Everything you need to host WordPress on your own servers
WPL7 is a control panel you run on your own servers. Sites, WordPress updates, backups, mail, security and servers live in one place. WPL7 is currently in beta.
Launch sites in minutes, go live without downtime
Create a site in four steps, build it on a dev address, then move it to the customer’s domain when it’s ready. Certificates, PHP, files and logins are handled per site.
- New site wizard. Four steps. The site answers at once on
<slug>.dev.yourdomain, or you can create it on the customer’s domain directly. - Go live. Up to 10 customer domains per site. The dev address can stay as a 301, and URLs are rewritten in the database with no downtime.
- Automatic HTTPS. Let’s Encrypt certificates for every hostname, plus a wildcard certificate for dev sites with a Cloudflare token.
- PHP per site. 8.2, 8.3, 8.4 or 8.5, switchable. If the site doesn’t answer on the new version, it rolls back.
- Files and FTP. A web file manager with PHP syntax check, resumable uploads up to 2 GiB, zip/unzip and search; every change is logged. FTP/SFTP logins per site, optionally limited to a folder and with an expiry. SFTP runs on port 2222; plain FTP is always refused (TLS only).
- Visitor stats. Read from the server’s access log: no script, no cookie. Visitors, page views, top pages, referrers and countries, with bots counted separately.


Every plugin, theme and WordPress version in one place
See what runs where, update it across many sites at once with safety checks switched on, and know which versions are vulnerable.
- One inventory. Every plugin, theme and WordPress version across all sites. Update, activate, deactivate or delete on many sites at once.
- Safe by default. “Back up first” and “check the site answers afterwards” are on by default.
- Vulnerability ratings. From wpvulnerability.net; only slugs and versions are sent. “Fix vulnerable” updates only what a release fixes, and auto-updates can be limited to security fixes.
- Plugin catalog. wordpress.org plugins plus your own premium zips, malware-checked on upload. Defaults are pre-ticked for new sites.
- Licence recipes. Pro plugin licences are activated on new sites, re-activated when a domain changes and released on delete (ACF PRO and Breakdance included).
- Everyday tools. One-click wp-admin login, maintenance mode and a WP-CLI console.

Backups you can restore, even without WPL7
Every site is backed up as plain files on a schedule and before risky changes, with optional verified copies to offsite storage.
- Plain files. A database dump, a files archive, a manifest and checksums. You can restore them without WPL7.
- Scheduled and kept. Daily at 03:00 by default (the cron is configurable), keeping the newest 10 per site. Backups taken before updates, restores, deletion and moves are kept until you delete them.
- Careful restores. Checksums are verified first and a pre-restore backup is taken; the previous files are kept aside for a day.

Offsite copies
- Any storage. Via rclone: S3 and S3-compatible (Backblaze B2, Cloudflare R2, Wasabi, Hetzner…), SFTP, FTP/FTPS, WebDAV or any rclone remote.
- Verified. Each copy is verified; failed copies are retried and you get an alert email.
- Encrypted if you want. Optional client-side encryption of contents and file names.
Email from every site, without an SMTP plugin
Each server runs a send-only relay, so WordPress mail just works, signed with DKIM and limited to each site’s own domains.
- No SMTP plugin.
wp_mail()works on every site via a relay on each server. - DKIM per domain. A 2048-bit key per domain, created in the panel and copied to every server.
- No impersonation. Each site can only send as its own domains, so a hacked site can’t impersonate another customer.
- Guided DNS setup. SPF, DKIM, DMARC, reverse DNS and port 25, checked against public DNS. With a Cloudflare token the panel publishes the records itself.
- Traffic view. Every message, the queue, volume per site and 30 days of history. An abuse guard flags and suspends sites that send too much.
- Send-only. No inboxes to run. A smarthost is optional.

Protection that lives outside the site
Firewall rules, the fleet block list and malware scans run at server level, where a compromised site can’t switch them off.
- Fleet block list. Attacks are detected every minute across all sites and servers. A block reaches every server’s firewall within a minute and grows on repeat offences; verified search engines are never blocked.
- Daily malware scans. In a throwaway container with no network, checked against wordpress.org checksums and AMWScan signatures. Quarantine, reinstall or ignore.
- Isolation. One container and one network per site, with CPU, memory and process limits. Two-factor authentication for panel accounts.

Per-site firewall
- Three levels. Off, Standard (default) or Strict. Blocks secret files, PHP in uploads, scanners and user enumeration, and rate-limits logins; custom rules per site.
- Out of reach. Rules live outside the site, read-only, so nothing the site can write turns them off.
Many servers, one panel
Add servers over SSH and run them from one place. Every change is a job you can follow, and sites keep serving even when the panel is down.
- Add a server over SSH. Point the panel at a fresh Ubuntu 26.04 VPS and it sets it up.
- Independent sites. Each site lives on one server; if the panel is down, the sites keep serving. Sites can move between servers.
- Monitoring. Load, memory and disk per server, and uptime, CPU and memory per site, every minute.
- Jobs with live logs. Every change is a job that shows who started it: an admin, an API key, an AI app or a schedule.
- Schedules. Built-in schedules plus up to 100 custom ones: backups, updates, WP-CLI, shell commands and REST requests.
- Terminal and updates. A root terminal in the browser, and one-click panel updates that roll back if the new version doesn’t come up.


An API and an MCP server for everything
Script the panel over REST, or let AI apps like Claude and ChatGPT run it, at the access level an admin approves.
- REST API. Everything the panel does, with Bearer tokens. Slow actions return a job you can follow.
- API keys. Three levels: Read only, Manage and Full. An activity log of every request for 30 days, and an API console built into the panel.
- MCP server. At
panel.yourdomain/mcp, so Claude, ChatGPT, Claude Code, Cursor and VS Code can run the panel. It is off until you switch it on. - Approved access. Apps connect by OAuth with admin approval, or with an API key. Each app gets the level an admin approves, revocable at any time.
- Hard limits. The terminal, admin accounts and API keys are never reachable through MCP, and jobs show “Claude via MCP (approved by …)”.

Run WordPress hosting on your own servers
Install WPL7 on a fresh server with the step-by-step guide, or read the source on GitHub. WPL7 is in beta.