Web

What Is CyberPanel and How Do You Install It on a VPS?

Talha Aslan 18 min read 1 views

What is CyberPanel and what does it do?

CyberPanel is a free, open source hosting control panel that runs on top of the OpenLiteSpeed web server. It lets you manage websites, email, DNS, FTP, SSL certificates and WordPress installs on your own VPS from a browser. As a result, you can host several sites from one interface without living in the command line.

In this guide we cover what CyberPanel offers, what it needs and how to install it with the official installer, step by step. We are Talha Aslan and team, a digital marketing and web design studio, not a hosting company. Therefore we base every technical detail on CyberPanel's official documentation, LiteSpeed's product pages and public security records.

We do not quote version numbers here, because the panel changes often and so does the list of supported systems. Check the current list on the official page right before you install. In addition, each section ends with an honest answer to one question: should you really do this yourself?

Which services does CyberPanel bring into one panel?

CyberPanel aims to put the jobs you repeat on a web server into a single dashboard. When you pick the full service option, the official installer also sets up PowerDNS, Postfix and Pure-FTPd. So the panel works less like a web server add-on and more like a small hosting stack.

  • Websites: add domains and subdomains, pick a PHP version and manage a user per site.
  • SSL: issue and renew free Let's Encrypt certificates for each site.
  • Email: Postfix mailboxes, forwarders and webmail access.
  • DNS: run your own nameservers and zone records with PowerDNS.
  • FTP: per site FTP accounts through Pure-FTPd.
  • WordPress: one click installs plus page caching through the LiteSpeed Cache plugin.
  • Databases and backups: MySQL or MariaDB databases, phpMyAdmin and backup screens.

However, every component brings upkeep. For example, once you turn on the mail server, deliverability, blocklists and PTR records become your job. That said, switching off services you do not need during setup is usually the safer start.

What is OpenLiteSpeed, and why does CyberPanel ship with it?

OpenLiteSpeed is the open source web server from LiteSpeed Technologies. It uses an event driven design and runs PHP through its own LSAPI interface. CyberPanel grew up as the management layer for this server. In other words, the panel writes OpenLiteSpeed's virtual host settings for you.

The best known benefit of the pair shows up in WordPress. The LiteSpeed Cache plugin talks straight to the server level page cache. So you get fast responses without adding another caching layer. On the other hand, that gain depends on sane settings. Heavy plugins and slow database queries will not improve just because you swapped the web server.

We compared OpenLiteSpeed and Nginx in a separate article. If you want to know which server fits your project, read our guide on OpenLiteSpeed vs Nginx differences. Here we only cover the parts that matter for CyberPanel.

In short, choosing CyberPanel also means choosing OpenLiteSpeed as your web server. That decision affects many details, from .htaccess behavior to your caching plugin.

How does OpenLiteSpeed differ from LiteSpeed Enterprise?

The CyberPanel installer offers two web servers: free OpenLiteSpeed and licensed LiteSpeed Enterprise. LiteSpeed's official editions comparison page lists the key differences clearly.

FeatureOpenLiteSpeedLiteSpeed Enterprise
LicenseFree, open sourceNeeds a paid license key
.htaccessSupports rewrite rules; a new .htaccess file needs a restartDetects changes on its own and reads most Apache directives
Apache compatibilityNot a drop in Apache replacementDrop in Apache replacement
Control panelsPanels that support OpenLiteSpeed, such as CyberPanelPanels that support Apache, such as cPanel, Plesk and DirectAdmin
WordPress brute force protectionNo built in protectionBuilt in protection
Shared featuresLSCache engine, HTTP/3, unlimited virtual hosts, GZIP and Brotli compression

In practice, the .htaccess behavior is what you will notice most. For example, when a plugin edits the .htaccess file, OpenLiteSpeed does not pick up a new file right away. As a result, those rules may stay inactive until a restart. If an older app relies on Apache specific directives, test that gap before you install anything.

What are the CyberPanel system requirements?

The official CyberPanel install guide asks for at least 1024 MB of RAM and 10 GB of disk space. It also expects a fresh operating system. If Apache, Nginx or another panel already runs on the server, CyberPanel will clash with it.

The guide names Ubuntu long term support releases, AlmaLinux and CloudLinux as supported distributions. However, that list changes over time, and different pages of the docs sometimes show different releases. So check the current list on the official page right before you start.

Treat those values as a floor. As a starting range based on field experience, not a guarantee, plan for more memory if one server will run email, DNS and several WordPress sites. Your real needs depend on traffic, plugin count and database load.

When you pick a VPS, the virtualization type, disk type and backup options matter too. We explain these in our guide to VPS vs cloud server vs VDS. For the wider decision, our article on how to choose web hosting is a good place to start.

How should you prepare the server before installing?

A few prep steps before you run the installer prevent most later headaches. Above all, sorting out the domain and DNS first makes the SSL and email steps much easier.

  1. Take a snapshot from your provider's dashboard, so you can return to a clean state if the install goes wrong.
  2. Connect over SSH with a key, and plan to turn off password based root logins.
  3. Give the server a hostname, for example panel.example.com.
  4. Create an A record for that name in DNS. We use 203.0.113.10 as the example IP.
  5. If you plan to send email, ask your provider to set the reverse DNS (PTR) record to the same hostname.
  6. Update system packages with your distribution's own package manager, then reboot.

You can check whether the record has propagated with our DNS lookup tool. We cover how PTR records affect inbox placement in what is a PTR record.

Also find out whether your provider offers a network level firewall. That way you can restrict the panel port before traffic even reaches the operating system.

How do you install CyberPanel? The official script in two steps

The official docs show the install as a one line command that downloads the script and pipes it straight into a shell. We suggest splitting it into two steps instead. First you download the script to a file. Then you read it. Finally you run it. That way you see which file will run with root rights.

Step 1: download and review the script.

curl -fsSL -o cyberpanel-install.sh https://cyberpanel.net/install.sh
less cyberpanel-install.sh

Look for unexpected redirects, and check that it pulls files from official domains. The script can be long. Still, even reading the first sections gives you a sense of what it does.

Step 2: run it from a root shell.

sudo su -
sh /home/youruser/cyberpanel-install.sh

The path here is only an example, so use the folder where you saved the file. For non root users, the official docs also run the command through sudo su in a root shell. According to the docs, the install takes roughly 5 to 10 minutes, depending on server speed.

If your SSH session drops during the install, the process can stop halfway. So for long jobs, a session manager such as screen or tmux is a good habit.

Which questions does the installer ask?

Once the script starts, it asks a series of questions. Here are the options and defaults that the official docs list.

  1. Web server: OpenLiteSpeed (free) or LiteSpeed Enterprise (needs a license key).
  2. Full service: installs PowerDNS, Postfix and Pure-FTPd. The default answer is yes.
  3. Remote MySQL: keeps the database on another server. The default answer is no.
  4. CyberPanel version: the latest release by default.
  5. Admin password: the docs themselves advise against the default. Always set a strong, unique password.
  6. Memcached and Redis: caching components. The default answer is yes.
  7. Watchdog: a component that watches services. The default answer is yes.

The admin password step matters most. A panel with the default password is at risk the moment it faces the internet. In addition, answering no to full service cuts the number of open ports and parts to patch, if you will not host email or DNS.

When the install finishes, you see a summary. It shows the panel URL, the admin username and a random password for the OpenLiteSpeed WebAdmin console. Store those details in a password manager right away.

Which ports does CyberPanel need open?

The official docs list the ports your provider's network firewall should allow. However, that list assumes you installed every service. You do not need to open a port for a service you do not use.

ServicePort and protocolOur advice
CyberPanel admin panelTCP 8090Open only to your own IP or use an SSH tunnel
Web (HTTP and HTTPS)TCP 80, TCP 443, UDP 443Open to everyone
FTPTCP 21 and passive range 40110-40210Close if you can and use SFTP
EmailTCP 25, 587, 465, 110, 143, 993Only if you host email
DNSTCP 53, UDP 53Only if you run your own nameservers
OpenLiteSpeed WebAdminTCP 7080Keep closed to the outside

Port 7080 does not appear in the official port list, yet the install summary shows WebAdmin console details. When you need that console, reach it through an SSH tunnel as well. Put simply, admin interfaces should never be open to the whole internet.

What should you set up after the first login?

After the install, open the panel in a browser at an address like https://203.0.113.10:8090, using your own server IP. Per the official docs, the username is admin and the password is the one you chose during setup. On first visit, the browser may warn you about a self signed certificate.

  1. Change the admin password, and turn on two factor authentication if your version offers it.
  2. Issue an SSL certificate for the panel hostname, so the browser warning goes away.
  3. Open the panel port only to your own IP, or close it fully and use an SSH tunnel.
  4. Stop services you do not use (FTP, email, DNS) and close their ports.
  5. Set up automatic backups to a target outside the server.
  6. Turn off password logins for SSH and allow key based logins only.

These steps take a few minutes. Still, they remove most of the risk in the panel's first week. Do not postpone step 3 in particular, because the security incident we describe below hit exactly the panels that faced the internet.

How do you add your first website and SSL certificate?

To add a site in CyberPanel, you first define a package with resource limits. Then you create the website from the Websites section. On the same form you set the domain, the owner, the PHP version and, if you like, SSL. Menu names can change between releases, so look for the closest match on your screen.

For the certificate to issue cleanly, the domain's A record must point to your server IP. Otherwise the Let's Encrypt check fails. So a quick DNS check before you add the site saves time.

Once the certificate is live, confirm the chain and expiry date with our SSL checker. We explain why SSL matters and how HTTPS works in what is an SSL certificate.

A separate system user per site also makes it harder for one hacked site to reach the others. That said, this isolation does not guarantee safety. You still need to review file permissions and PHP settings.

Should you host email and DNS on CyberPanel?

You can, but it is not the right call for every project. CyberPanel can set up email through Postfix and DNS through PowerDNS. Yet running your own mail server brings ongoing work, such as deliverability checks and blocklist monitoring.

Business email delivery depends on SPF, DKIM, DMARC and PTR records all working together. For example, if one hacked site starts sending spam, every message from that IP can suffer. Therefore we usually advise small businesses to keep email on a separate, specialized service.

DNS has a similar trade off. Running your own nameservers means the whole domain goes dark when the server goes down. On the other hand, if you use your registrar's nameservers or a managed DNS service, DNS stays up even when the panel has trouble.

In short, using CyberPanel for websites only, and leaving email and DNS to specialists, carries less risk in most cases. That choice starts with your answer to the full service question in the installer.

How do you install and speed up WordPress with CyberPanel?

CyberPanel offers a dedicated WordPress management screen. From there you can install a site in one step, turn on the LiteSpeed Cache plugin and handle tasks such as a staging copy. So you skip the manual download and database setup.

The main speed gain comes from the server level page cache. The LiteSpeed Cache plugin talks to OpenLiteSpeed directly, so you do not need a second caching plugin. In fact, running two caching plugins at once causes conflicts, so remove the old one.

  • After you turn on caching, check that logged in users and cart pages stay out of the cache.
  • Turn on image optimization and CSS combining one setting at a time, and test the site after each change.
  • If you chose Redis or Memcached in the installer, consider object caching.

A plugin cannot make up for a bloated theme or needless plugins. In our web design projects, we first trim the page structure and the plugin list. Then we build the server cache on top of that.

CyberPanel security: what can we learn from the critical flaw?

CyberPanel has a serious security incident in its history. The CVE-2024-51567 record, published in October 2024, describes how attackers could bypass authentication in a database function and run remote commands. It also notes that the PSAUX ransomware campaign exploited it in the wild that same month.

The record lists a CVSS 3.1 score of 10.0, which means critical. In addition, the US agency CISA added the flaw to its Known Exploited Vulnerabilities catalog in November 2024. That tells you the flaw was not theoretical; attackers used it for real.

In its official announcement, the CyberPanel team said it had patched the issue and asked users to update their panels. The post also told users whose SSH access had been blocked to contact their hosting provider for the update.

The lesson is simple. Free and open source does not mean secure. Also, a critical flaw splits servers into two groups: those that patch fast and those that wait. So if you run CyberPanel, following its security news is part of your job.

Why is it risky to expose the admin port?

A flaw that works before login does not care how strong your password is. If an attacker can reach the login page, they can try it. Therefore leaving port 8090 open to the whole internet makes your server a direct target for every flaw found in the future.

The simplest fix is to reach the panel through an SSH tunnel. Then you can close port 8090 to the outside completely:

ssh -L 8090:127.0.0.1:8090 youruser@203.0.113.10

While this command runs, open https://localhost:8090 in your browser, and the traffic flows through the encrypted SSH link. Alternatively, open port 8090 only to your fixed office IP in your provider's network firewall.

None of these layers is enough alone. Together, however, they shrink your attack surface a lot.

How do you keep CyberPanel updated and backed up?

The official install guide shows the cyberpanel upgrade command in the install summary for moving to the latest release. In addition, the CyberPanel community publishes an official upgrade guide. Always take a server snapshot before you upgrade, so you can roll back within minutes if something breaks.

Updating the panel alone is not enough. Operating system packages, PHP versions, WordPress core and plugins each need their own updates. For example, even with a current panel, an old plugin can be the easiest way into a site.

  1. Follow CyberPanel's official blog and changelog for security news.
  2. Take a snapshot before each update, then check each site afterwards.
  3. Send backups to a storage target outside the server.
  4. At least once a month, restore a backup in a test setup to prove it works.

We cover backup planning in detail in our website backup strategy guide. In short, a backup that sits on the same server will not save you when that server gets hacked or its disk fails.

What errors come up most often during a CyberPanel install?

Most install problems come from skipped prep, not from the panel itself. The topics that come up most in the official community forum also tend to point at the same few causes. We suggest scanning this list once before you install.

  • A system that is not fresh: a server with Apache or another panel already on it runs into port and package clashes.
  • A blocked panel port: if the provider's network firewall blocks 8090, the login page will not load. Try an SSH tunnel first.
  • A wrong DNS record: if the A record points to another IP, the SSL certificate will fail.
  • A dropped SSH session: if the install stops halfway, rolling back to the snapshot and starting again is often fastest.
  • Too little memory: on servers below the minimum, database or build steps can fail.

With these errors, a reinstall on a clean system usually takes less time than repairing the panel by hand. Still, note the error message. Searching for it in the official forum often turns up a fix from someone who hit it before you.

Where does CyberPanel stand against cPanel, Plesk and aaPanel?

The right control panel depends on budget, team skills and app type. The table below is not a ranking. Instead, it sums up the axes to weigh when you decide. Prices and license terms change often, so check each vendor's official site for current details.

CriterionCyberPanelcPanel and WHMPleskaaPanel
LicenseFree, open sourceCommercial licenseCommercial licenseHas a free edition
Web serverOpenLiteSpeed or LiteSpeed EnterpriseApache, optional LiteSpeedApache and Nginx, optional LiteSpeedChoice of Nginx, Apache or OpenLiteSpeed
Typical userDevelopers and small agencies running their own VPSShared hosting companies and resellersAgencies and mixed Windows and Linux setupsVPS users who want a simple interface
.htaccess supportLimited, needs a restartFull (Apache)Full when using ApacheDepends on the chosen server
SupportCommunity plus paid support optionsCommercial supportCommercial supportMostly community

CyberPanel's strength is that it pairs LiteSpeed caching with WordPress at no license cost. On the other hand, cPanel and Plesk stand out with long running commercial support and wide plugin ecosystems. For hands on cPanel tasks, see our guide on how to change the PHP version in cPanel.

When should you not use CyberPanel?

CyberPanel is not the right tool for every project. If one of the points below applies to you, consider another option, or leave server management to your hosting provider.

  • Nobody on your team will patch the server and follow security news.
  • Your app leans heavily on Apache specific .htaccess directives.
  • You run a high revenue online store and cannot accept any downtime.
  • Your business needs contractual commercial support and a service level agreement.
  • You already have a managed panel on shared hosting and no concrete reason to move to a VPS.

Also, if you only run one static site or a different runtime such as Node.js, a full hosting panel adds needless complexity. In that case, a plain web server config or a lean deploy setup is often simpler. Our Node.js deployment guide shows that path.

Should you run your own CyberPanel server or leave it to a host?

The honest answer depends on your team. If someone is comfortable at the command line, patches on schedule and tests backup restores, CyberPanel is a good tool. Then you can manage several sites flexibly without license fees.

On the other hand, server management is not a set and forget job. When a critical flaw goes public, you may need to patch within hours. If you cannot keep that pace, managed hosting or a managed VPS is cheaper and safer in the long run.

On website and online store projects, we usually ask clients one question: who will look at the server when it breaks at midnight? If you cannot name a person, leaving the infrastructure to a specialist provider is the better call. Then you can spend your energy on content, SEO and sales.

A short CyberPanel decision checklist

To wrap up this guide, we gathered the questions to ask yourself before you install into one list. If you can say yes to each, CyberPanel is a reasonable choice for you.

  • Do you have a fresh install of a distribution on the official list?
  • Will you download and review the script before you run it?
  • Can you limit the panel port to your own IP or an SSH tunnel?
  • Is someone going to follow updates and security news on a schedule?
  • Do your backups live off the server, with a tested restore?

If even one answer is no, fix that gap first. In the end, CyberPanel is a strong, free tool, yet its security depends on the discipline of whoever runs it.

Frequently Asked Questions

Is CyberPanel completely free?
Yes, CyberPanel itself is free and open source. You use it with the OpenLiteSpeed web server at no license cost. However, if you pick LiteSpeed Enterprise during setup, that server needs a separate license key. Server rental, off site backup storage and optional paid support also remain costs that sit outside the panel itself.
How much RAM does CyberPanel need?
The official install guide asks for at least 1024 MB of RAM and 10 GB of disk space. Treat those values as a floor. If one server will run email, DNS and several WordPress sites, plan for more memory. Your real needs depend on traffic, plugin count and database load, so monitor usage before you decide.
Can I install CyberPanel on an existing cPanel server?
No, you should not install CyberPanel on a system that already runs another panel or web server. The official guide expects a fresh operating system. If you want to move existing sites, set up a new VPS with CyberPanel, migrate the sites from backups and then switch the DNS records. That route is far safer.
What is the CyberPanel login URL and username?
By default the panel runs on port 8090 and opens over HTTPS at your server IP. Per the official docs, the username is admin and the password is the one you set during install. For safety, do not leave this port open to everyone; allow only your own IP or connect through an SSH tunnel to localhost.
Is CyberPanel secure?
It can be a reasonable choice when you configure it well and keep it updated, but it has had a critical flaw. CVE-2024-51567, made public in October 2024, saw real attacks. So keep the panel current, close the admin port to the outside, use a firewall and store your backups off the server.
Does OpenLiteSpeed read .htaccess files?
Partly. According to LiteSpeed's official comparison, OpenLiteSpeed supports rewrite rules but not every Apache directive. It also needs a restart to load a new .htaccess file. LiteSpeed Enterprise, by contrast, detects changes on its own and reads most Apache directives. Test your rules before you migrate any site.
  • cyberpanel
  • openlitespeed
  • hosting control panel
  • vps management
  • litespeed enterprise
  • server security
  • wordpress hosting
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.