Skip to content
How to install

Known limits

What WPL7 does not do, does not contain or does not automate, as each page says it in its Limits section. Each heading links to the page with the details.

  • The installer is for Ubuntu 26.04 on x86-64. The images are not built for ARM.
  • Piped into bash, the installer asks nothing. Every answer is a flag, and the panel generates the admin password.
  • The generated password is printed once, on the first boot. Editing PANEL_ADMIN_PASSWORD in .env afterwards changes nothing.
  • Without a Cloudflare token, each dev site gets a certificate of its own. Let’s Encrypt limits how many certificates one domain gets per week.
  • Only Ubuntu 26.04 on x86-64. On another release, setup.sh warns and carries on.
  • The installer refuses a directory that already holds an install.
  • Docker publishes ports past UFW: 80 and 443, plus the FTP ports while a site has an FTP login.
  • The generated password is printed once. Editing PANEL_ADMIN_PASSWORD in .env later changes nothing.
  • An install from a checkout cannot use the update button in the panel.
  • Lost the admin password? Reset a user’s password on the WordPress tab makes a new one.
  • A site’s slug cannot be changed after it is created.
  • Search engines stay discouraged after going live. Untick Discourage search engines from indexing this site in WordPress under Settings → Reading.
  • The list has no search and no selection. To change many sites at once, use Bulk management.
  • The uptime check asks for one page. A site that answers it can still be broken elsewhere.
  • Mode only says whether the site went live. It does not check that the domain’s DNS still points at the server.
  • The slug cannot be changed later. A few names are reserved, such as admin, api, www, new and bulk.
  • A site has at most ten domains, and a domain belongs to one site only.
  • Search engines stay discouraged until you untick the setting in WordPress. Going live does not change it.
  • If the cleanup after a failure fails too, the site stays as Error. Delete site on its Settings tab removes it.
  • At most ten domains per site, and a domain belongs to one site.
  • The panel checks DNS but does not wait for it. A domain that points elsewhere gets no certificate until its record is fixed.
  • The Cloudflare option only reaches zones in the account the token belongs to. Other domains need their records created by hand.
  • Going live does not let search engines in. A new site starts with Discourage search engines from indexing this site ticked. Untick it in WordPress under Settings → Reading.
  • Changes need the site to be running. A stopped site shows its last scan.
  • The panel does not renew the maintenance page, and Log in to WordPress does not work while it shows.
  • A failed update is not rolled back. Restore the backup from the Backups tab.
  • Deleting a plugin leaves its database tables and options behind.
  • Longer commands belong in your own scheduled jobs.
Limit Value
A file in the editor, and one save 8 MiB
One upload 2 GiB
Free disk an upload or extraction must leave 1 GiB
Entries listed per folder 10,000
One search 1,000 matches or 45 seconds
Entries one compress may take 200
Downloads at once, per server 3
  • The site has to be running. A stopped site’s tab offers Start the site.
  • While any job other than a backup runs on the site, changes are refused. Browsing and downloading carry on.
  • Binary files and text that is not UTF-8 open read-only or download.
  • A folder keeps work tidy, not people out. PHP uploaded there runs as the site and can read all of it.
  • FTP needs the server’s public IPv4 address. Without one, the server offers SFTP only.
  • A cloud firewall in front of the server has to allow the ports. Only IPv4 is served.
  • Repeated failed logins ban an address for 30 minutes, and longer each time.
  • An interrupted upload starts over instead of resuming.
  • Countries follow address registrations. A company’s network shows where it registered its addresses, not where the visitor sits.
  • A crawler that presents itself as a browser counts as a visitor.
  • Only requests that reach Traefik count. Pages a CDN serves from its cache never arrive.
  • The first read of a server’s log goes back six hours at most. Nothing older is filled in.
  • Resource limits apply to all sites alike. One site cannot have limits of its own.
  • Switching PHP replaces the container, so the site does not answer for a few seconds.
  • If a recreated container starts but does not answer, Recreate container leaves it in place. The job log warns about it.
  • A vendor that cannot be reached keeps its license activation. The job warns, and the site is deleted anyway.
  • A dev site keeps serving while it is copied, so changes made meanwhile are lost.
  • A site keeps its dev address. One created under another server’s dev domain keeps that domain, so it needs an A record of its own on the new server.
  • Outgoing mail now leaves from the new server’s address. With direct delivery, add that address to each domain’s SPF record.
  • A hostname with an AAAA record is never finalized automatically. Use Finalize now.
  • Older backups stay on the old server. Restoring one needs its offsite copy, fetched back first.
  • The old server cannot be removed while a cleanup is pending.
  • A failed update is not rolled back. Restore the pre-update backup from the site’s Backups tab.
  • Pre-update backups stay until you delete them, so they use disk.
  • A site that has never been scanned cannot join a run.
  • Bulk management changes what is installed. It does not install new plugins.
  • The panel sends no email when a site or a server goes down. You see it in the lists and on the dashboard only.
  • The uptime check runs from the server itself, through its Traefik. It does not test DNS, or the route a visitor takes from outside.
  • The disk figures cover the filesystem that holds /srv. A backup location on another disk shows under Backups → Storage instead.
  • Resource samples are kept for seven days. The charts show at most the last 24 hours.
  • The dialog connects on SSH port 22. Add a server on another port through the API, with sshPort.
  • Without a Cloudflare token, the panel creates no DNS records and gives no reminder. Create each site’s record by hand.
  • The panel’s key is root on every server that trusts it. Protect /srv/panel/ssh like a root password.
  • The panel does not move sites off a server that is down.
  • At most ten terminals are open at once, across all servers and people.
  • A session closes after 30 minutes without input or output.
  • An open shell keeps running after you sign out, or after your account is removed, until it exits or idles out.
  • On the panel’s own server, the terminal connects to SSH on port 22. The SSH daemon must accept root logins with a key.
  • An API key needs Full access to open a terminal, and AI apps over MCP cannot open one.
  • The shell is root. Nothing it does is checked, contained or undone by the panel.
  • A site’s disk figure counts its files, not its database.
  • A backup needs free disk of one and a half times the site’s size. With less, it fails.
  • Docker publishes its ports past UFW. A UFW rule does not close 80, 443 or the FTP ports.
  • The FTP ports are published on IPv4 only.
  • Housekeeping runs once a night. It does nothing about a disk that fills up during the day.
  • The panel shows no container logs. Read them in the Terminal.
  • The numbers are as old as the last read. A plugin installed in wp-admin appears after the next scan.
  • Stopped sites are not read on schedule. Check now needs the site running.
  • The panel takes at most ten Check now requests a minute.
  • Must-use plugins and drop-ins are listed, but the panel does not manage them.
  • A failed read keeps the previous list, and shows the error beside it.
  • Malware that was in a zip when you uploaded it, and that AMWScan does not know, is vouched for on every site that has the file.
  • A zip with no single folder at its top, or one that unpacks to more than 1 GB, vouches for nothing.
  • Zips are checked only while Scan every site is on, in Settings → Security.
  • In the panel, the catalog serves new sites only. A site’s WordPress tab installs from wordpress.org. An uploaded zip reaches an existing site through the API only.
  • A new advisory shows once the panel next refreshes that slug, up to a day later.
  • A failed update is not undone automatically. Restoring the backup also undoes every other change made to the site since.
  • Where no fixed release exists, Fix vulnerable leaves the plugin as it is. Deactivating it is your decision.
  • Every administrator of a site with the plugin can read its key. That is what licensing a site means.
  • Release on delete is best effort. If the vendor cannot be reached, the activation stays.
  • Whether a dev address counts against a license is the vendor’s rule.
  • Disabling or uninstalling a recipe leaves what it already activated. Its constants leave a site at that site’s next recipe run.
  • A command that prints a key in another form, cut short or in capitals, shows it in the job log.
  • A recipe step runs inside the site’s container. It can do what a site administrator can, and nothing on the server.
  • A backup reads the files while the site serves visitors. A file changed meanwhile may not match the database dump.
  • A stopped site is not backed up on schedule.
  • A backup restores onto a site of the same name only. There is no restore into a new site under another name.
  • The panel’s SSH key is not in the panel’s own backup. Keep a copy of /srv/panel/ssh somewhere else.
  • Only scheduled backups and panel snapshots are pruned. Everything else stays until you delete it.
  • A restore replaces everything that changed since the backup: posts, orders, comments and uploads.
  • A backup restores only onto the site of the same name, on the server that holds the backup. From another server, fetch it back from an offsite copy, or move the site back first.
  • A deleted site’s backup has no Restore. Create a site with the same name first.
  • The panel’s own database is restored by hand, never from the panel.
  • The files a restore set aside are deleted by the nightly housekeeping, a day or more later.
  • An API key needs Manage access to restore, and Full access to download the panel’s own database.
  • A location may not be /, a system folder, or inside or around the live data under /srv: sites, mysql, panel, mail, traefik and plugins.
  • When the panel takes BACKUP_ROOT at start, it moves nothing. Backups taken before stay where they were, listed and restorable, until retention removes them or you delete them.
  • The location of a server the panel cannot reach cannot be changed.
  • Backups stay on their server when a site moves to another one.
  • The panel lists only the copies it made. Older backups in a bucket you set up again are read by hand.
  • Removing a destination drops the backups kept only there from the panel’s lists. Their files stay.
  • Credentials and the passphrase are stored in the panel’s database in plain text. Encryption protects the copies from the provider, not from someone who has the panel.
  • A panel snapshot holds every credential the panel has. Copy it only where you would keep them.
  • A Custom rclone remote takes its other settings through the API only. A Provider cannot be changed after saving.
  • Copies are checked after upload, never test-restored.
  • A deleted backup cannot be recovered, from the server or from a destination the panel cleared.
  • A backup cannot be deleted while it is being written or uploaded, or while a job for its site may be reading it.
  • A destination that manages its own retention keeps its copies. Remove them with the provider’s tools.
  • Deleting a backup’s local files with Keep the remote copies leaves it restorable only after Fetch back.
  • WPL7 sends mail and does not receive it. Mailboxes for your customers’ domains live elsewhere.
  • A relay that stops takes mail() away from every site on its server. Mail never fails over to another server.
  • Mail from a domain without a DKIM key goes out unsigned. Mail from a domain no site uses is accepted and never signed, and the recipient’s own checks judge it.
  • The smarthost is set per server. The panel does not copy it to the servers it adds.
  • Reverse DNS and a smarthost’s SPF value are always set by hand.
  • Without a token, or for a zone it cannot reach, you add the records by hand. The panel publishes through Cloudflare only.
  • SPF is planned for the delivery mode of the panel’s own server, and checked for IPv4 only.
  • The panel suspends a site by itself but never resumes one. A person decides.
  • Mail the relay accepted before a suspension is still delivered, unless you empty the queue.
  • The guard looks at the last hour only. A slower run stays under it and shows only as a mark.
  • sent means the receiving server accepted the message, not that it reached the inbox.
  • Traffic comes from each relay’s log. If the panel cannot read a log for longer than the server keeps it, the messages in between never appear.
  • The levels allow logins and XML-RPC in bursts of 2, because of an open Traefik bug. Traefik gives an address that pauses a few seconds a full burst again. Attack detection still blocks an address after 20 login attempts in 10 minutes.
  • Requests and assets keep large bursts, which a client renews the same way.
  • Rate limits start from zero whenever a server’s rules change.
  • Without IPv6 in Docker, IPv6 visitors are not limited one by one.
  • A proxy that sends only X-Forwarded-For cannot be trusted.
  • Request bodies are never read. A POST exploit is refused by its path, or not at all.
  • The settings inside the container stop a stolen admin login, not code already running in the site.
  • Detection reacts within about two minutes, not seconds.
  • SSH and FTP are not covered. They keep their own protection.
  • A crawler on a domain the panel does not know is not verified, and can be blocked.
  • A bot whose company publishes no address list is blocked like any visitor when it crosses a rule.
  • Without IPv6 in Docker, direct IPv6 visitors arrive as one private address and are not detected one by one.
  • A scan reads files, not the database. A backdoor that rewrites its file from there comes back.
  • Premium plugins and themes have no checksums. A backdoor in one is found only if AMWScan knows it.
  • Malware already in a catalog zip when you uploaded it, and unknown to AMWScan, is vouched for on every site that has it.
  • Calls to eval() and the like are not findings on their own. A backdoor that hides behind nothing else is found only if a signature knows its shape.
  • Signatures lag behind new malware. Scripts over 1 MiB are read only at their start and end.
  • Two-factor authentication guards the browser sign-in only.
  • Removing an admin leaves every API key working, including keys that person created.
  • A terminal already open outlives the session that opened it, until it exits or sits idle for 30 minutes.
  • On an account without a second factor, whoever reads its recovery mailbox can reset its password.
  • The published address lists and the country tables have no switch of their own.
  • Traefik’s version check has no switch in the panel.
  • Ubuntu itself, such as its package updates, is outside this list.
  • A long job delays the other jobs on its server.
  • The panel runs at most eight jobs at the same time, across all servers.
  • A job stopped partway, by a cancel or a timeout, can leave its work half done. Its log shows how far it got.
  • An interrupted job is not resumed.
  • Built-in schedules cannot be deleted, and their timing is changed in Settings, not here. The housekeeping time is fixed.
  • The tasks marked Always on cannot be paused.
  • New monitoring intervals take effect after the panel restarts.
  • Pausing scheduled backups also stops the nightly snapshot of the panel’s own database.
  • Through the API, pausing, resuming or running a built-in schedule needs a Full key.
  • At most 100 custom schedules.
  • Each server runs one command at a time. A long command delays the other sites’ commands there.
  • A started command cannot be canceled. Only its time limit stops it.
  • A wp godmode command that waits on a chat is refused.
  • Scheduled backups count toward the backup retention, so frequent runs push out older backups.
  • A key belongs to the panel, not to a person. Two-factor authentication does not apply to it, and endpoints that ask for your own password refuse it.
  • A Manage key can read whatever a site holds, license keys included. What it creates inside a site stays after you revoke it.
  • The activity log keeps at most the newest 100,000 requests.
  • There are no webhooks. Your tool polls jobs.
  • Some endpoints are never reachable through MCP, whatever the level: signing in, admin accounts, API keys, the activity log, uploads, binary downloads and the terminal.
  • What an app creates inside a site stays after you revoke it: WordPress users, application passwords, FTP logins, changed files.
  • The panel offers tools only. It has no MCP resources or prompts.
  • The panel writes A records only, never AAAA, because servers are added by their IPv4 address.
  • The panel writes records through Cloudflare only, in the zones the token reaches. Other domains need their records created by hand.
  • The records it writes are not proxied through Cloudflare.
  • Every server issues its own wildcard certificate, for the same names. Turn it on for at most five servers a week.
  • Settings apply to the whole panel. A site’s own PHP version and protection are on its own page.
  • Every admin can change every setting.
  • The panel’s domain, the mail relay and other values in deploy/.env are not here. See Configuration.
  • The backup schedule and other values read from deploy/.env on the first boot belong to the panel afterwards. Editing the file changes nothing.
  • A panel that always has a job running keeps updates waiting.
  • The button needs the panel’s SSH access as root to its own host. A host that refuses root logins updates from the command line.
  • Existing sites keep their site image until their container is recreated.
  • There are no lesser roles. Every admin controls the whole panel and every server, terminal included. Give an account only to someone you would trust with root.
  • Two-factor authentication guards the browser sign-in only. API keys are a separate credential.
  • An owner who forgot the password and has no recovery email, or lost both the phone and the recovery codes, needs a shell on the server to get back in.
  • The theme and accent belong to the browser, not to your account. They do not follow you to another device.
  • The Machine card describes the panel’s own server, not the other servers.
  • The Enterprise package is a premium service offered on wpl7.com, not inside the panel.
  • setup.sh is written for Ubuntu 26.04. On another system it prints a warning and carries on.
  • There is no uninstall script.
  • --dns-provider, --dns-token-stdin, --admin-user and --admin-password only count on the first run, when deploy/.env is written.
  • --dns-provider=hetzner writes HETZNER_API_KEY. Traefik’s ACME library reads that variable as a key for Hetzner’s legacy DNS API, which it marks as deprecated.
  • install.sh refuses a directory that already holds an install. Use update.sh there.
  • Each site has a Docker network of its own, and the panel creates it from Docker’s default address pools. On Docker 29 these hold 31 networks.
  • The stack’s own networks and Docker’s default bridge take four of them, and FTP two more on a server with FTP logins. That leaves room for about 25 sites per server.
  • setup.sh replaces /etc/docker/daemon.json with provision/daemon.json whenever they differ, so a larger address pool added there by hand does not survive the next run.
  • The panel is root-equivalent on its own host. Anyone who can sign in to it can run anything on its servers.
  • A step runs inside the site’s container as www-data, so it can do what a site administrator could do and nothing on the host.
  • Site administrators can read a license key once its plugin is on the site. That is what licensing a site means.
  • Job logs hide a secret only where a step prints it exactly. A vendor’s command that prints it changed, such as in capitals or cut short, can reveal it. Callers with Read only access never see a failed step’s output.
  • Each plugin has one recipe at a time.
  • The steps restore the files and the database. A site rebuilt on another host runs without what the panel adds: its own mail login, its protection rules and its resource limits.
  • The database password of a site is not in its backup. On another host, the site gets a new database user.
  • Restoring the panel’s database rolls back everything the panel knows to that night, users and API keys included.
  • The relay and the DKIM signer follow latest. An install that pulls its images gets their newest release whenever setup.sh runs, which every update does.
  • Traefik and MariaDB follow their minor versions, so patch releases arrive the same way.
  • AMWScan runs with its signature updates switched off. Its signatures are the ones in the pinned image, and they age until a WPL7 release moves the pin.
  • Only the newest release gets fixes. There is no backporting while WPL7 is at 0.x.
  • The bug and security links on the Support page follow WPL7_REPO, so an install from a fork sends its people to the fork’s repository.