DocsInstall WordPress

Install WordPress

Install WordPress on a new or existing website, or bring an existing WordPress site over, then sign in, secure it and fix common installation errors.

ZoPanel installs WordPress with wp-cli: it creates the database, downloads the latest WordPress, writes wp-config.php and creates your administrator in one task. Use this page to get WordPress running. Once it runs, the WordPress Toolkit covers updates, staging, security and maintenance.

Before you start

  • Point the domain to the server first. Create the A (and AAAA) records as described in Your first website. When the domain already resolves to this server, the certificate is issued before WordPress is installed, so WordPress starts on https://.
  • A PHP version must be installed. The new-website dialog uses PHP 8.3 when it is installed, otherwise another installed version.
  • The package must allow one more database. Every installation creates its own database. On the Free license, the whole server can have 10 databases (see Licensing).
  • The package must include WordPress. A package can leave out App installer & WordPress tools (see Packages and limits). Its customers then get "this feature is not included in your hosting package".

Option 1: create a new website with WordPress

  1. Open Websites and click New website.
  2. Enter the Domain without http://, for example example.com. Keep Also serve www.example.com ticked if you want both names.
  3. Administrators and resellers: choose the Owner (the hosting account).
  4. Under Website type, choose WordPress.
  5. Choose the PHP version.
  6. Keep Free SSL (Let's Encrypt) on.
  7. Fill in WordPress settings (see the table below).
  8. Click Create website. A task window shows each step. You can close it: the task keeps running, and Tasks keeps its log.

Installation fields

Field Default Rules and effect
Site title The domain The name WordPress shows in the header and browser tab. Up to 200 characters. You can change it later in WordPress under Settings → General.
Admin email The email of your panel login Required. WordPress sends password resets and admin notices here.
Admin username admin 3 to 60 characters: letters, digits, ., _, @ and -.
Admin password A generated 16-character password 8 to 128 characters, no colon. Copy it before you click Create website: the panel does not show it again.

WordPress is installed in the language of the panel: Vietnamese when you use the panel in Vietnamese, English (en_US) otherwise.

Important: change Admin username from admin before you create the site. Bots try admin first, and the toolkit's security check flags an administrator with that name. A WordPress username cannot be renamed from wp-admin later.

Option 2: install WordPress on an existing website

  1. Open the website and stay on the Overview tab.
  2. In the Applications card, click Install WordPress.
  3. Check Site title, Admin email, Admin username and Admin password (same rules as above).
  4. Click Install.

The Applications card appears only when the website runs PHP (not a reverse proxy), has no application installed yet, and its document root is inside public_html. WordPress is installed into the document root. Start from an empty document root: ZoPanel removes its own placeholder index.html, but leaves your other files in place.

WordPress uses https:// if the website already has a certificate, and http:// otherwise. Installing also switches the website to the WordPress nginx rules (see below).

What the installation does

The task log shows these steps:

  1. SSL (new websites with SSL on): the certificate is requested. If the domain does not point to the server yet, the log says "SSL could not be issued" and the installation continues over HTTP.
  2. Database: a MariaDB database and user named <account>_wp<4 random characters> are created with a random 24-character password and linked to the website. The password is only written into wp-config.php.
  3. Download: the latest WordPress is downloaded. A network failure (DNS timeout, reset connection) is retried up to 3 times.
  4. Configuration: wp-config.php is written with DB_HOST localhost and made readable by the account only (mode 640).
  5. Install: WordPress is installed with your title and administrator. No welcome email is sent.
  6. Scheduled tasks: the server takes over WordPress's scheduled tasks and runs them every 5 minutes (see Server runs scheduled tasks).
  7. Warm-up: the home page is requested once so the first visitor gets a compiled page.

The website uses the WordPress nginx rules: pretty permalinks work without .htaccess, and xmlrpc.php, PHP files in wp-content/uploads and direct access to wp-config.php, readme.html and license.txt are blocked.

Option 3: bring an existing WordPress site

Where the site is now Use
A cPanel or DirectAdmin server Migrate in. Files, databases (with their users and passwords), email and cron jobs come over together. See Migrating to ZoPanel.
Another ZoPanel server Move to another server on the website's Overview tab (administrators). Database names, users and passwords stay the same, so wp-config.php needs no change.
Anywhere else Copy it by hand, as below.

Move a WordPress site by hand

  1. On the old host, download a copy of the files (a .zip or .tar.gz of the WordPress folder) and an SQL dump of the database.

  2. Create the website in ZoPanel with the PHP type (not WordPress, which would install a new copy).

  3. Open File Manager, go to domains/<domain>/public_html, delete the placeholder index.html, upload the archive and click Extract. See File Manager. For large sites, SFTP or rsync is faster (see SSH access and terminal).

  4. In Databases, click New database, choose Link to website, and store the password.

  5. In the database's menu, choose Import / restore and upload the dump (.sql or .sql.gz).

  6. Edit wp-config.php in the File Manager and set the new values:

    define( 'DB_NAME', 'alice_shop' );
    define( 'DB_USER', 'alice_shop' );
    define( 'DB_PASSWORD', 'the password from step 4' );
    define( 'DB_HOST', 'localhost' );
    
  7. If the domain changed, replace the old address in the database from the terminal, with a dry run first:

    cd domains/new-domain.com/public_html
    wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid --dry-run
    wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid
    
  8. Open the website's WordPress tab. ZoPanel reads the installation with wp-cli, so the toolkit works as for a site it installed.

  9. In the Security card, click Apply all. This also switches the website to the WordPress nginx rules. Alternatively, set PHP & config → Rewrite rules to WordPress.

  10. In the Maintenance card, turn on Server runs scheduled tasks (every 5 min, not on visits). It is only turned on automatically for installations made by ZoPanel.

Note: the Install WordPress button can still appear on the Overview tab of a site you copied by hand. Do not use it: it refuses to run with "WordPress is already installed in this website".

Sign in to WordPress

  • WP Admin at the top of the website page opens https://<domain>/wp-admin (shown on websites where ZoPanel installed WordPress, or after Apply all in the Security card). You can also type that address yourself.
  • Log in to WordPress on the WordPress tab signs you in as the first administrator without a password. The panel creates a single-use link that is valid for 60 seconds, and the activity log records it. Allow pop-ups for the panel if nothing opens.

If you lose the admin password, use Reset password in the Security card of the WordPress tab.

First steps after the installation

  1. HTTPS: on the SSL tab, check that a certificate is installed, then turn on Redirect HTTP to HTTPS. See SSL certificates.
  2. Page cache: on PHP & config, turn on Page cache. Logged-in users, carts, checkout and admin pages are never cached. See Websites and PHP.
  3. Permalinks: in wp-admin, open Settings → Permalinks and choose a structure such as Post name. No .htaccess change is needed.
  4. Security: on the WordPress tab, review the Security card and click Apply all.
  5. Updates: in the Maintenance card, choose Safe automatic updates to update every night with a snapshot and automatic rollback. See WordPress Toolkit.

If DNS does not point to the server yet

You can install WordPress before switching DNS, but:

  • WordPress is installed with http://<domain> as its address, because no certificate can be issued yet.
  • ZoPanel keeps trying to issue the certificate every hour and installs it as soon as the domain resolves to the server. It then switches WordPress from http://<domain> to https://<domain> automatically (a wp-cli search-replace, so links in posts change too; the task log says "WordPress now uses https://…").

If WordPress uses another address (for example a temporary domain), switch it yourself once the certificate is installed, either in wp-admin under Settings → General (WordPress Address (URL) and Site Address (URL)), or in the terminal:

cd domains/example.com/public_html
wp search-replace 'http://old-address' 'https://example.com' --skip-columns=guid

Once WordPress uses https://, turn on Redirect HTTP to HTTPS on the SSL tab.

To preview the site before DNS switches, add a line for the domain to the hosts file of your own computer (/etc/hosts on macOS and Linux, C:\Windows\System32\drivers\etc\hosts on Windows), then remove it when DNS is live:

203.0.113.10  example.com www.example.com

Troubleshooting

Message or symptom What to do
"the package of alice allows 10 databases" or "database limit reached" The account's package has no database left. Delete an unused database or raise Databases in the package.
"your Free plan allows 10 databases" The server's license limit is reached. See Licensing.
"this feature is not included in your hosting package" The package leaves out App installer & WordPress tools. Ask your provider.
"WordPress needs a PHP website" The website is static or a reverse proxy. Set a PHP version on PHP & config and set Application port to 0, or create a new PHP website.
"WordPress admin username is too short" / "invalid WordPress admin username" Use 3 to 60 characters: letters, digits, ., _, @, -.
"WordPress admin password: password must be 8-128 characters" or "contains forbidden characters" Use 8 to 128 characters without a colon.
"WordPress is already installed in this website" The document root already has a wp-config.php. Use the WordPress tab, or remove the old files first.
"wp core download failed: … cURL error 6/28 …" The server could not reach wordpress.org after 3 attempts. Check the server's DNS resolver and outgoing HTTPS, then install again from the Overview tab.
"wp-cli is not installed" The installer could not download wp-cli. Ask the administrator to rerun the installer or install wp-cli to /usr/local/bin/wp.
"SSL could not be issued" in the log DNS does not point to the server yet, or port 80 is closed. WordPress still works over HTTP: see If DNS does not point to the server yet.
The WordPress tab says WordPress is not installed WordPress must be in the website's document root (PHP & config → Document root). Reload the page after uploading.
"no WordPress administrator found" WordPress has no user with the Administrator role. Create one with wp user create in the terminal.
"This login link has expired." The one-time link was used or is older than 60 seconds. Click Log in to WordPress again.
"the database of example.com (…) is not one of the account's databases" Updates and staging need the database to belong to the account. Create the database in Databases and point wp-config.php to it.

← SSL certificates WordPress Toolkit →