Skip to main content
Features

Everything you need to host WordPress on your own servers

WPL7 is a control panel you run on your own servers. Sites, WordPress updates, backups, mail, security and servers live in one place. WPL7 is currently in beta.

Sites

Launch sites in minutes, go live without downtime

Create a site in four steps, build it on a dev address, then move it to the customer’s domain when it’s ready. Certificates, PHP, files and logins are handled per site.

  • New site wizard. Four steps. The site answers at once on <slug>.dev.yourdomain, or you can create it on the customer’s domain directly.
  • Go live. Up to 10 customer domains per site. The dev address can stay as a 301, and URLs are rewritten in the database with no downtime.
  • Automatic HTTPS. Let’s Encrypt certificates for every hostname, plus a wildcard certificate for dev sites with a Cloudflare token.
  • PHP per site. 8.2, 8.3, 8.4 or 8.5, switchable. If the site doesn’t answer on the new version, it rolls back.
  • Files and FTP. A web file manager with PHP syntax check, resumable uploads up to 2 GiB, zip/unzip and search; every change is logged. FTP/SFTP logins per site, optionally limited to a folder and with an expiry. SFTP runs on port 2222; plain FTP is always refused (TLS only).
  • Visitor stats. Read from the server’s access log: no script, no cookie. Visitors, page views, top pages, referrers and countries, with bots counted separately.
WPL7 sites list showing every site with its domain, server, PHP version and statusWPL7 sites list showing every site with its domain, server, PHP version and status
WPL7 go-live dialog for moving a site from its dev address to customer domains
Go live: add up to 10 customer domains and keep the dev address as a 301.
WPL7 visitor statistics for a site with visitors, page views, top pages, referrers and countriesWPL7 visitor statistics for a site with visitors, page views, top pages, referrers and countries
Visitor stats from the server’s access log — no script, no cookie.
WordPress

Every plugin, theme and WordPress version in one place

See what runs where, update it across many sites at once with safety checks switched on, and know which versions are vulnerable.

  • One inventory. Every plugin, theme and WordPress version across all sites. Update, activate, deactivate or delete on many sites at once.
  • Safe by default. “Back up first” and “check the site answers afterwards” are on by default.
  • Vulnerability ratings. From wpvulnerability.net; only slugs and versions are sent. “Fix vulnerable” updates only what a release fixes, and auto-updates can be limited to security fixes.
  • Plugin catalog. wordpress.org plugins plus your own premium zips, malware-checked on upload. Defaults are pre-ticked for new sites.
  • Licence recipes. Pro plugin licences are activated on new sites, re-activated when a domain changes and released on delete (ACF PRO and Breakdance included).
  • Everyday tools. One-click wp-admin login, maintenance mode and a WP-CLI console.
WPL7 bulk WordPress view listing plugins, themes and core versions across all sites with update actions
WordPress tab of a single site in WPL7 with its plugins, themes and core versionWordPress tab of a single site in WPL7 with its plugins, themes and core version
The WordPress tab of a single site, with one-click wp-admin login.
WPL7 licence recipes for activating pro plugin licences on new sites
Licence recipes activate pro plugins on new sites and release them on delete.
Backups

Backups you can restore, even without WPL7

Every site is backed up as plain files on a schedule and before risky changes, with optional verified copies to offsite storage.

  • Plain files. A database dump, a files archive, a manifest and checksums. You can restore them without WPL7.
  • Scheduled and kept. Daily at 03:00 by default (the cron is configurable), keeping the newest 10 per site. Backups taken before updates, restores, deletion and moves are kept until you delete them.
  • Careful restores. Checksums are verified first and a pre-restore backup is taken; the previous files are kept aside for a day.
WPL7 backups overview listing backups for all sites with dates, sizes and restore actionsWPL7 backups overview listing backups for all sites with dates, sizes and restore actions
WPL7 offsite storage settings for rclone remotes such as S3, SFTP and WebDAV
Offsite storage: add any rclone remote and every copy is verified.

Offsite copies

  • Any storage. Via rclone: S3 and S3-compatible (Backblaze B2, Cloudflare R2, Wasabi, Hetzner…), SFTP, FTP/FTPS, WebDAV or any rclone remote.
  • Verified. Each copy is verified; failed copies are retried and you get an alert email.
  • Encrypted if you want. Optional client-side encryption of contents and file names.
Mail

Email from every site, without an SMTP plugin

Each server runs a send-only relay, so WordPress mail just works, signed with DKIM and limited to each site’s own domains.

  • No SMTP plugin. wp_mail() works on every site via a relay on each server.
  • DKIM per domain. A 2048-bit key per domain, created in the panel and copied to every server.
  • No impersonation. Each site can only send as its own domains, so a hacked site can’t impersonate another customer.
  • Guided DNS setup. SPF, DKIM, DMARC, reverse DNS and port 25, checked against public DNS. With a Cloudflare token the panel publishes the records itself.
  • Traffic view. Every message, the queue, volume per site and 30 days of history. An abuse guard flags and suspends sites that send too much.
  • Send-only. No inboxes to run. A smarthost is optional.
WPL7 mail overview with sending domains, DKIM status and recent volumeWPL7 mail overview with sending domains, DKIM status and recent volume
WPL7 mail setup guide checking SPF, DKIM, DMARC, reverse DNS and port 25 against public DNS
The setup guide checks SPF, DKIM, DMARC, reverse DNS and port 25.
WPL7 mail traffic view with messages, queue and volume per site
Traffic: every message, the queue and volume per site, with 30 days of history.
Security

Protection that lives outside the site

Firewall rules, the fleet block list and malware scans run at server level, where a compromised site can’t switch them off.

  • Fleet block list. Attacks are detected every minute across all sites and servers. A block reaches every server’s firewall within a minute and grows on repeat offences; verified search engines are never blocked.
  • Daily malware scans. In a throwaway container with no network, checked against wordpress.org checksums and AMWScan signatures. Quarantine, reinstall or ignore.
  • Isolation. One container and one network per site, with CPU, memory and process limits. Two-factor authentication for panel accounts.
WPL7 security overview across all sites with the fleet block list and malware scan resultsWPL7 security overview across all sites with the fleet block list and malware scan results
WPL7 security tab of a single site with firewall level and custom rules
Each site gets its own firewall level and custom rules.

Per-site firewall

  • Three levels. Off, Standard (default) or Strict. Blocks secret files, PHP in uploads, scanners and user enumeration, and rate-limits logins; custom rules per site.
  • Out of reach. Rules live outside the site, read-only, so nothing the site can write turns them off.
Servers

Many servers, one panel

Add servers over SSH and run them from one place. Every change is a job you can follow, and sites keep serving even when the panel is down.

  • Add a server over SSH. Point the panel at a fresh Ubuntu 26.04 VPS and it sets it up.
  • Independent sites. Each site lives on one server; if the panel is down, the sites keep serving. Sites can move between servers.
  • Monitoring. Load, memory and disk per server, and uptime, CPU and memory per site, every minute.
  • Jobs with live logs. Every change is a job that shows who started it: an admin, an API key, an AI app or a schedule.
  • Schedules. Built-in schedules plus up to 100 custom ones: backups, updates, WP-CLI, shell commands and REST requests.
  • Terminal and updates. A root terminal in the browser, and one-click panel updates that roll back if the new version doesn’t come up.
WPL7 servers list with load, memory and disk for each serverWPL7 servers list with load, memory and disk for each server
WPL7 jobs list with live log output and who started each jobWPL7 jobs list with live log output and who started each job
Every change is a job with a live log and who started it.
Root terminal in the WPL7 panel, dark theme
A root terminal in the browser.
Automation

An API and an MCP server for everything

Script the panel over REST, or let AI apps like Claude and ChatGPT run it, at the access level an admin approves.

  • REST API. Everything the panel does, with Bearer tokens. Slow actions return a job you can follow.
  • API keys. Three levels: Read only, Manage and Full. An activity log of every request for 30 days, and an API console built into the panel.
  • MCP server. At panel.yourdomain/mcp, so Claude, ChatGPT, Claude Code, Cursor and VS Code can run the panel. It is off until you switch it on.
  • Approved access. Apps connect by OAuth with admin approval, or with an API key. Each app gets the level an admin approves, revocable at any time.
  • Hard limits. The terminal, admin accounts and API keys are never reachable through MCP, and jobs show “Claude via MCP (approved by …)”.
WPL7 MCP settings in the dark theme with connected AI apps and their approved access levels
WPL7 REST API documentation and console built into the panelWPL7 REST API documentation and console built into the panel
The API reference and console, built into the panel.
WPL7 API keys list with Read only, Manage and Full access levels
API keys at three levels, with 30 days of request history.

Run WordPress hosting on your own servers

Install WPL7 on a fresh server with the step-by-step guide, or read the source on GitHub. WPL7 is in beta.

Prefer that we set it up for you? Managed setup →