DocsWordPress Toolkit

WordPress Toolkit

Install WordPress in one click, harden it, run safe updates with automatic rollback, work on a staging copy, and let the server run WordPress's scheduled tasks.

The WordPress tab of a website gathers everything you need to run WordPress: one-click login, safe updates, staging copies, security hardening, plugins and themes. It appears on every PHP website; ZoPanel reads the installation with wp-cli, so it also works for WordPress sites you uploaded or migrated yourself.

Install WordPress

Choose one of these:

  • New website: in Websites → New website, pick the WordPress type, fill in Site title, Admin email, Admin username and Admin password, then Create website.
  • Existing PHP website: on the Overview tab, under Applications, click Install WordPress. This card appears while the document root is in public_html and no application is installed yet.

ZoPanel creates a database and installs the latest WordPress with wp-cli (in Vietnamese when you use the panel in Vietnamese). For a new website with SSL on, the certificate is issued first when the domain already points to the server, so WordPress starts on https://; on an existing website, WordPress uses https:// if the site already has a certificate. The account's package must allow one more database.

Tip: the admin username defaults to admin. Change it before you create the site; the security check flags an administrator named "admin".

Log in without a password

Click Log in to WordPress. ZoPanel opens wp-admin as the first administrator, using a one-time link that is valid for 60 seconds and works only once. No password is stored or sent.

Security hardening

The Security card checks the recommended settings:

Check What it means
Theme/plugin editor disabled DISALLOW_FILE_EDIT is set, so a stolen admin login cannot edit PHP files.
Debug mode off WP_DEBUG is off on the live site.
wp-config.php readable only by the account The file has mode 600.
xmlrpc.php, PHP in uploads and wp-config.php blocked The website uses the WordPress nginx rules.
No administrator named "admin" The first name bots try.
Everything up to date Core, plugins and themes.

Click Fix next to a single item, or Apply all to set every recommended option at once (it also rotates the security keys). Note that blocking xmlrpc.php disables apps and plugins that rely on XML-RPC.

Other buttons on the card:

  • Verify file integrity compares core and plugin files with the official checksums and lists modified files.
  • Rotate security keys generates new salts in wp-config.php, which signs every user out.
  • Reset password sets a new password for any WordPress user.

Updates

The header shows whether a core update is available, and the Plugins and Themes tables show pending updates.

  • Update all runs a safe update: ZoPanel takes a snapshot of the files and database, updates, then checks that / and /wp-login.php still answer without a server error or a PHP "critical error". If the site broke, it is rolled back to the snapshot automatically.
  • To update only some plugins, select them in the table and click Update.
  • Automatic updates in the Maintenance card: choose Safe automatic updates to run the same snapshot-update-check-rollback cycle every night, or Off (WordPress defaults) to leave updates to WordPress.
  • The Auto-update switch on each plugin row controls WordPress's own automatic update for that plugin.

If the site already had a problem before the update, ZoPanel notes it in the log and does not roll back for that reason.

Staging copy and publishing to live

A staging copy is a full copy of the site (files and database) on another domain, hidden from search engines, where you can test changes.

  1. Click Create staging. The domain defaults to staging.<your domain>; any domain or subdomain of the account works.
  2. Point that name to the server. SSL is issued automatically once DNS resolves.
  3. Work on the staging site. Its WordPress tab shows staging of example.com.
  4. When ready, open the staging site's WordPress tab and click Publish to live.

Publishing replaces the live site's files (except wp-config.php, .user.ini and .maintenance) and its database with the staging ones. ZoPanel replaces the staging URL with the live URL throughout the database (a wp-cli search-replace), keeps the live site's search-engine visibility setting and flushes caches. A snapshot of the live site is taken first: if the live site breaks after publishing, it is restored automatically.

Clone makes an independent copy on another domain instead (files, database, URLs replaced), for example to start a new site from an existing one. Staging copies and clones count toward the package's website and database limits.

Plugins and themes

The Plugins table lists every plugin with its version, status and pending update. Select plugins to Update, Activate, Deactivate or delete them. The Themes list shows the active theme and lets you Activate another one.

Maintenance card

Option Effect
Visible to search engines WordPress's "Search engine visibility" setting.
Maintenance mode Shows WordPress's maintenance page to visitors.
Debug logging (wp-content/debug.log) Turns on WP_DEBUG and WP_DEBUG_LOG, never displaying errors to visitors. Turn it off when you are done.
Server runs scheduled tasks (every 5 min, not on visits) See below.
Flush caches Runs wp cache flush and deletes all transients.

Server runs scheduled tasks

WordPress normally runs its scheduled tasks (scheduled posts, shop emails, plugin jobs) from visitor requests by calling its own wp-cron.php. Quiet sites then run them late or never, busy sites pay for an extra PHP request, and if the domain resolves slowly each call can hold a PHP worker for 10 to 20 seconds.

When you turn this option on, ZoPanel:

  1. sets DISABLE_WP_CRON to true in wp-config.php;
  2. creates a systemd timer that runs the due tasks every 5 minutes with wp-cli (wp cron event run --due-now), as the hosting account, inside its resource limits and at low CPU and disk priority. Sites are spread over the interval.

Turning it off removes the timer, and removes DISABLE_WP_CRON only if ZoPanel added it. A site that had already disabled wp-cron itself keeps its own setting.

Caching for WordPress

Two caches work together. Both are on the PHP & config tab:

  • Page cache serves whole pages from nginx to anonymous visitors. Logged-in users, carts, checkout and admin pages are never cached. A small must-use plugin purges the site's cached pages whenever content changes, and Purge cache clears them by hand. See Websites and PHP.
  • Redis object cache keeps database query results in Redis (with the Redis Object Cache plugin), which helps wp-admin, WooCommerce and logged-in users. Redis must be installed on the server under Databases; ZoPanel creates a private Redis database for the site and configures the plugin.

WordPress not detected?

If the tab says WordPress is not installed, check that WordPress is in the website's document root (PHP & config → Document root), then reload the page.


← SSL certificates Git deploy →