[1.8.0] - 2026-08-26
Release Overview
This release reorganises the admin panel around subject areas and adds a single Logs page, panel-managed cPanel migrations, Node.js, Python and Ruby applications with a runtime manager behind them, PostgreSQL and MySQL Governor as optional modules, off-site server configuration backups with a one-command disaster restore, MailChannels inbound filtering, a domain ownership guard with an admin approval queue, and an expanded client REST API.
Admin panel
- A reorganised admin area - the sidebar goes from a long flat list to eleven task-oriented groups, related screens are gathered behind one destination with tabs, and every configuration screen moves into a single Settings area. Old addresses answer with a permanent redirect in one hop, so bookmarks and scripted URLs still land in the right place. The appendix lists where each screen went.
- Logs - every log this server writes on one page with a tab per source: the Apache, LiteSpeed and OpenLiteSpeed access and error logs, Postfix and Dovecot, Rspamd, Roundcube, ModSecurity, Fail2Ban, FTP and Linux security, the panel's own error log, the agents, and the execution log.
- Health - services, database health and metrics, the Fail2Ban status and the Apache server status become scopes of one page. The database scope reports a live query rate and says when the query cache is switched off.
- Email dashboard - the Web Server and Email areas each gain a dashboard of their own.
- SSL Issuance History - every certificate issuance is recorded, including the ones a DNS preflight declined.
- Installation finishes in the background - the installer sets up one PHP version and hands you a usable panel; the remaining PHP versions, SecureBox and SymLock install afterwards, one at a time, with progress on the dashboard and every step recorded in the execution log. A panel restart in the middle loses nothing.
- Failures that explain themselves - a failed action anywhere in the panel says why it failed and what to do next, under one correlation id you can quote, and an action that half succeeded is reported as such instead of as a flat success. A module operation you started re-attaches after a page reload, and a stuck one no longer holds the page for everyone else.
- Bulk actions - hosting account lists gain bulk suspend, unsuspend, change plan and delete, and domain lists gain bulk delete and bulk SSL issuance. A bulk delete asks you to type a confirmation first, and the result separates completed, completed with warnings, failed and skipped, each with its next step. A batch in which nothing ran says so instead of reporting success.
Migration
- Panel-managed cPanel migration - a new Migration > External Migrations wizard moves accounts off a cPanel server without leaving the panel. You give the source host, approve its SSH host key fingerprint, and bootstrap the run either by pasting a one-time command on the source or by an upload from this server. The run outlives the browser, so the page can be closed and reopened at any time, and its view carries live status, the preflight, per-account state, the event log and the cleanup state of every credential the run held. You pick the accounts before the run starts, map each source hosting plan to an existing plan or let it be created from the package, and approve the DNS cutover as a separate step. Every decision is recorded with the administrator, IP and timestamp.
bolt-cli external-migration-disableends every active run and releases what it holds, leaving already-imported accounts working.
Applications and runtimes
- Node.js, Python and Ruby applications - clients create an application from a wizard that ships a starter page serving immediately, with the application root taken relative to the domain folder, its own log, restart from the panel, and full coverage in the client REST API. Applications run on Apache and on OpenLiteSpeed, and the panel decides by what is actually serving.
- Runtime Manager - a new admin page under Runtimes lists the runtime versions the repositories offer next to the ones this server has, installs one version or all of them, reports what is running, and says so when the application server is missing. It carries an admin REST API of its own.
- CloudLinux settings - CloudLinux servers gain their own settings section, with Resource Usage, PHP Selector, X-Ray, AccelerateWP and LVE Manager offered to the account through the hosting plan feature. X-Ray and AccelerateWP are panel modules that report their real availability, and
alt-*builds are preferred when no runtime version is chosen.
Databases
- PostgreSQL - install PostgreSQL from the Module Manager beside MariaDB and hand it to accounts through the PostgreSQL Databases feature on the hosting plan feature list. Clients create databases and roles, manage remote access, open Adminer on a PostgreSQL database as one of the account's roles, and reach all of it over the client REST API. PostgreSQL data counts towards the account's disk usage, its databases ride along in account backups and are replayed on a full restore, and the PHP drivers are installed for every PHP family on the server. Existing feature lists pick up the new feature on upgrade.
- MySQL Governor - CloudLinux servers get a Settings > Databases > MySQL Governor page that installs the Governor with the installer output shown as it runs, reports the running state once it is up, and offers removal on its own page with the output streamed live.
Backups and disaster recovery
- Server configuration backup - a new Backups > Server Config surface takes the whole server configuration off-site to a backup destination, on a schedule you set, with its own retention and an optional repository passphrase you keep in your own vault. Export DR keys hands you the bootstrap secrets, asks the acting admin for a fresh second-factor code first, and records every export in the audit log. From those secrets alone
bolt-cli disaster-restorerebuilds a fresh box from the newest off-site snapshot,bolt-cli disaster-reprovisionre-materialises modules, PHP versions and hosting accounts, andbolt-cli restore-all-accountsandbolt-cli restore-all-databasesbring back the account files and their dumps. Every destructive restore asks you to name the machine being overwritten. - Infrastructure database snapshots - local snapshots of the mail and DNS databases are listed on the Server Backup page with Back up now, Restore showing the snapshot age and record counts before you commit, and Delete.
bolt-cli backup-infra-databasesandbolt-cli restore-infra-databasedo the same from the shell, and a snapshot is taken before every panel-driven system update. - Server-wide backup policy - a backup policy with no target is the server-wide default and covers every account that nothing more specific claims, so a newly added hosting plan is never left without backups. Resolution order is account, then reseller, then plan, then the server-wide default. The client restore cooldown, the daily manual-backup cap and the restore concurrency are admin settings under Backups > Limits.
- Restore into the database - clients gain a restore action next to the dump download, with the database's current contents snapshotted first so an accidental import can be undone.
Email
- MailChannels inbound filtering - a new MailChannels tab in Email Settings holds the Inbound API key and its subscription. Clients whose plan includes the feature get a per-domain filtering toggle and one-click sign-in to MailChannels; enabling registers the domain and swaps the MX records only once the filter confirms the delivery route, and disabling restores them first. A domain is filtered by at most one of MailChannels and SpamExperts, the apex MX of a filtered domain stays with the filter against zone edits, imports and DNS templates, and an hourly sync plus a daily verify repair drift and retry unfinished changes.
- Mailbox restrictions - incoming mail, outgoing mail and mailbox login can each be set to allow or suspend on the mailbox create and edit forms, and the server enforces each direction on its own. The Restrictions column names what is suspended, and a sending suspension is listed beside the manual restrictions with its expiry rather than masking them. Existing servers pick up the enforcement on upgrade.
- Plan mailbox quotas - the hosting plan's mailbox quota fields are enforced in the client panel, the admin panel and both REST APIs. A create without a quota takes the plan's default, a quota above the cap is refused with the cap named, and a plan that caps mailboxes does not offer unlimited. Keeping a mailbox's current value always saves, so a mailbox left above the cap by a plan downgrade can still be edited.
- Lowercase mail addresses - mailbox usernames, mailing list names and catch-all targets are stored in lowercase, folded live in the form and again in the service, and duplicate checks ignore case. An upgrade sweeps the mail server and the panel for mixed-case rows already on the server, renames the mail directories with them, and reports both what it repaired and what it could not.
- Panel mail exemption - the panel sends its own notifications and bounces through its own mailbox login, which is exempt from the outbound sending limits, so a busy server cannot silence the channel a mail problem is reported through. The Sending Limits page states the exemption, lists the exempt logins, and raises a banner if the panel's own mail is ever throttled.
- SLA-covered MX set - the SpamExperts Cluster MX hostnames help text names N-able's SLA-covered global set in priority order, warns that the
filterNN.antispamcloud.comrecords shown in the vendor panel sit outside its uptime guarantee, and offers a one-click action that fills the SLA-covered set for you.
Security and access
- Domain ownership guard - a domain being added is checked against the whole platform's namespace rather than an exact name only, so two accounts cannot end up serving overlapping names, while an account's own subdomains are unaffected. A rejected add is recorded on the new Domain Security page, where an admin approves or dismisses it and manages the approved overlaps, with the pending count on the navigation badge. An optional ownership policy asks a domain new to the platform for a DNS TXT record before it is provisioned, shows the exact record to add, and verifies automatically on retry. Overlaps that already exist, and overlaps arriving with a migration, are carried over on upgrade.
- Impersonation sessions - an administrator stays signed in to their own panel across an impersonation, and leaving it, logging out, signing in elsewhere or letting the session expire all end the impersonation and close its entry in the activity log, with the start and its end paired to each other.
API
- Client REST API - the client API gains cron job management that adopts hand-added lines before every write, address and domain forwarders with loop and duplicate rejection, the per-domain PHP directives to read and set, database user grants in the read payload, opt-in database size and mailbox usage, and the account's IP address and home directory on the single-account read. A scoped file manager covers the account home - list, stat, download, upload, write, move, copy, chmod, symlink, archive, extract and delete - paginated and size-capped. WP-CLI runs against a domain document root behind a per-key switch that is off by default, with the commands that escape WordPress refused and every call audited. Single-use, short-lived sign-in URLs can be issued for phpMyAdmin and webmail. Clients can create their own restricted keys.
- API review fixes - hosting plan create and update validate and persist the full field set,
PUT /api/hosting-account/domains/{id}works,php_version_idis accepted on domain create and update and rebuilds the PHP configuration behind it, and admin keys gain DNS record, IP blocker and per-domain SSL certificate routes. A write naming a field the panel does not apply is refused with the reason rather than answered with success. The per-key endpoint allowlist applies to every key type, and API secrets are stored encrypted at rest and displayed exactly once.
Fixes and improvements
- FTP settings invariants - the directives the panel's FTP stack depends on are applied on every write and are no longer offered as editable fields, so saving that page cannot leave a server whose FTP accounts fail to log in, list files or transfer. An upgrade repairs a server whose stored or live configuration disagrees with those invariants, naming what it changed.
- Web stack restarts - web stack services come back on their own after a failure such as an out-of-memory kill, instead of staying down until someone starts them by hand. An upgrade applies the policy to every server already in the field.
- Apache configuration validation - a vhost write is checked against Apache before the reload and rolled back when the check fails, with the offending file and Apache's own message reported.
- SSH access state - the SSH toggle on an account reflects what the server actually has: a failed server-side step leaves the stored value where it was and reports the reason, and an edit that does not carry the toggle leaves SSH access alone.
- Domain rename - renaming a domain carries its document root, PHP-FPM pool, log directories, parked domains and page cache with it, retires the old vhost, and rolls the whole rename back and repairs the server when a step fails. The rename target is refused when any account already holds it, and writes to one domain are serialized while writes to different domains stay parallel.
- Web log permissions - accounts read their real bandwidth and access log figures again: an upgrade repairs the web log ownership and permissions, installs per-account log rotation, and
bolt-cli repair-web-log-permissionsruns the same sweep on demand. OpenLiteSpeed logs are read for bandwidth as well. - JetBackup restores - a restore replays the account's captured DNS zone, so custom TXT, SPF, DKIM, DMARC and SRV records come back with it; the replay is all-or-nothing and refuses before applying anything when the capture holds records it cannot represent. The page, the health check and the log warn when the reseller owner of an account is dropped from JetBackup's own account list.
- MariaDB repository mirrors - provisioning writes several mirror addresses for the MariaDB repository, so an installation continues when one of them does not answer, and names the cause when none of them does.
- Certificate expiry digests - when more certificates cross a warning threshold in one scan than the number you set (5 by default), the whole cohort is delivered as a single digest naming every affected domain, instead of one notification per certificate.
- Onboarding and billing - finishing the onboarding wizard registers the server with billing once provisioning has succeeded and the credentials are already on screen, so a slow or unreachable billing system cannot cost you passwords that exist nowhere else. A paid license is left alone rather than signed up for a trial, and a trial is confirmed by a link in the confirmation mail, with the License page polling for the result and offering to resend it.
[1.7.0] - 2026-08-10
Release Overview
This release adds per-account backups with scheduled snapshots and self-restore, two-factor authentication and passkeys for every role, a panel-wide audit log, outbound mail sending limits with automatic suspension, SpamExperts incoming filtering, CPGuard as a second server security suite, LSPHP on plain Apache, and configurable remote IP handling for servers behind a CDN.
Backups
- Per-account backups - a new Backups section where you register a storage destination, attach a backup policy to a hosting plan, a reseller or a single account, and follow every account's backup state, size, last run and error from one dashboard. Backups run on the server without holding up the panel, older ones are removed on the retention you set, and a failed run raises a notification. The history is on Backup Runs and Restore Jobs.
- Client self-restore - clients get their own Backups page with a snapshot picker, a searchable file browser, restore in place or as a copy that leaves the live files untouched, and a Backup now button with a daily limit. Self-restore is granted per policy, and an account can be opted out of backups entirely.
- Reseller backups - resellers see the same dashboard for the accounts they manage, and can start a backup or a restore for any of them. Every run records who asked for it.
- JetBackup restores - restoring an account that no longer exists in the panel now completes end to end: the system user is adopted and the domain, DNS zone, quota and cron jobs are provisioned around it. Restored sites serve and restored mail is delivered, and the account's cron jobs are reconciled as soon as the restore finishes. The admin JetBackup page reports the licence, version, storage and last-backup figures read from JetBackup itself.
Security and access
- Two-factor authentication - admin, reseller and client accounts can add a second step to their login with an authenticator app or a passkey, with single-use recovery codes for a lost device. Changing the second factor, regenerating recovery codes or removing a passkey asks for a fresh code first, and an admin resetting another account's second factor confirms with their own. The client version is on Password & Security, the reseller version on Security.
- Activity Log - a new Logs → Activity Log page recording who changed what and when across hosting accounts, domains, DNS records, email, databases, FTP accounts, cron jobs, certificates, firewall rules, hosting plans, API keys and the panel's own accounts. Entries open on the previous and the new values, and the list filters by event, object type, actor role, date and impersonated actions only. Resellers get the same page scoped to their own accounts. Passwords, tokens and keys are recorded as changed without keeping the value. Entries are kept for 90 days.
- CPGuard - CPGuard joins Imunify360 in the Module Manager as a server security suite; one of the two is active per server. Follow the status, licence and connection state on the admin page, and hand the client page to accounts through the hosting plan feature. Use CPGuard WAF switches the web application firewall from the shipped rule set to CPGuard's own, and restores the shipped rules when you switch back.
Email
- Outbound sending limits - a new Sending Limits tab in Email Settings with hourly and daily limits per mailbox and per domain, per-plan values and per-sender overrides. The Email → Sending Limits page lists every rejected message with the account, domain and mailbox it came from. With automatic suspension on, a mailbox over its limit loses SMTP login until its rate drops back under the limit and keeps IMAP and webmail meanwhile. Mail sent by site scripts carries the site's own sender address, so it is delivered and counted against the right domain.
- SpamExperts - a new SpamExperts page in Email Settings for the cluster API and the MX hosts. Clients whose plan includes the feature get a per-domain filtering toggle and one-click sign-in to the Spam Panel: enabling registers the domain on the cluster before the MX records are rewritten, and disabling restores them first, so mail keeps flowing either way.
- Outbound SMTP relay - send outgoing mail through an external relay, configured from the panel or the CLI with host, port, credentials and encryption.
- Sender Rewriting Scheme - forwarded mail leaves the server with a rewritten envelope sender, so a forward passes the receiving side's sender checks.
Web server
- LSAPI Engine - install mod_proxy_lsapi from the Module Manager to serve LSPHP on plain Apache, with a pool per account and PHP version carrying the hosting plan's memory, CPU and process limits. LSPHP then appears next to the other PHP providers on the domain, plan and PHP Engine Migration screens.
- Remote IP Handling - servers behind Cloudflare or another CDN can name the header that carries the visitor address and the proxies allowed to set it, from both the Apache and the LiteSpeed settings pages, with a one-click Cloudflare preset. Visitor statistics, access logs, the IP Blocker, login protection and
REMOTE_ADDRthen all read the visitor's own address. The client Access Logs viewer gains a Remote Host column. - OpenLiteSpeed hostname SSL - under OpenLiteSpeed the panel hostname is served by its own virtual host, so hostname certificate issuance and renewal complete, and the server is restarted after a certificate change.
Firewall
- ICMP and IPv6 rules - firewall rules can be created for ICMP and ICMPv6 and for IPv6 addresses, with the port fields hidden where they do not apply and an IP Version badge in the list. The ping rules that used to be fixed become editable system rules. The page warns you when the firewall service is down or the live rule set is empty, and a rule the server refuses reports the reason.
CloudLinux
- IP-based licences - install CloudLinux without an activation key to use an IP-based licence: leaving the key empty selects it, and the panel shows which mode a server was licensed in. The page also names the pre-check checks that failed, shows how long a running job has been going, and lists the CageFS daemons on the Services page.
Monitoring
- Usage history - hosting accounts get Disk Usage History and Bandwidth History charts built from a daily snapshot of disk, database and transfer usage, with a day the panel could not collect drawn as a gap. The reseller dashboard shows real disk and bandwidth totals and trends across its accounts. Retention is configurable in Panel Settings and defaults to 90 days.
- Certificate expiry alerts - the panel warns before a certificate expires, warns again when a renewal fails, and reports a certificate that has expired, over email, webhooks and the admin bell. All three templates are editable under System Notifications.
Fixes and improvements
- Database name casing - a database created with capital letters in its name is addressed under the same name everywhere, so grants, size, delete and backup all act on the database that exists. The client forms fold the name to lowercase while you type.
- SSH access on account edit - saving an account with SSH enabled re-applies its SSH access configuration on the server, and reports a warning naming the reason when the server refuses.
- Failure reasons in notifications - a failed action tells you why it failed in the admin, reseller and client panels, instead of a generic message.
- WordPress uninstall cleanup - a WordPress uninstall reports an error when its database cleanup does not finish and removes the site files last, so a failed uninstall stays visible and a retry completes it.
- Faster panel after upgrade - the panel's framework caches are built into the package, so the first page after an install or an upgrade is served without building them on the server first.
[1.6.0] - 2026-08-04
Release Overview
This release adds OpenLiteSpeed as a third web server, Remote MySQL access for hosting accounts, a webmail.<domain> address for every domain and subdomain, login history and active session management for every role, panel-owned admin credentials, and managed open_basedir paths.
Web server
- OpenLiteSpeed - OpenLiteSpeed joins Apache and LiteSpeed Enterprise as a supported web server. Install it from the Module Manager and manage it from the new OpenLiteSpeed Dashboard, with the WebAdmin console, restart and switch actions, Settings, Error Logs and Access Logs. A switch is reported as successful only once the incoming server has started; otherwise the panel restores the previous one on the ports.
- .htaccess handling - choose
off, restart-on-change or the experimental per-request module mode. A site using a directive module mode does not cover falls back to restart-on-change, is listed with the offending directive, and has its own Retry. - LiteSpeed Cache for admins - per-domain cache settings and purge actions across every account, on both LiteSpeed Enterprise and OpenLiteSpeed. The client page follows the hosting plan's LiteSpeed Cache feature.
- PHP Engine Migration - the REMI and LSPHP migration covers OpenLiteSpeed and lives in whichever LiteSpeed-family navigation group the server has.
- Login Shortcut URLs -
/cpanel,/paneland/webmailare managed from one shared section on the MyApache and LiteSpeed settings pages, and are served the same way on all three web servers.
Databases
- Remote MySQL - an account authorizes external hosts to reach its own databases. Admins get Remote MySQL Settings with a server-wide wildcard policy, off by default, and Remote MySQL Hosts to review and revoke allowed hosts across every account. The page is enabled per hosting plan.
Email
- Webmail subdomain - domains and subdomains are provisioned with
webmail.<domain>serving Roundcube; parked domains are not. The parent domain keeps serving as before, and a hostedwebmail.<domain>of your own takes precedence, which is why itswebmailrecord stays in the parent zone when it is deleted.
Websites
- Managed open_basedir - the SitePad editor path is whitelisted automatically wherever Softaculous is installed, and admins can add extra
open_basedirpaths per account. Entries are validated on save, naming any line that is rejected.
Security and access
- Login history and sessions - every role gets recent login attempts and active sessions with per-session revoke and Log out all other sessions: on the client Password & Security page, the admin Edit Profile page, and the new reseller Security page. Retention is configurable in Panel Settings and defaults to 90 days.
- Panel admin credentials - admin accounts are owned by the panel and have their own passwords, kept separate from the server's system accounts. Existing installs keep their current password; the
rootadmin, whose password mirrored the Linux root account, is asked to set a panel password on its next sign-in. - License enforcement - license validity applies to the client and reseller panels and to the API, where reads keep working and changes are refused. Hosted websites, mail, DNS and webmail are never gated.
- Input validation - Track DNS, Git operations and directory privacy credentials validate their input on submit.
Backups
- JetBackup hooks on upgrade - a host that ran JetBackup before AdminBolt shipped its integration receives the hooks and database configuration on upgrade, and an hourly check reinstalls them if a JetBackup update replaces them.
- Restored cron jobs - cron jobs restored outside the panel are adopted onto the Cron Jobs page within five minutes and keep running.
@rebootlines, environment assignments and malformed schedules are left untouched.
SSL
- Certificate issuance - a domain's web server configuration is brought up to date before validation starts. New
bolt-cli rebuild-apache-vhostsregenerates every non-parked domain, or one with--domain=; run it once after updating.
Fixes and improvements
- Firewall rule source - a rule created with a Source or Destination IP applies to exactly those addresses.
- Managed cron on upgrade - every upgrade reconciles the managed cron entries, including the sweep that issues and renews certificates for hosting domains.
- Webmail after a panel upgrade - webmail keeps working after an upgrade that does not include Roundcube itself, and the shipped fail2ban jails come back up.
- Module Manager - the web server modules are reconciled with what is installed on disk, so a package removed outside the panel can be installed again.
[1.5.0] - 2026-07-29
Release Overview
This release introduces mail queue and delivery visibility, BIND zone import and export, Cloudflare zone management, per-domain AI bot blocking, JetBackup Linux integration, configurable landing pages, and security, firewall and filesystem improvements.
Email
- Mail Queue - a new admin page with active, deferred and hold totals and sender, recipient and domain filters. Preview a message, retry or delete it, delete everything matching the current filters, or flush the queue. The Email dashboard shows a backlog indicator when the queue grows.
- Mail Delivery - a new client page listing recent delivered, deferred and bounced messages for the account's own domains, with the deferral or bounce reason and the original recipient when an alias expanded.
- Outbound SMTP over IPv6 - Default Email Settings gain an Outbound mail (SMTP) over IPv6 select (
auto,disabled,enabled). The existing toggle is relabelled Enable IPv6 (IMAP/POP3) so each control states exactly what it covers.
DNS
- Zone export and import - export a zone as a BIND zone file and import one back, in both the Zone Editor and Global DNS Zones. The import previews the result and reports every line it could not apply. TTLs are clamped to the panel's
60-86400range, and the SOA record stays panel-managed. - Configurable DMARC - DNS settings gain a DMARC Policy and Report Address, used by both mail DNS provisioning and the DNS record templates. A
_dmarcrecord you created by hand is never overwritten. - Cloudflare - add a domain to your Cloudflare account, see the assigned nameservers and zone status, push panel DNS records one way to Cloudflare, toggle proxying per domain, purge the cache and use development mode.
Websites
- AI bot blocking - allow or block AI bots per site, by bot type and by owner, from a catalog of 27 known AI bots.
- Default landing page - admins and resellers manage landing page templates and assign one per hosting plan.
- Custom 404 for PHP requests - a site with a custom 404 page now serves it for requests to non-existent
.phpfiles too.
Backups
- JetBackup Linux integration - backups and restores cover every account resource rather than just the home directory, including packages, domains with zone files, email and FTP accounts, SSL certificates, databases, cron jobs and DNS records. FTP and mailbox passwords survive a restore intact.
Migration
- In-place conversion - an in-place cPanel or DirectAdmin conversion adopts each account's existing system user, so uids, files and passwords are kept. Plain backup restores still refuse an existing username.
API
- Admin and reseller User API - admin and reseller API keys can call every
/api/client/*endpoint on behalf of an account named in theX-Hosting-Accountheader.
Security and access
- Process listing privacy - an account's running processes and their command lines stay visible only to that account.
- Home directory permissions - site and account directories use restricted permissions that keep other accounts out, applied to every existing account on upgrade.
- Firewall source restrictions - a rule pinned to an IPv4 source or destination applies over IPv4 only, an IPv6-pinned rule over IPv6 only, and a rule with no family over both.
- Panel login protection - a shipped
bolt-panelfail2ban jail bans repeated failed panel logins for admin, reseller and client sign-in alike. - File ownership handling - file ownership checks stay within the account's own home directory and validate the path before any privileged operation.
- Client email page scoping - Subscribers, Catch All and Email Filters in the client panel list only the signed-in account's records.
Fixes and improvements
- Update reliability - a module that fails to upgrade no longer stops the chain,
bolt-update.logends with a per-module summary, the log view shows the underlying error, and scheduled update checks can no longer collide with a running upgrade. - JetBackup service control - service state, version and license are reported correctly, and service control verifies the result.
- PHP disable_functions cleanup -
parse_ini_file,file_get_contentsandcurl_multi_execare removed from storeddisable_functionslists on upgrade. - Email account status - the email account list shows Restricted only for a mailbox that actually carries a restricting state.
- Admin Send Email - Send Email delivers to the address typed in the To field.
- Database and user deletion - deleting a database together with its user revokes the grant first, then removes both, and reports the real error when a step fails.
- License revalidation - runs on the scheduler, so it never delays an admin request.
[1.4.0] - 2026-07-23
Release Overview
This release adds internationalised domain name (IDN) support and login shortcut URLs, alongside broad security hardening across the panel, bolt-agent, Git, databases, email, and file handling.
Domains
- Internationalised domain names (IDN) - domains with non-ASCII names (for example
пример.example) can be added and used throughout AdminBolt. They are stored in Punycode and shown in their readable Unicode form. Document roots and other filesystem paths use the stored Punycode form.
Login
- Login shortcut URLs - every hosted domain answers on short paths that redirect to a login screen:
/cpaneland/panelopen the panel login, and/webmailopens webmail. Accounts moved from cPanel keep the entry points their users already know. The paths, their destinations, and the feature itself are configurable in MyApache Settings.
Security and access
This release includes extensive input-validation, access-control, and data-protection hardening. The main themes:
- Agent authentication - bolt-agent requests require a valid token, which stays enabled by default.
- Ownership enforcement - hosting, network, email, mailing list, database backup, WordPress install, and DNS health-check actions verify that the signed-in account owns the target resource.
- Input validation - certificate issuance, database backup and restore, directory-protection credentials, domain, file, SSH key, JetBackup license, TrackDNS, and mailing list inputs are validated on submit.
- Git safety - Git clone URLs are allow-listed, SSH host keys are verified, and repository paths, ownership changes, and key handling use restricted file operations.
- Path and permission handling -
.htaccessbuilds, SSL storage, and hosting, database, and email file operations use restricted paths; framework directories and panel database files use restricted permissions. - Secret and log privacy - database and hosting operations keep credentials out of process listings, and database-related logs mask sensitive values.
- Reserved usernames - hosting account creation rejects reserved system usernames.
[1.3.0] - 2026-07-15
Release Overview
This release adds mailbox migration from external IMAP servers, reseller resource limits, panel-wide translation with 18 new languages, automatic SSL for hosting domains, and broad security hardening.
Email
- Mailbox import via IMAP - migrate email from an external IMAP server into an existing mailbox. The client panel adds a per-mailbox Import email (IMAP) action with connection testing and live progress.
- Mail subdomain SSL and SNI - mail hostnames (
mail,autoconfig,autodiscover) are issued as a separate certificate group, and mail SNI keys off the certificate the server actually issued.
Internationalisation
- Full panel translation - hardcoded UI strings across the panel are now translatable.
- 18 new languages - added Brazilian Portuguese, Japanese, and 16 more panel languages.
Reseller
- Reseller resource limits - resellers get resource limits (accounts, disk, and bandwidth) on the accounts they manage.
SSL
- Auto-SSL for hosting domains -
bolt-cli setup-cron-jobsnow schedulesbolt-cli run-auto-ssl, so certificates for active hosting domains are issued and renewed automatically.
Security and access
- FTP passwords hashed - FTP passwords are stored as one-way hashes and can no longer be viewed after creation.
- Unattended install admin password - a new
bolt-cli set-admin-passwordcommand sets the admin password during unattended installation. - Mailing list validation - mailing list names are validated on create.
- Data protection hardening - Roundcube, mail, FTP credential, and hosting account export files use restricted ownership and permissions.
Reliability
- ModSecurity audit log page - the ModSecurity audit log viewer now works end to end.
- Lighter health checks - the Services page polls a lighter health endpoint, reducing load.
- Plan allocation alerts - fully used plan allocations no longer raise critical-severity alerts.
PHP
- System restrictions apply reliably - saving
disable_functionsordisable_classesrestarts PHP-FPM so the change takes effect. - Imported domain PHP engine - domain import no longer assigns the wrong PHP engine on LiteSpeed servers.
Fixes
- Update modal - the update modal no longer stays open after an update completes.
- MySQL complex passwords - MySQL user creation accepts a wider range of complex passwords.
- mod_passenger uninstall - uninstalling mod_passenger now removes it from the Apache configuration.
[1.2.2] - 2026-07-09
Release Overview
This release adds a per-account bandwidth limit override with a per-calendar-month usage view, lets email forwarders keep a local copy of forwarded mail, and gives the Hub dashboard clearer stale and offline status for nodes that stop reporting in.
Bandwidth
- Per-calendar-month usage - bandwidth usage now shows the current calendar month instead of a lifetime total, so the counter resets on its own at the start of each month.
- Per-account limit override - admins and resellers can set a bandwidth limit on an individual hosting account that overrides the plan default. Leave it blank to keep the plan's limit, or set 0 for unlimited. Clients cannot change it.
- Consistent units - the client dashboard now shows bandwidth in the same units as the admin panel everywhere.
Email
- Forwarders can keep a local copy - a new Keep a copy toggle delivers each message to both the forwarding address and the local mailbox, so forwarded mail stays visible in webmail.
Security and access
- Suspended client login message - suspended clients now see a clear "Your account has been suspended" message instead of a blank login form.
- IP blocker CIDR handling - the client IP blocker handles CIDR blocks and IP ranges more consistently, so a single block is enforced as one rule.
- Admin panel not indexed - the admin panel is excluded from search engine indexing. Client and reseller panels are unaffected.
Reliability
- Stale and offline node detection - the Hub dashboard flags nodes that stop reporting in as Stale and then Offline, and shows when each node was last seen.
PHP
- igbinary and msgpack locked with Redis - the PHP version form keeps both extensions switched on and labels them "Required by Redis" whenever Redis is enabled.
- Imported domains resolve PHP version - imported domains now pick up the right PHP version automatically.
Fixes
- SSH Terminal page - fixed an error opening the client SSH Terminal page.
- Update screen freezing - a follow-up fix so the update screen no longer gets stuck on an out-of-date view during an update.
[1.2.1] - 2026-07-03
Release Overview
This release introduces BoltTerminal, a new terminal module for CloudLinux servers, brings native CloudLinux SSH and cron support to hosting accounts, and fixes LiteSpeed trial-key activation.
BoltTerminal
- BoltSSH is now BoltTerminal - the SSH module has been renamed and rebuilt as BoltTerminal, with its own installer and health check.
- Built for CloudLinux - BoltTerminal requires CloudLinux and will not install alongside a running SecureBox. On non-CloudLinux servers, SecureBox remains the way to provide isolated SSH access.
- Shell greeting - root login sessions now show a Bolt greeting message.
CloudLinux
- Native SSH access - toggling SSH access on a hosting account uses CloudLinux natively (CageFS and a per-user sshd configuration) instead of SecureBox. Leftover SecureBox setups are cleaned up automatically.
- Cron jobs - hosting accounts on CloudLinux can manage cron jobs whenever SSH access is enabled. Commands run through bash under CageFS isolation.
- CageFS refresh on upgrade - CloudLinux servers get a one-time CageFS update during the panel upgrade.
Fixes
- LiteSpeed trial key - activating LiteSpeed with Use Trial Key no longer fails with a 500 error.
- Custom hostname SSL - the hostname certificate is re-issued when its name no longer matches the configured hostname, so it no longer breaks after a panel update.
- Update screen freezing - fixed the update screen freezing on a stale modal during panel updates.
[1.2.0] - 2026-07-01
Release Overview
This release adds full CloudLinux and LiteSpeed integration, along with a completely rebuilt PHP version manager that lets regular (REMI), CloudLinux Alt-PHP, and LiteSpeed (LSPHP) engines run side by side. See the CloudLinux and LiteSpeed guides for the full workflow.
CloudLinux
- Guided installer - a CloudLinux installation page walks you through activation: enter your license key, run a pre-check that validates the key and system, then convert the OS with a live deploy log. The page tracks the full lifecycle (converting → installed → reboot → converted) and surfaces a Reboot now action when the server is waiting to switch kernels.
- Feature provisioning - after conversion you choose which CloudLinux runtimes to enable (PHP, Node.js, Python, Ruby, and mod_lsapi) with per-runtime version pickers and a live progress log.
- LVE Manager - integrated LVE Manager with single sign-on, installed on demand directly from the panel, for managing per-account resource limits.
- Alt-PHP - install, remove, and configure CloudLinux Alt-PHP versions (5.2 through 8.x) from the PHP manager, including per-version extension selection and default profiles.
- Resource limits from hosting plans - hosting plans gain a Resource Limits tab (CPU speed, memory, IO, IOPS, processes, entry processes). Limits are pushed to the matching CloudLinux/LVE package automatically on plan create, update, and account provisioning, with a backfill command for existing plans.
- Control-panel hooks - AdminBolt fires the CloudLinux control-panel hooks on admin, account, domain, and package changes so CloudLinux stays in sync with your accounts.
LiteSpeed
- Web server switching - switch between Apache and LiteSpeed from the panel. The license is validated before switching, the incoming server's saved settings profile is applied first, and both servers are safely stopped and started so no request is dropped during the change.
- LSPHP - LiteSpeed PHP (LSPHP) versions 7.4 through 8.5 can be installed, configured, and assigned to domains. Matching LSPHP versions are provisioned automatically when LiteSpeed is installed.
- Settings and profiles - a LiteSpeed Settings page with server, security, performance, and module tabs, backed by a default-profile system that is applied on install.
- LSCache - per-domain LiteSpeed Cache management: enable or disable caching, tune default and maximum TTL, maximum object size, and excluded paths, and clear a domain's cache from a dedicated LiteSpeed Cache page.
- Logs and admin - built-in LiteSpeed access and error log viewers, a restart action for the LiteSpeed service, and one-click access to the LiteSpeed WebAdmin console (port 7080 is opened in the firewall on install).
- PHP engine migration - a dedicated migration page moves your domains and plans between matching REMI and LSPHP versions when you switch web servers, with a dry-run preview beforehand. Switching back to Apache is blocked (with a direct link to the migration page) while any domain still uses LSPHP, so sites cannot break.
Improvements
- Rebuilt PHP version manager - a single page to install, remove, configure, and set default profiles for every PHP engine (REMI, Alt-PHP, LSPHP), with vendor logos and clear per-version labels. Domains and plans now reference a specific PHP version, so regular, CloudLinux, and LiteSpeed builds of the same version no longer collide, and a PHP version still assigned to any plan or domain can no longer be uninstalled by accident.
- Automatic PHP sync - installing or removing a PHP package over SSH (for example
dnf install alt-php83) now updates the panel automatically via a dnf/yum hook and connects a matching default profile, with no manual refresh needed. - Hardened shared-hosting defaults - the default
disable_functionslist for PHP profiles has been tightened for safer shared-hosting environments. - Execution logs - background operations are saved to a durable execution log with a title, status, timing, and the operator and IP that started them, plus a richer, level-colored log viewer.
- Reseller account view - resellers can open the full account detail view for their own accounts.
- Convenience - copy actions on hosting plans and feature lists, and a new Resolver Configuration page.
- Performance - CloudLinux control-panel API calls run through a native binary instead of booting PHP per request, making CloudLinux and LVE Manager interactions noticeably faster.
- Stability - the CloudLinux installer detects and recovers from a stalled conversion, and update checks are skipped cleanly on servers where the AdminBolt repository is not configured.
- Fixes - resolved a Safari sign-on issue on the LVE Manager page, ensured Apache is fully restarted after enabling modules (such as mod_lsapi) that require it, corrected PHP-FPM toggle visibility, hardened PHP CLI path resolution so Alt-PHP versions no longer shadow usable binaries, fixed the WordPress one-click installer, and corrected system notification email fallbacks.
[1.0.2] - 2026-05-14
Source
Generated automatically from the panel's built-in changelog (/admin/change-log).
Release Overview
Security and hardening
- phpMyAdmin: deprecated admin endpoint removed; SSO hardened (one-time tokens, hashing, POST-only validation, rate limits, stricter checks).
- Command injection / shell safety: MLMMJ subscribe/unsubscribe and related paths; cron validation + safer command rebuild; backup tar/mkdir args escaped; nmcli DNS inputs validated/escaped; GoAccess path traversal blocked; JetBackup SSO user, license key, and log reads hardened; FTP paths jailed/validated against traversal.
- Databases: strict DB name rules and 422 for invalid names.
- Git: BoltGitService aligned with bolt-git (required Linux user, branches API, safer cleanup semantics).
Major product work
- WordPress: client management UI (plugins/themes/posts, SSO, operations), async installer with progress, conflict handling, shared WP-CLI helpers, i18n, and follow-up security/UX fixes.
- AI Agent Hub: SSO, WA pairing, embedded chat (proxied streams), API key scoping, admin/client routes, hub registration, and related fixes (see large #69 work in history).
Platform and services
- Symlock provisioning and health integration (AB-931).
- SSHD via Bolt Agent (provision/configure, bolt:manage-sshd, profiles command, service rename to SSHD).
- File manager installer URL/version bump (0.0.7 mirror).
UX and admin
- License page: removed extra “license information” block; key UI retained. (AB-961)
- Safari: Filament language switcher layout/z-index fixes.
- Admin SSO CLI: optional --expire duration on generate. (AB-452)
Email and network
- POP3 in mail settings and defaults; POP3/POP3S firewall ports. (AB-514)
Cleanup and refactors
- Removed unusable Fail2BanBannedIpService.
- Removed deprecated htaccess PHP-version rebuild job/path; domain updates only rebuild general htaccess.