Features
Everything the panel does
Unicorn Panel covers the full hosting lifecycle across an entire fleet: websites, databases, mail, DNS, backups, security, and the operational glue that keeps it all running. Nearly every UI action is also a REST endpoint, with per-account keys and the same access rules as the panel.
Core resources
The eight pillars
Each has a dedicated page. Dive in for the detail.
Websites
Four web engines per site, swappable at any time. PHP 5.6 to 8.5 per site, automatic SSL, cross-server creation, per-site analytics.
Learn moreDatabases
MariaDB, MySQL, PostgreSQL, and Mimir. Per-database backups with table-level restore, and single sign-on into the admin tools.
Learn moreHermes mail suite: IMAP and SMTP, DKIM per domain, spam and virus filtering, Sieve, Roundcube, branded outgoing mail.
Learn moreDNS
Built-in Heimdall DNS: authoritative on any host with the role, plus recursion for the whole server so lookups stay yours.
Learn moreBackups
Per-resource layout, selective restore down to a file, a table, or a mail folder, with safe merge for mail, and backups that can live on another server.
Learn moreFleet management
One-command secondaries, per-host roles, live health, per-host logs, and actions forwarded to the right server automatically.
Learn moreSecurity
Per-site containers, Unicorn Shield, fleet-wide malware scanning, firewall with protected rules, passkey sign-in.
Learn moreCLI & API
A documented REST API with per-account keys, and one call reaches any server in the fleet.
Learn moreMulti-server
One panel, every server
Add a secondary with one command. Every action taken in the panel is forwarded to whichever host holds that site, database, mailbox, or backup. There is no SSH between hosts and no shared filesystem, and nobody has to know which box their work lands on.
- Add a server with a single command on the box
- Actions forwarded to the right host automatically
- Per-host health: CPU busy, memory, disk, uptime, and bandwidth history
- Per-host roles: Web, DB, Mail, DNS, Backup, and Malware Scanner
- IPv6-only servers supported end to end
- Per-host firewall, with the panel’s own rules protected from accidental edits
Websites & WordPress
The things you actually do all day
A WordPress toolkit on every WP site, so the routine jobs stop being SSH jobs: update core, manage plugins, flush permalinks, clear caches, search and replace URLs, and log straight into wp-admin as any of that site’s admins.
- Swap the web engine (NGINX, Apache, Sleipnir, OpenLiteSpeed) at any time, alias domains carried over
- Force HTTPS, force WWW or non-WWW, applied at the proxy layer
- Reinstall core, toggle maintenance mode and debug, manage the admin list
- Disable a site in one click: visitors get a polite holding page, SSL and DNS keep working
- Import a site from an archive, with a picker for databases, mailboxes, and DNS records
- Per-site controls: block AI crawlers and bad bots, ban an IP, basic auth, redirects, cron, SSH keys
File manager
Browse and edit files on any host
A per-site file browser with an inline, syntax-highlighting editor, working across servers through the Primary. Every tenant is jailed to its own files, and bulk delete, move, and copy are checked so nothing can reach across that line.
- Every tenant jailed to its own files, including bulk delete, move, and copy
- Inline editor with syntax highlighting, and find across every editor
- Around 22 MB of PHP-FPM memory even while a 20 GB file downloads
- Extract zip and tar archives in place, inside the same jail
- Download-from-URL refuses private and internal network addresses
- Chunked uploads for large files, so a dropped connection resumes
Mail that carries the reseller’s brand
Every reseller can set their own mail hostname, and every mailbox they own uses it across IMAP, SMTP, webmail, and outgoing password-reset mail. Certificates for those hostnames issue and renew on a nightly sweep, and the panel checks the DNS points the right way before you save.
- A custom mail hostname per reseller, applied everywhere their customers see it
- Several hostnames on one server, each with its own certificate
- Certificates issued and renewed automatically, with an expiry sweep
- Aliases, forwarders, catch-all, DKIM per domain, and per-user Sieve rules
- Spam and virus filtering, with per-domain and per-mailbox allowlists
- Suspend and un-suspend, and a quota per mailbox
Backups
Backups that can restore, not just archive
Every site, database, and mailbox has its own backup schedule. Restore anything back into place from one modal that asks you to type the name to confirm. Take the whole archive, or just the files, tables, or mail folders you actually need.
- Restore a website down to individual files or folders
- Restore a database down to specific tables
- Restore a mailbox whole or by folder, merging so mail received since is kept
- Backups can live on a different server than the site they came from
- Chunked transfers, so a backup interrupted half way resumes instead of restarting
- Off-box destinations such as S3 and BunnyCDN, with a retry when a ship fails
Webapps
Bundled admin tools, auto-installed
Enable a role and its tools install in the background. You are signed into them already: no second set of credentials to hand out or to lose.
Adminer
Universal database admin for every supported engine, reached by single sign-on.
phpMyAdmin
Familiar MariaDB and MySQL administration, no separate login.
phpPgAdmin
PostgreSQL administration in the browser, no separate login.
Roundcube
Webmail with single sign-on, working on the first click and across servers.
Web SSH
A terminal in the browser, on any host in the fleet, with per-session token auth.
Survives upgrades
The wrappers are version-independent, so a role upgrade does not break the tools behind it.
Monitoring & analytics
Know what the fleet is doing
Traffic you can compare
A line chart with hover detail, a compare mode for this period against last, and custom ranges up to 366 days.
Real CPU, not load average
Busy percentage measured from the kernel’s own counters, so the number means what you think it means.
Memory, disk, uptime, bandwidth
Live per server on the Servers page, with bandwidth history rather than just a current figure.
Mail and database sparklines
Sent and received per mailbox, and database and domain activity, each with hover detail.
Certificates before they expire
A daily sweep across the fleet, for the panel, for sites, and for mail hostnames.
Where traffic comes from
Country flags against the addresses you are blocking, so a ban list is readable at a glance.
Security
Isolation, malware, and getting in safely
Real isolation per site
Every site is its own container with its own PHP-FPM, and its own limits on CPU, memory, disk, and processes.
Malware across the whole fleet
Every scanner-enabled server reports into one view, running ClamAV and Linux Malware Detect.
Quarantine where you found it
Quarantine, restore, whitelist, or delete a finding in place, from the fleet view or the site’s own tab.
Passkeys and real 2FA
Passwordless sign-in, and 2FA that also covers password reset, so a stolen inbox is not enough to take an account.
Sessions bound to the browser
A stolen cookie replayed from somewhere else fails. Sign-in errors never reveal whether an address exists.
Scans that show their work
Live progress with elapsed time and interim hits, so a long scan never looks like a stuck one.
Network & DNS
Your resolver, your firewall, your addresses
Recursion for the whole server
Mail, the panel, and everything else on the host resolve through your own DNS, so spam and certificate lookups are not handed to your provider.
Firewall with guard rails
A rules editor where panel-managed rules are protected from accidental edits, and a custom SSH port is detected and kept open.
IPv6 that does not strand you
Turn it on after install and the bridge and firewall re-sync. IPv6-only servers are supported, and a broken resolver swap rolls itself back in seconds.
SSL that keeps itself current
Let’s Encrypt with automatic renewal, two-part domains handled, and sites behind a CDN allowlist renewing correctly.
Multi-tenancy, packages & branding
Six roles, packages that hold them together
Owner, SuperAdmin, Reseller, Customer, Collaborator, and Support Staff. Collaborators help run someone else’s site with the same tools the owner has, and cannot delete anything. Packages bundle the limits, the resource caps, and which parts of the panel each account can see.
- Limits on sites, mailboxes, databases, domains, aliases, and customers
- Caps on CPU, memory, disk, processes, bandwidth, and mailbox quota
- Resellers keep their own package catalog, and their own brand and outgoing mail
- Log in as any account from the admin view, to see exactly what they see
Notifications
Templated mail on the events that matter
Event hooks
Backup failed, site provisioned, SSL renewed or failed, mailbox created, and password reset.
Per-recipient brand
Each notification renders with the recipient’s reseller brand, not yours, and goes out through that reseller’s own SMTP.
Operator override
Replace the default template across the whole fleet when you need the wording to be yours.
Operational primitives
The glue that keeps upgrades boring
Per-version upgrade steps
Every release carries what that version needs applying: schema changes, file moves, service reloads. You run one command.
Roll out at your pace
Upgrade one host, watch it, then take the rest of the fleet. Roles across the fleet can be brought up in one action.
Backed up before it starts
Every upgrade snapshots state before it touches anything, so a bad one is a restore rather than a rebuild.
Quiet when nothing happens
Polling slows down when the fleet is idle and stops when the tab is hidden, so watching a fleet costs almost nothing.
Run your fleet from one panel.
Self-hosted. Multi-server. No usage telemetry, no hidden tiers.