, bmp, mp4, webm, mp3, ogg, pdf, zip`.
4. Click **Save**.

Requests from your own domain, its aliases and their subdomains are always allowed, as are direct visits (no referrer). Other referrers get HTTP 403. Page and code files (`php`, `html`, `htm`, `js`, `css`, `json`, `xml`, `txt`) cannot be hotlink-protected, so you cannot break your own site by accident. This card is not shown for proxy websites.

## Custom error pages

Show your own page instead of the default error page. Enter a path inside the document root for any of the codes **403**, **404**, **500**, **502** and **503**, for example:

```text
404  →  /errors/404.html
503  →  /errors/maintenance.html
```

Leave a field empty to keep the default page. Upload the files with the File Manager first. Custom error pages are not available for proxy websites; your application answers its own errors there.

## PHP settings for this website

PHP websites show **PHP settings for this website**. The card reminds you of the limits that come from the package (memory limit and maximum execution time) and the upload limit of 256 MB.

| Setting | Accepted values | Example |
| --- | --- | --- |
| `upload_max_filesize` | 1M to 256M | `128M` |
| `post_max_size` | 1M to 256M | `128M` |
| `max_input_vars` | 100 to 999999 | `5000` |
| `max_input_time` | `-1` or 0 to 9999 seconds | `60` |
| `session.gc_maxlifetime` | seconds | `1440` |
| `date.timezone` | a valid time zone | `Asia/Ho_Chi_Minh` |
| `short_open_tag` | default, On or Off | |
| `output_buffering` | default, Off or 4096 | |

Empty fields keep PHP's default. ZoPanel writes the values to `.user.ini` in the document root, inside a block marked `; BEGIN ZoPanel` … `; END ZoPanel`; lines you added to that file yourself are kept. The account's PHP-FPM pool is reloaded so the change applies at once. `.user.ini` cannot be downloaded by visitors.

In Apache mode, `php_value` and `php_flag` lines in `.htaccess` are ignored: use this card instead.

## Web application firewall

If the administrator has installed the firewall, each website shows a **Web application firewall** card. It uses ModSecurity with the OWASP Core Rule Set to stop SQL injection, XSS, file inclusion, remote code execution and vulnerability scanners.

| Mode | Effect |
| --- | --- |
| **On (block attacks)** | Matching requests are blocked. |
| **Detect only (log)** | Matching requests are logged but allowed. |
| **Off** | The firewall does not inspect this website. |

Recommended rollout:

1. Set **Detect only (log)** for a few days.
2. Review the events table (time, IP, request and reason). Each event is marked **blocked** or **logged**.
3. If a legitimate request was flagged (a page builder or an import, for example), click **Allow this**. The matching rule IDs are added to **Allowed rules** for this website only. Click a rule in that list to **Remove** the exception.
4. Switch to **On (block attacks)**.

Static files such as images, CSS and JavaScript skip the firewall, which saves CPU.

**For administrators:** install the firewall in **Security → Web application firewall → Install firewall**, or from **Components**. It is loaded only while at least one website uses it (about 25 MB of RAM per nginx worker). **Apply to all websites** sets one mode on every website at once, and the card shows how many websites block, only log, or have it off.

## .htaccess support (Apache mode)

The **.htaccess support (Apache mode)** card on the **Tools** tab switches the website to Apache mode, so `.htaccess` rules work as on cPanel or DirectAdmin. What is supported and what is ignored is described in [Websites and PHP](/docs/hosting#apache-mode-for-htaccess).
