Install WordPress
Install WordPress on a new or existing website, or bring an existing WordPress site over, then sign in, secure it and fix common installation errors.
ZoPanel installs WordPress with wp-cli: it creates the database, downloads the latest WordPress, writes wp-config.php and creates your administrator in one task. Use this page to get WordPress running. Once it runs, the WordPress Toolkit covers updates, staging, security and maintenance.
Before you start
- Point the domain to the server first. Create the A (and AAAA) records as described in Your first website. When the domain already resolves to this server, the certificate is issued before WordPress is installed, so WordPress starts on
https://. - A PHP version must be installed. The new-website dialog uses PHP 8.3 when it is installed, otherwise another installed version.
- The package must allow one more database. Every installation creates its own database. On the Free license, the whole server can have 10 databases (see Licensing).
- The package must include WordPress. A package can leave out App installer & WordPress tools (see Packages and limits). Its customers then get "this feature is not included in your hosting package".
Option 1: create a new website with WordPress
- Open Websites and click New website.
- Enter the Domain without
http://, for exampleexample.com. Keep Also serve www.example.com ticked if you want both names. - Administrators and resellers: choose the Owner (the hosting account).
- Under Website type, choose WordPress.
- Choose the PHP version.
- Keep Free SSL (Let's Encrypt) on.
- Fill in WordPress settings (see the table below).
- Click Create website. A task window shows each step. You can close it: the task keeps running, and Tasks keeps its log.
Installation fields
| Field | Default | Rules and effect |
|---|---|---|
| Site title | The domain | The name WordPress shows in the header and browser tab. Up to 200 characters. You can change it later in WordPress under Settings → General. |
| Admin email | The email of your panel login | Required. WordPress sends password resets and admin notices here. |
| Admin username | admin |
3 to 60 characters: letters, digits, ., _, @ and -. |
| Admin password | A generated 16-character password | 8 to 128 characters, no colon. Copy it before you click Create website: the panel does not show it again. |
WordPress is installed in the language of the panel: Vietnamese when you use the panel in Vietnamese, English (en_US) otherwise.
Important: change Admin username from admin before you create the site. Bots try admin first, and the toolkit's security check flags an administrator with that name. A WordPress username cannot be renamed from wp-admin later.
Option 2: install WordPress on an existing website
- Open the website and stay on the Overview tab.
- In the Applications card, click Install WordPress.
- Check Site title, Admin email, Admin username and Admin password (same rules as above).
- Click Install.
The Applications card appears only when the website runs PHP (not a reverse proxy), has no application installed yet, and its document root is inside public_html. WordPress is installed into the document root. Start from an empty document root: ZoPanel removes its own placeholder index.html, but leaves your other files in place.
WordPress uses https:// if the website already has a certificate, and http:// otherwise. Installing also switches the website to the WordPress nginx rules (see below).
What the installation does
The task log shows these steps:
- SSL (new websites with SSL on): the certificate is requested. If the domain does not point to the server yet, the log says "SSL could not be issued" and the installation continues over HTTP.
- Database: a MariaDB database and user named
<account>_wp<4 random characters>are created with a random 24-character password and linked to the website. The password is only written intowp-config.php. - Download: the latest WordPress is downloaded. A network failure (DNS timeout, reset connection) is retried up to 3 times.
- Configuration:
wp-config.phpis written withDB_HOSTlocalhostand made readable by the account only (mode 640). - Install: WordPress is installed with your title and administrator. No welcome email is sent.
- Scheduled tasks: the server takes over WordPress's scheduled tasks and runs them every 5 minutes (see Server runs scheduled tasks).
- Warm-up: the home page is requested once so the first visitor gets a compiled page.
The website uses the WordPress nginx rules: pretty permalinks work without .htaccess, and xmlrpc.php, PHP files in wp-content/uploads and direct access to wp-config.php, readme.html and license.txt are blocked.
Option 3: bring an existing WordPress site
| Where the site is now | Use |
|---|---|
| A cPanel or DirectAdmin server | Migrate in. Files, databases (with their users and passwords), email and cron jobs come over together. See Migrating to ZoPanel. |
| Another ZoPanel server | Move to another server on the website's Overview tab (administrators). Database names, users and passwords stay the same, so wp-config.php needs no change. |
| Anywhere else | Copy it by hand, as below. |
Move a WordPress site by hand
-
On the old host, download a copy of the files (a
.zipor.tar.gzof the WordPress folder) and an SQL dump of the database. -
Create the website in ZoPanel with the PHP type (not WordPress, which would install a new copy).
-
Open File Manager, go to
domains/<domain>/public_html, delete the placeholderindex.html, upload the archive and click Extract. See File Manager. For large sites, SFTP or rsync is faster (see SSH access and terminal). -
In Databases, click New database, choose Link to website, and store the password.
-
In the database's menu, choose Import / restore and upload the dump (
.sqlor.sql.gz). -
Edit
wp-config.phpin the File Manager and set the new values:define( 'DB_NAME', 'alice_shop' ); define( 'DB_USER', 'alice_shop' ); define( 'DB_PASSWORD', 'the password from step 4' ); define( 'DB_HOST', 'localhost' ); -
If the domain changed, replace the old address in the database from the terminal, with a dry run first:
cd domains/new-domain.com/public_html wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid --dry-run wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid -
Open the website's WordPress tab. ZoPanel reads the installation with wp-cli, so the toolkit works as for a site it installed.
-
In the Security card, click Apply all. This also switches the website to the WordPress nginx rules. Alternatively, set PHP & config → Rewrite rules to WordPress.
-
In the Maintenance card, turn on Server runs scheduled tasks (every 5 min, not on visits). It is only turned on automatically for installations made by ZoPanel.
Note: the Install WordPress button can still appear on the Overview tab of a site you copied by hand. Do not use it: it refuses to run with "WordPress is already installed in this website".
Sign in to WordPress
- WP Admin at the top of the website page opens
https://<domain>/wp-admin(shown on websites where ZoPanel installed WordPress, or after Apply all in the Security card). You can also type that address yourself. - Log in to WordPress on the WordPress tab signs you in as the first administrator without a password. The panel creates a single-use link that is valid for 60 seconds, and the activity log records it. Allow pop-ups for the panel if nothing opens.
If you lose the admin password, use Reset password in the Security card of the WordPress tab.
First steps after the installation
- HTTPS: on the SSL tab, check that a certificate is installed, then turn on Redirect HTTP to HTTPS. See SSL certificates.
- Page cache: on PHP & config, turn on Page cache. Logged-in users, carts, checkout and admin pages are never cached. See Websites and PHP.
- Permalinks: in wp-admin, open Settings → Permalinks and choose a structure such as Post name. No
.htaccesschange is needed. - Security: on the WordPress tab, review the Security card and click Apply all.
- Updates: in the Maintenance card, choose Safe automatic updates to update every night with a snapshot and automatic rollback. See WordPress Toolkit.
If DNS does not point to the server yet
You can install WordPress before switching DNS, but:
- WordPress is installed with
http://<domain>as its address, because no certificate can be issued yet. - ZoPanel keeps trying to issue the certificate every hour and installs it as soon as the domain resolves to the server. It then switches WordPress from
http://<domain>tohttps://<domain>automatically (a wp-cli search-replace, so links in posts change too; the task log says "WordPress now uses https://…").
If WordPress uses another address (for example a temporary domain), switch it yourself once the certificate is installed, either in wp-admin under Settings → General (WordPress Address (URL) and Site Address (URL)), or in the terminal:
cd domains/example.com/public_html
wp search-replace 'http://old-address' 'https://example.com' --skip-columns=guid
Once WordPress uses https://, turn on Redirect HTTP to HTTPS on the SSL tab.
To preview the site before DNS switches, add a line for the domain to the hosts file of your own computer (/etc/hosts on macOS and Linux, C:\Windows\System32\drivers\etc\hosts on Windows), then remove it when DNS is live:
203.0.113.10 example.com www.example.com
Troubleshooting
| Message or symptom | What to do |
|---|---|
| "the package of alice allows 10 databases" or "database limit reached" | The account's package has no database left. Delete an unused database or raise Databases in the package. |
| "your Free plan allows 10 databases" | The server's license limit is reached. See Licensing. |
| "this feature is not included in your hosting package" | The package leaves out App installer & WordPress tools. Ask your provider. |
| "WordPress needs a PHP website" | The website is static or a reverse proxy. Set a PHP version on PHP & config and set Application port to 0, or create a new PHP website. |
| "WordPress admin username is too short" / "invalid WordPress admin username" | Use 3 to 60 characters: letters, digits, ., _, @, -. |
| "WordPress admin password: password must be 8-128 characters" or "contains forbidden characters" | Use 8 to 128 characters without a colon. |
| "WordPress is already installed in this website" | The document root already has a wp-config.php. Use the WordPress tab, or remove the old files first. |
| "wp core download failed: … cURL error 6/28 …" | The server could not reach wordpress.org after 3 attempts. Check the server's DNS resolver and outgoing HTTPS, then install again from the Overview tab. |
| "wp-cli is not installed" | The installer could not download wp-cli. Ask the administrator to rerun the installer or install wp-cli to /usr/local/bin/wp. |
| "SSL could not be issued" in the log | DNS does not point to the server yet, or port 80 is closed. WordPress still works over HTTP: see If DNS does not point to the server yet. |
| The WordPress tab says WordPress is not installed | WordPress must be in the website's document root (PHP & config → Document root). Reload the page after uploading. |
| "no WordPress administrator found" | WordPress has no user with the Administrator role. Create one with wp user create in the terminal. |
| "This login link has expired." | The one-time link was used or is older than 60 seconds. Click Log in to WordPress again. |
| "the database of example.com (…) is not one of the account's databases" | Updates and staging need the database to belong to the account. Create the database in Databases and point wp-config.php to it. |
Related
- WordPress Toolkit
- Your first website
- SSL certificates
- Migrating to ZoPanel
- File Manager
- WordPress documentation and Changing the site URL