How to Create a MySQL Database in cPanel: Users, Privileges and Setup

How do you create a MySQL database in cPanel?
Creating a MySQL database in cPanel means opening the Database Wizard (formerly MySQL Database Wizard), entering a database name, creating a database user with a strong password, and ticking the privileges that user needs. The whole job takes a few minutes. After that, you add the details to your app's config file, such as wp-config.php.
That is the short answer. However, the details are where sites break. A missed username prefix, an overly generous ALL PRIVILEGES box or a wide open remote access rule can leave a site offline or exposed. So this guide walks through each step and checks it against cPanel's own documentation.
We are Talha Aslan and team, a digital marketing and web design group, not a hosting company. Therefore, we verified interface names and limits in the official cPanel MySQL Databases documentation. Your panel may look slightly different, because hosts can switch individual features on or off.
What should you prepare before creating a MySQL database?
A little preparation saves time. You can rename a database later, but cPanel notes that renaming drops active connections, so it is better to choose well up front. Have these ready before you log in:
- The app: WordPress, Laravel, OpenCart or a custom PHP project. Name the database after it.
- A short database name: for example, wpdb or shop. Remember that a prefix will make it longer.
- A separate username: for example, wpuser. That way, one user per app also limits the damage if something goes wrong.
- A strong password: ideally a random string of 16 characters or more.
- The required privileges: check the app's install guide and note what it asks for.
- Remote access needs: if another server will connect, find out its static IP address.
Also, your hosting plan may cap the number of databases you can create. If you hit that limit, remove old databases you no longer use, or instead ask your host about a plan upgrade. In practice, this quick checklist prevents half finished setups.
Database Wizard or Manage My Databases: which one should you use?
cPanel offers two main screens for this work. In cPanel and WHM version 120 and later, MySQL Database Wizard became Database Wizard, and the old MySQL Databases screen became Manage My Databases. However, if your host runs an older release, you will still see the old labels. The functions are the same; only the names changed.
| Feature | Database Wizard | Manage My Databases |
|---|---|---|
| Former name | MySQL Database Wizard | MySQL Databases |
| Best for | Your first database and user | Extra users, privilege changes, maintenance |
| Linking user to database | Automatic | Manual, via Add User To Database |
| Check and Repair | No | Yes |
| Rename and delete | No | Yes |
| Change user password | No | Yes, in Current Users |
cPanel itself recommends the wizard for your first database and user. Still, you will return to Manage My Databases later, for instance to tighten a user's privileges or reset a password. In short, treat the two screens as partners rather than alternatives.
How do you set up a MySQL database with the Database Wizard?
The wizard moves through four short steps and links the user to the database for you. According to the cPanel Database Wizard documentation, the flow looks like this:
- Open Database Wizard from the Databases section of the cPanel home page.
- Type a name into the New Database box and select Next Step. If prefixing is on, the prefix already sits to the left of the box.
- Enter a username in the Username box. This field accepts letters and numbers only.
- Add the password twice, or use Password Generator, and then select Create User.
- Tick the privileges you need on the next screen and finish with Next Step.
Next, a success message appears. From there, you can also add another database, open Manage My Databases to create more users, or go back home. Because the wizard already grants the user access, you do not need the separate Add User To Database step.
Before you leave the screen, save the full database name and full username in a password manager. Prefixed names are easy to mistype, so copy them character for character into the config file. Also, take a moment on the privileges screen; read the privileges section below before you tick ALL PRIVILEGES.
How do you add a database and user separately in Manage My Databases?
The manual route has three separate tasks: create the database, create the user, then link them. The risk is forgetting the last part. In fact, that missing link is one of the most common causes of connection errors.
- Create New Database: type the name in New Database and select Create Database. It then shows up in the Current Databases table.
- Add New User: fill in Username and the password fields, then select Create User.
- Add User To Database: pick the user and the database from the menus and select Add. On the privileges screen, tick the boxes you need and save with Make Changes.
cPanel adds an important warning here: do not use phpMyAdmin to create databases or database users. phpMyAdmin does not map them to your cPanel account, so backups and restores will not work properly. Therefore, create everything in cPanel and keep phpMyAdmin for working with the data itself.
The same screen also offers Check Database and Repair Database. If you suspect a corrupt table, run Check first; if it finds a problem, try Repair. Also, take a backup before any repair attempt.
Why do the cPanel prefix and name length limits matter?
If your host has enabled database prefixing, cPanel adds your account username and an underscore to the front of every name. For example, with the account name exampleacct, a database you call wpdb becomes exampleacct_wpdb. Your config file therefore needs that full name, not the short one.
A database name can have up to 64 characters. However, because of how cPanel stores names, each underscore uses two characters of that limit. With prefixing enabled, the maximum drops to 63 characters, including the prefix and underscore. Username limits depend on the database engine:
| Database engine | Username limit | Left with a db_ prefix |
|---|---|---|
| MySQL 5.6 and earlier | 16 characters | 13 characters |
| MySQL 5.7 and later | 32 characters | 29 characters |
| MariaDB | 47 characters | 44 characters |
These figures come from cPanel's own examples. The wizard also rejects a forward slash, double quotes, single quotes and backticks in database names. So short, lowercase names with few underscores are the safest choice.
The prefix has a second benefit. For example, hundreds of accounts on the same server can all use a short name like wpdb without clashing. On the other hand, it needs care when you move hosts. If the new account has a different username, the database and user names change too. Then update the config file to match, or the site will fail on its first load.
How do you pick a strong password for the database user?
cPanel rates your password on a scale of 100 points, where 0 is weak and 100 is very secure. Some hosts set a minimum score. So when the Strength meter turns green, you have reached that threshold.
The easiest option is the Password Generator button right on the screen. Alternatively, our password generator tool creates long random strings in your browser. Save the result in a password manager straight away, because cPanel will not show it again. If you lose it, the only fix is to set a new one from the Current Users table.
A few habits make passwords easier to live with:
- Never reuse your cPanel or email password for a database user.
- Avoid quote marks that can break a config file. Letters, digits and a few safe symbols are enough.
- Share credentials with a developer through a time limited method, not in the body of an email.
- Rotate the password as soon as a staff member or agency leaves the project.
Should you grant ALL PRIVILEGES or only what the app needs?
When you add a user to a database, cPanel shows a checkbox for each MySQL privilege, with ALL PRIVILEGES at the top. One click feels convenient. However, the principle of least privilege says a user should hold only the rights its job requires. As a result, even if the app has a flaw, an attacker can do less.
The MySQL privileges reference explains each right in detail. Broadly, they fall into three groups:
- Data privileges: SELECT reads, INSERT adds, UPDATE changes and DELETE removes rows. Most daily work runs on these four.
- Structure privileges: CREATE, ALTER, DROP and INDEX change table structure. Installs, updates and plugins often need them.
- Others: LOCK TABLES, CREATE TEMPORARY TABLES, CREATE VIEW, TRIGGER and EXECUTE matter for specific apps.
The rule is simple: grant what the app's install guide asks for. If the guide is silent, ask your developer instead which rights the code truly uses. In other words, ALL PRIVILEGES should be a last resort, not the default.
Which MySQL privileges does WordPress actually need?
The official WordPress hardening guide is clear on this. For normal work such as publishing posts, uploading media, posting comments and adding users, SELECT, INSERT, UPDATE and DELETE are enough. Moreover, removing administrative rights such as DROP, ALTER and GRANT can help contain damage.
That said, the same guide adds a caveat. Some plugins, themes and major WordPress updates make structural database changes. Without those rights, an update can fail halfway. So in practice you have two options:
- Keep CREATE, ALTER, DROP and INDEX enabled during installs and updates, then remove them afterward.
- Leave them enabled and manage the risk with regular, tested backups.
For small business sites, we usually find the second option easier to sustain, because toggling rights before every update is a routine people forget. On the other hand, a store with many plugins may justify the stricter setup. The guide also suggests a separate database and user for each WordPress install, so one compromised site cannot reach another.
How do you connect the database in wp-config.php?
With the database and user ready, the app needs the details. WordPress reads them from wp-config.php, which you can edit in File Manager. The values below are placeholders only; use your own full names and password:
define( 'DB_NAME', 'exampleacct_wpdb' );
define( 'DB_USER', 'exampleacct_wpuser' );
define( 'DB_PASSWORD', 'YOUR_STRONG_PASSWORD' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );The current WordPress sample config uses localhost for DB_HOST and utf8mb4 for DB_CHARSET. On most cPanel accounts, the database runs on the same server, so localhost is correct. That said, cPanel's documentation notes that if your host runs a separate MySQL server, a Remote MySQL Host section appears in Manage My Databases. In that case, use the address shown there as DB_HOST instead.
One more security note. Never paste wp-config.php as is into a public repository, a support forum or an AI chat. If you must share it, mask the password line first. Also, the WordPress guide notes that using a table prefix other than the default wp_ can block some automated SQL injection attacks.
Where do Laravel and other PHP apps store connection details?
The logic is the same everywhere: four core values, namely host, database name, username and password. Only the file and the field names change. For instance, Laravel reads them from the .env file in the project root:
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=exampleacct_laravel
DB_USERNAME=exampleacct_lruser
DB_PASSWORD=YOUR_STRONG_PASSWORDOn shared hosting, localhost or 127.0.0.1 usually works for DB_HOST. If you are unsure, use the value your hosting provider gives you instead. We cover folder layout and protecting the .env file in our guide to deploying Laravel on cPanel and VPS.
Packaged software such as OpenCart or PrestaShop asks for the same details in its installer form. Once you submit the form, the installer then writes the config file for you. Also check that your PHP version suits the app; if you need to switch it, see our guide to changing the PHP version in cPanel.
How do you allow remote MySQL access with Remote Database Access?
By default, only apps on the same server reach your database. So if an app on another server or a desktop SQL client needs to connect, you use Remote Database Access. In cPanel and WHM version 118 and earlier, this screen was called Remote MySQL.
According to the cPanel Remote Database Access documentation, you type a hostname, IPv4 or IPv6 address into the Host box and select Add Host. The Comment field is optional, but noting who the entry is for saves confusion later. To find your own connection's public address, use our what is my IP tool.
The percent sign is the critical detail. cPanel treats it as a wildcard, so a lone percent sign opens your database to connection attempts from anywhere. Follow these rules instead:
- Add only static IP addresses you know, such as 203.0.113.25.
- For changing IPs, like a home connection, delete the entry once the job is done.
- If you spot an entry you do not recognize, ask your host before removing it; cPanel notes that hosts can add entries at server level.
- Where possible, prefer an encrypted route such as an SSH tunnel over open remote access.
What else matters when you connect remotely?
An entry in Remote Database Access may not be enough on its own. MySQL listens on port 3306 by default, yet shared hosts often keep that port closed at the firewall. If the connection times out even after you add the host, the problem is probably at the network layer. In that case, tell your host which IP you will connect from and ask whether the port is open.
Also, a remote connection uses the server's hostname or IP address, not localhost. If the traffic is not encrypted, your password could travel across the network in readable form. So enable TLS in your client or use an SSH tunnel. To confirm your domain points to the right server, try our DNS lookup tool.
Finally, do not treat remote access as a permanent architecture. If apps on two servers need the same database all the time, you have outgrown shared hosting and need a VPS or a managed database service. For that route, our guide on installing MySQL on Ubuntu is a good starting point.
How do you import and export a database with phpMyAdmin?
Once the empty database exists, you will often need to move data from an old site into it. phpMyAdmin in cPanel handles that. To export, follow these steps:
- Open phpMyAdmin and pick the database in the left menu.
- Switch to the Export tab at the top.
- Keep Quick as the method and SQL as the format; for large databases, Custom lets you choose compression.
- Select Go and store the downloaded file somewhere safe.
Importing works the other way round. Pick the target database, upload the SQL file on the Import tab and start with Go. However, the upload limit depends on the server's PHP settings, upload_max_filesize and post_max_size; the Import screen shows the maximum allowed size. If your file is larger, ask your host for help or use the command line.
Before importing, check whether the SQL file contains a CREATE DATABASE line. Such a line tries to create a new database without your cPanel prefix, and on shared hosting it stops with a permission error.
How and how often should you back up a MySQL database?
A phpMyAdmin export is fine for a quick copy, but a real backup plan goes further. cPanel's Backup and Backup Wizard screens let you download and restore databases one by one. Your host may also run its own automatic backups, so find out how often they run and how long they keep them.
The real question is not whether a backup file exists but whether it restores. For that reason, we suggest restoring a backup into a separate test database at least once a month. If you have shell access, our database backup and restore guide covers consistent dumps with mysqldump step by step.
Keeping backups only on the same server is not enough either. If the server fails, the backups go with it. For a wider plan that covers files, databases and email, read our website backup strategy guide.
Why do you get "Access denied for user" and how do you fix it?
This message means MySQL refused the connection. It usually comes in two forms. Error 1045 says the username or password is wrong. Error 1044, by contrast, says the user has no access to that particular database.
Work through the causes in this order:
- Confirm that the username in your config file is the full prefixed name. Writing wpuser instead of exampleacct_wpuser is the most common slip.
- Reset the password in Current Users and paste it into the config file. Watch for leading or trailing spaces.
- Look at the Privileged Users column in Manage My Databases. If the user is missing there, add it with Add User To Database.
- For remote connections, make sure your IP appears in Remote Database Access.
With error 1044, the cause is almost always step three: the user exists and the password is right, but nobody linked the user to the database. With error 1045, focus on the config file instead. A special character that breaks the quoting can make the app read a truncated password, so try a long letters and digits password. Some frameworks, Laravel among them, also cache configuration, so clear that cache after any change.
What should you check when you see "Error establishing a database connection"?
WordPress shows this message whenever it cannot talk to the database. It is generic; behind it may be wrong details, a stopped database service or a damaged table. So the fastest approach is to rule things out one by one:
- Details: compare DB_NAME, DB_USER and DB_PASSWORD with the full prefixed names.
- Host: should DB_HOST be localhost, or a separate address from your provider?
- Service: does phpMyAdmin open? If not, the database service may be down, so contact your host.
- Tables: if phpMyAdmin opens but the site does not, run Check Database to look for damaged tables.
- After a migration: confirm the data actually imported and the table prefix matches the config file.
Search engines see this error too. If a site stays down for long, crawlers cannot reach your pages and rankings can suffer. After the fix, check crawl errors in Search Console, a step we include in our SEO consulting work.
Does the MariaDB vs MySQL difference matter here?
Many cPanel servers run MariaDB rather than MySQL, yet the panel still labels the screens MySQL. For everyday tasks such as creating databases and users, you will not notice a difference. As the table above shows, though, the username length limit does depend on the engine.
The real difference shows up in app compatibility. Some software requires a specific MySQL version or feature. According to cPanel, changing the server's MySQL or MariaDB version is a job for the system administrator; as an account owner, you cannot do it from the panel. We compare the two engines in detail in MariaDB vs MySQL: differences and which to choose.
When should you leave this to your hosting provider?
Setting up a database for a single WordPress site is a task anyone comfortable with the panel can handle. Even so, in some situations a support ticket is faster and safer than doing it yourself:
- The database service does not respond, or phpMyAdmin will not open.
- You need to move a database that exceeds the import limit.
- The server's MySQL or MariaDB version has to change.
- Remote connections need a firewall port opened.
- Repair Database failed and you cannot find a recent clean backup.
If the issue sits in the app itself, for example the schema of a custom system or an online store migration, you need developers rather than hosting support. When a site changes hands, write the database, users and backup routine into the handover notes, so whoever takes over knows where everything lives. Our web design service treats this as part of a proper launch.
What should you verify after setup?
A five minute check right after setup prevents problems months later. Go through this list:
- Does the app run and write to the database? In WordPress, save a draft to test.
- Does the user hold only the privileges it needs?
- Are there unnecessary or wildcard entries left in Remote Database Access?
- Are the database name, username and password saved in a secure password manager?
- Have you taken a first backup and copied it off the server?
- Have you made sure the config file is not in a public folder or repository?
Security also lives in the application layer. Tight database privileges reduce the impact of attacks such as SQL injection, but they do not stop them alone. For the wider picture, see our OWASP Top 10 guide. Put simply, a well configured MySQL database is the foundation of a secure site, not the whole building.



