# Install WordPress

> Install WordPress on a new or existing website, or bring an existing WordPress site over, then sign in, secure it and fix common installation errors.

Source: https://zopanel.net/docs/wordpress-install  
Updated: 2026-10-09

ZoPanel installs WordPress with wp-cli: it creates the database, downloads the latest WordPress, writes `wp-config.php` and creates your administrator in one task. Use this page to get WordPress running. Once it runs, the [WordPress Toolkit](/docs/wordpress) covers updates, staging, security and maintenance.

## Before you start

- **Point the domain to the server first.** Create the A (and AAAA) records as described in [Your first website](/docs/first-website). When the domain already resolves to this server, the certificate is issued before WordPress is installed, so WordPress starts on `https://`.
- **A PHP version must be installed.** The new-website dialog uses PHP 8.3 when it is installed, otherwise another installed version.
- **The package must allow one more database.** Every installation creates its own database. On the Free license, the whole server can have 10 databases (see [Licensing](/docs/licensing)).
- **The package must include WordPress.** A package can leave out **App installer & WordPress tools** (see [Packages and limits](/docs/packages-limits)). Its customers then get "this feature is not included in your hosting package".

## Option 1: create a new website with WordPress

1. Open **Websites** and click **New website**.
2. Enter the **Domain** without `http://`, for example `example.com`. Keep **Also serve www.example.com** ticked if you want both names.
3. Administrators and resellers: choose the **Owner** (the hosting account).
4. Under **Website type**, choose **WordPress**.
5. Choose the **PHP version**.
6. Keep **Free SSL (Let's Encrypt)** on.
7. Fill in **WordPress settings** (see the table below).
8. Click **Create website**. A task window shows each step. You can close it: the task keeps running, and **Tasks** keeps its log.

### Installation fields

| Field | Default | Rules and effect |
| --- | --- | --- |
| **Site title** | The domain | The name WordPress shows in the header and browser tab. Up to 200 characters. You can change it later in WordPress under **Settings → General**. |
| **Admin email** | The email of your panel login | Required. WordPress sends password resets and admin notices here. |
| **Admin username** | `admin` | 3 to 60 characters: letters, digits, `.`, `_`, `@` and `-`. |
| **Admin password** | A generated 16-character password | 8 to 128 characters, no colon. Copy it before you click **Create website**: the panel does not show it again. |

WordPress is installed in the language of the panel: Vietnamese when you use the panel in Vietnamese, English (`en_US`) otherwise.

**Important:** change **Admin username** from `admin` before you create the site. Bots try `admin` first, and the toolkit's security check flags an administrator with that name. A WordPress username cannot be renamed from wp-admin later.

## Option 2: install WordPress on an existing website

1. Open the website and stay on the **Overview** tab.
2. In the **Applications** card, click **Install WordPress**.
3. Check **Site title**, **Admin email**, **Admin username** and **Admin password** (same rules as above).
4. Click **Install**.

The **Applications** card appears only when the website runs PHP (not a reverse proxy), has no application installed yet, and its document root is inside `public_html`. WordPress is installed into the document root. Start from an empty document root: ZoPanel removes its own placeholder `index.html`, but leaves your other files in place.

WordPress uses `https://` if the website already has a certificate, and `http://` otherwise. Installing also switches the website to the WordPress nginx rules (see below).

## What the installation does

The task log shows these steps:

1. **SSL** (new websites with SSL on): the certificate is requested. If the domain does not point to the server yet, the log says "SSL could not be issued" and the installation continues over HTTP.
2. **Database:** a MariaDB database and user named `<account>_wp<4 random characters>` are created with a random 24-character password and linked to the website. The password is only written into `wp-config.php`.
3. **Download:** the latest WordPress is downloaded. A network failure (DNS timeout, reset connection) is retried up to 3 times.
4. **Configuration:** `wp-config.php` is written with `DB_HOST` `localhost` and made readable by the account only (mode 640).
5. **Install:** WordPress is installed with your title and administrator. No welcome email is sent.
6. **Scheduled tasks:** the server takes over WordPress's scheduled tasks and runs them every 5 minutes (see [Server runs scheduled tasks](/docs/wordpress#server-runs-scheduled-tasks)).
7. **Warm-up:** the home page is requested once so the first visitor gets a compiled page.

The website uses the WordPress nginx rules: pretty permalinks work without `.htaccess`, and `xmlrpc.php`, PHP files in `wp-content/uploads` and direct access to `wp-config.php`, `readme.html` and `license.txt` are blocked.

## Option 3: bring an existing WordPress site

| Where the site is now | Use |
| --- | --- |
| A cPanel or DirectAdmin server | **Migrate in**. Files, databases (with their users and passwords), email and cron jobs come over together. See [Migrating to ZoPanel](/docs/migration). |
| Another ZoPanel server | **Move to another server** on the website's **Overview** tab (administrators). Database names, users and passwords stay the same, so `wp-config.php` needs no change. |
| Anywhere else | Copy it by hand, as below. |

### Move a WordPress site by hand

1. On the old host, download a copy of the files (a `.zip` or `.tar.gz` of the WordPress folder) and an SQL dump of the database.
2. Create the website in ZoPanel with the **PHP** type (not **WordPress**, which would install a new copy).
3. Open **File Manager**, go to `domains/<domain>/public_html`, delete the placeholder `index.html`, upload the archive and click **Extract**. See [File Manager](/docs/file-manager). For large sites, SFTP or rsync is faster (see [SSH access and terminal](/docs/ssh-terminal)).
4. In **Databases**, click **New database**, choose **Link to website**, and store the password.
5. In the database's menu, choose **Import / restore** and upload the dump (`.sql` or `.sql.gz`).
6. Edit `wp-config.php` in the File Manager and set the new values:

   ```php
   define( 'DB_NAME', 'alice_shop' );
   define( 'DB_USER', 'alice_shop' );
   define( 'DB_PASSWORD', 'the password from step 4' );
   define( 'DB_HOST', 'localhost' );
   ```

7. If the domain changed, replace the old address in the database from the [terminal](/docs/ssh-terminal), with a dry run first:

   ```bash
   cd domains/new-domain.com/public_html
   wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid --dry-run
   wp search-replace 'https://old-domain.com' 'https://new-domain.com' --skip-columns=guid
   ```

8. Open the website's **WordPress** tab. ZoPanel reads the installation with wp-cli, so the toolkit works as for a site it installed.
9. In the **Security** card, click **Apply all**. This also switches the website to the WordPress nginx rules. Alternatively, set **PHP & config → Rewrite rules** to **WordPress**.
10. In the **Maintenance** card, turn on **Server runs scheduled tasks (every 5 min, not on visits)**. It is only turned on automatically for installations made by ZoPanel.

**Note:** the **Install WordPress** button can still appear on the **Overview** tab of a site you copied by hand. Do not use it: it refuses to run with "WordPress is already installed in this website".

## Sign in to WordPress

- **WP Admin** at the top of the website page opens `https://<domain>/wp-admin` (shown on websites where ZoPanel installed WordPress, or after **Apply all** in the **Security** card). You can also type that address yourself.
- **Log in to WordPress** on the **WordPress** tab signs you in as the first administrator without a password. The panel creates a single-use link that is valid for 60 seconds, and the activity log records it. Allow pop-ups for the panel if nothing opens.

If you lose the admin password, use **Reset password** in the **Security** card of the **WordPress** tab.

## First steps after the installation

1. **HTTPS:** on the **SSL** tab, check that a certificate is installed, then turn on **Redirect HTTP to HTTPS**. See [SSL certificates](/docs/ssl).
2. **Page cache:** on **PHP & config**, turn on **Page cache**. Logged-in users, carts, checkout and admin pages are never cached. See [Websites and PHP](/docs/hosting#page-cache).
3. **Permalinks:** in wp-admin, open **Settings → Permalinks** and choose a structure such as **Post name**. No `.htaccess` change is needed.
4. **Security:** on the **WordPress** tab, review the **Security** card and click **Apply all**.
5. **Updates:** in the **Maintenance** card, choose **Safe automatic updates** to update every night with a snapshot and automatic rollback. See [WordPress Toolkit](/docs/wordpress#updates).

## If DNS does not point to the server yet

You can install WordPress before switching DNS, but:

- WordPress is installed with `http://<domain>` as its address, because no certificate can be issued yet.
- ZoPanel keeps trying to issue the certificate every hour and installs it as soon as the domain resolves to the server. It then switches WordPress from `http://<domain>` to `https://<domain>` automatically (a wp-cli search-replace, so links in posts change too; the task log says "WordPress now uses https://…").

If WordPress uses another address (for example a temporary domain), switch it yourself once the certificate is installed, either in wp-admin under **Settings → General** (**WordPress Address (URL)** and **Site Address (URL)**), or in the terminal:

```bash
cd domains/example.com/public_html
wp search-replace 'http://old-address' 'https://example.com' --skip-columns=guid
```

Once WordPress uses `https://`, turn on **Redirect HTTP to HTTPS** on the **SSL** tab.

To preview the site before DNS switches, add a line for the domain to the `hosts` file of your own computer (`/etc/hosts` on macOS and Linux, `C:\Windows\System32\drivers\etc\hosts` on Windows), then remove it when DNS is live:

```text
203.0.113.10  example.com www.example.com
```

## Troubleshooting

| Message or symptom | What to do |
| --- | --- |
| "the package of alice allows 10 databases" or "database limit reached" | The account's package has no database left. Delete an unused database or raise **Databases** in the package. |
| "your Free plan allows 10 databases" | The server's license limit is reached. See [Licensing](/docs/licensing). |
| "this feature is not included in your hosting package" | The package leaves out **App installer & WordPress tools**. Ask your provider. |
| "WordPress needs a PHP website" | The website is static or a reverse proxy. Set a **PHP version** on **PHP & config** and set **Application port** to 0, or create a new PHP website. |
| "WordPress admin username is too short" / "invalid WordPress admin username" | Use 3 to 60 characters: letters, digits, `.`, `_`, `@`, `-`. |
| "WordPress admin password: password must be 8-128 characters" or "contains forbidden characters" | Use 8 to 128 characters without a colon. |
| "WordPress is already installed in this website" | The document root already has a `wp-config.php`. Use the **WordPress** tab, or remove the old files first. |
| "wp core download failed: … cURL error 6/28 …" | The server could not reach wordpress.org after 3 attempts. Check the server's DNS resolver and outgoing HTTPS, then install again from the **Overview** tab. |
| "wp-cli is not installed" | The installer could not download wp-cli. Ask the administrator to rerun the installer or install wp-cli to `/usr/local/bin/wp`. |
| "SSL could not be issued" in the log | DNS does not point to the server yet, or port 80 is closed. WordPress still works over HTTP: see [If DNS does not point to the server yet](#if-dns-does-not-point-to-the-server-yet). |
| The **WordPress** tab says WordPress is not installed | WordPress must be in the website's document root (**PHP & config → Document root**). Reload the page after uploading. |
| "no WordPress administrator found" | WordPress has no user with the Administrator role. Create one with `wp user create` in the terminal. |
| "This login link has expired." | The one-time link was used or is older than 60 seconds. Click **Log in to WordPress** again. |
| "the database of example.com (…) is not one of the account's databases" | Updates and staging need the database to belong to the account. Create the database in **Databases** and point `wp-config.php` to it. |

## Related

- [WordPress Toolkit](/docs/wordpress)
- [Your first website](/docs/first-website)
- [SSL certificates](/docs/ssl)
- [Migrating to ZoPanel](/docs/migration)
- [File Manager](/docs/file-manager)
- [WordPress documentation](https://wordpress.org/documentation/) and [Changing the site URL](https://developer.wordpress.org/advanced-administration/upgrade/migrating/)
