Features

Everything included. Not upsold.

Every tool below is in every tier, including the free one. What the tier changes is how many websites a server may host — never which features you get. Each account is isolated as its own Linux user, with its own PHP.

For the person who owns a website

The everyday panel

Ten groups of tools, reachable from one dashboard and searchable by name. The panel speaks ten languages — English, Indonesian, Chinese, Spanish, French, German, Japanese, Russian, Arabic and Hindi, with a right-to-left layout for Arabic. Light and dark themes.

Files

A full file manager with a folder tree, uploads, in-browser editing, compress and extract — and a trash bin, so a wrong click is recoverable. Bulk copy, move and delete. Or mount the account as a network drive over WebDAV (Web Disk).

SFTP and FTP

Per-account file access, chrooted to the account's own files, with no shell. Add your own SSH keys, or download a ready-made FileZilla profile. Create several FTP logins for one account, or open an anonymous read-only area for public downloads.

Backups and restore

Scheduled full-account backups with retention, plus off-server copies to S3-compatible storage. Restore everything, or pick out single files, one database, mail or cron.

Email

Mailboxes with quotas, forwarders, autoresponders, Sieve filters and a catch-all. Import a whole list of addresses at once, preview first. Spam is scored and tagged, never rejected outright. Encrypt incoming mail with GPG, screen unknown senders with BoxTrapper, run mailing lists, and sync calendars and contacts to your devices over CalDAV and CardDAV with your mailbox password.

Domains and DNS

Addon domains, subdomains, aliases and 301/302 redirects. A full zone editor (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA), one-click presets for Google Workspace, Microsoft 365 and Zoho, DNSSEC with the DS record to hand your registrar, dynamic DNS, and dual-stack IPv6 with AAAA records seeded for you.

Databases

MySQL and MariaDB, PostgreSQL, and phpMyAdmin behind a per-account sign-on. One database user can hold several databases. Imports stream straight into the server, so there is no upload ceiling to work around.

Security

HTTPS that issues and renews itself, or upload your own certificate. Two-factor sign-in, password-protected folders, an IP block list, hotlink protection, and an on-demand virus scan that reports rather than deletes. Generate a GPG key pair for encryption without the command line. A security scan of your own site flags risky file permissions, exposed backups and stray uploads, with a fix for each.

Apps and runtimes

44 one-click applications, each installed as the account into its own database: WordPress, Joomla, Drupal, Grav and Concrete CMS; shops like OpenCart, PrestaShop and AbanteCart; forums (phpBB, SMF, MyBB), wikis (MediaWiki, DokuWiki), Nextcloud, Matomo, SuiteCRM, Invoice Ninja, LimeSurvey and more. Node, Python and Ruby apps run as managed services behind your domain, Perl modules install into your own home, and a Laravel or Symfony site publishes from its own public/ folder so the source and its .env stay above the web root.

Metrics and control

Visitor statistics from your own access log, live access and error logs, real disk and bandwidth figures, cron jobs, custom error pages with a preview, and PHP version, settings and extensions for your site alone.

Developer tools

A terminal in the browser that opens a shell as your own account — never root — over an isolated service. Connect a Git repository and redeploy on demand. A WordPress toolkit that finds your installs, flags core, plugin and theme updates, and applies them in one click.

Publishing from a folder other than public_html One database user, several databases

The migration blocker, solved

Your .htaccess works exactly as it did

This is the usual reason a site cannot leave a traditional host. A rules file that is quietly ignored is worse than one that errors: the plugin says "saved" and nothing happens.

Decided per site, not per server

A site that needs Apache rules gets a real Apache behind nginx. A site that never touches .htaccess keeps the faster single hop — and on a server where nobody needs it, no second web server runs at all.

Switched on for you at import

If an imported account carries directives that cannot be translated, the account is created in Apache mode straight away. Nobody has to know what "Apache mode" means for their site to work.

Isolation is unchanged

Apache talks to that account's own PHP-FPM socket, so PHP still runs as the account's Linux user. HTTPS still terminates at nginx, so certificates and renewals are untouched.

Or translate instead

Prefer to stay on the single hop? The panel converts common directives to nginx rules and tells you, line by line, what it could not reproduce — rather than dropping them in silence.

Or run OpenLiteSpeed

Prefer LiteSpeed? OpenLiteSpeed is supported as an opt-in, server-wide web server. Accounts keep their own PHP-FPM and the same isolation, and .htaccess rewrite rules are honoured natively.

The two modes in detail, and what switching costs

For the person who runs the server

Run a hosting business from the dashboard

Everything an operator needs is in the panel, not in a config file over SSH.

Accounts and plans

Create, suspend and terminate accounts, singly or in bulk. Plans carry disk, bandwidth, domain and database limits, plus CPU and memory caps and PHP ceilings. Disk quotas are enforced by the kernel, not by a reminder. Each account's CPU, memory, disk and bandwidth usage is plotted as graphs over time, so you can see who is growing before a limit is hit.

Choose what each plan shows

A per-plan feature list decides which tools an account can see and use. Sell a mail-only plan, or a plan without databases, without touching any account.

Resellers

Give a reseller an allocation, the set of plans they may sell, and only the privileges you choose — create, suspend, terminate, brand. Overselling is a switch, not an accident. A reseller can own a website of their own and get one merged panel for both jobs.

White-label

A reseller's customers sign in at panel.theirdomain.com over HTTPS, see the reseller's name, logo and colour, and get DNS from the reseller's own nameservers. The panel writes the zones, checks the delegation against public DNS, and tells them the exact glue records to add.

Sell hosting

A signup page on your own server, branded, with your plans and prices. Enter payment credentials from the dashboard — they are written to a root-owned file, never to the database and never back to the browser.

Billing and support desk

NimboBilling runs inside the panel — recurring subscriptions, branded invoices you can print to PDF, coupons and multi-country tax, account credit and proration, dunning, fraud screening, an affiliate programme and a help desk with a knowledge base and departments. PayPal, Stripe and Xendit; enable all three or just one. Included with every paid tier.

Server security

A scored security review with fixes, brute-force protection with a block list and an attempt log, two-factor sign-in, and named API tokens you can revoke.

Mail operations

Watch the Postfix queue and flush or clear it. Check whether your server's address is on a blocklist and send a test message. Configure a relay from the panel if your provider filters outbound mail — the panel measures that rather than assuming it.

Server health

Live service status for nginx, PHP-FPM, MariaDB, BIND, Postfix, Dovecot and OpenDKIM, with start, stop and restart. A setup checklist that resolves your panel, nameserver and mail records and tells you the exact record to add.

Updates and licensing

Releases are signed, and so is the installer. Update from the dashboard or leave it to the daily check. Apply or change a license key in the panel.

Grow past one server

Register your other Nimbopanel servers and watch their health from one panel. Run a second nameserver on another server so your zones keep answering if the primary goes down — the zones replicate to it automatically.

How NimboBilling handles the money side

Three tiers, one product

Admin · Reseller · Customer

A real multi-tenant model: admins run the server, resellers run their own branded slice, customers manage their own accounts — each isolated from the others.

Admin

The whole server: accounts, plans, resellers, services, backups, security, mail, billing and system health.

Reseller

Their own customers, inside an allocation, under their own brand — and their own website in the same panel if they want one.

Customer

One account, and only that account: files, domains, email, databases, apps, SSL, cron and metrics.

How it is built

The parts that decide whether you sleep well

One Linux user per account

Every account runs as its own user, with its own PHP-FPM pool and its own open_basedir — the same boundary on every supported system. On the RHEL family an account's ~/.ssh is pinned so that even a compromised PHP script cannot write itself a key, and that is tested in both directions on a real server.

The panel is not root

The web interface and API run unprivileged. Anything that needs root goes through a small helper with a fixed vocabulary of 196 named operations — never a shell command assembled from input.

A desired-state engine

You describe the account you want; a reconciler makes the server match, and keeps it matching. Repeatable, and self-healing after a restart.

Signed, verified releases

Updates and the install script are both checked against a signature before anything runs as root. HTTPS proves who served it; the signature proves it is ours.

No fine print

What to know before you install

Two things are worth saying plainly, because finding them out afterwards is the expensive way.

Supported systems

Ubuntu 22.04, 24.04 and 26.04, Debian 12, AlmaLinux 8/9/10, Rocky Linux 8/9/10 and CloudLinux 8/9 — twelve OS releases across five distributions, installed and tested end to end on real servers you control. phpMyAdmin and Roundcube webmail are installed for you on Debian and Ubuntu; on the RHEL family they are not, and you manage databases and mailboxes from the panel instead.

External integrations stay off until you switch them on

Stripe, a domain registrar, fraud screening and Cloudflare each need your own account, and every one of them ships disabled. Nothing reaches an outside service until you enter its credentials — out of the box the panel runs entirely on its own.

FAQ

Feature questions, answered

Does Nimbopanel include a file manager?

Yes. Every account has a full file manager with a folder tree, uploads, in-browser editing, compression and a trash bin for wrong clicks. You can also connect over SFTP or FTP — chrooted to the account, no shell — or mount the account as a network drive over WebDAV.

Which databases does Nimbopanel support?

MySQL and MariaDB and PostgreSQL, with phpMyAdmin behind a per-account sign-on. One database user can hold several databases, remote access is available, and imports stream straight into the server, so there is no upload size ceiling to work around.

Can I run Node.js, Python or Ruby apps?

Yes. Node, Python and Ruby apps run as managed services behind your own domain, alongside PHP 5.6 to 8.5 chosen per site. One-click WordPress, Joomla and Drupal, a WordPress toolkit, Git deploys and Perl modules are included on every tier.

What email features are built in?

Mailboxes with quotas, forwarders, autoresponders, Sieve filters and a catch-all, plus webmail. Mail is authenticated with SPF, DKIM and DMARC set up for you, spam is scored rather than rejected, and you can sync calendars and contacts over CalDAV and CardDAV.

Does Nimbopanel do automatic backups?

Yes. Schedule full-account backups with retention and off-server copies to S3-compatible storage. Restore everything at once or pick out single files, one database, mail or cron — and a trash bin recovers the everyday deletion without a full restore.

What security tools are included?

HTTPS that issues and renews itself, two-factor sign-in, brute-force protection, a web application firewall, password-protected folders, IP and hotlink blocking, an on-demand virus scan, and a scored security review of your own site — every one of them on every tier.

See it on your own server

Start free with one website, or bring an account across and run it on hardware you control.