A hosting control panel holds the keys to every website, database and mailbox on your servers. That makes it one of the most attractive targets in your infrastructure. A weak panel login, a shared credential between servers, or one unpatched site that can reach its neighbors can turn a small incident into a fleet-wide one.
This checklist covers fifteen protections every hosting provider should have in place, grouped into five layers. For each, we note how Unicorn Panel handles it, based on its security page, so you can compare against whatever you run today.
Layer 1: Isolate tenants from each other
Most compromises start with one vulnerable website. Isolation decides whether that stays one website.
1. Every site in its own container. Each site should have its own processes, user and resource limits, so a compromised or overloaded site cannot reach or starve its neighbors. Unicorn Panel: every site runs in its own container with its own user, ports and limits on CPU, memory, disk and processes. Our guide to container-per-site hosting goes deeper.
2. No shared PHP-FPM pool. A shared pool can let one site read another's files. Unicorn Panel: each site has its own PHP-FPM; nothing is shared between tenants.
3. Jailed file access. Panel file tools must respect tenant boundaries, including bulk operations. Unicorn Panel: file access is jailed per tenant, including bulk moves and copies.
4. Least privilege for the panel itself. The panel should not run with unlimited power over the host. Unicorn Panel: one small daemon per host does the privileged work, and the panel holds only the access it needs.
Layer 2: Stop attacks at the edge
5. Brute-force banning at the firewall. Logging failed logins is not enough; repeat offenders should be blocked before they reach the site, database or panel. Unicorn Panel: Unicorn Shield watches WordPress logins, SSH, panel sign-ins and malicious request patterns at the proxy, and bans offenders at the firewall. Bans survive restarts, and every banned address is listed with its country, with manual ban and unban.
6. A firewall you cannot lock yourself out of. Custom rules are necessary, and mistakes are common. Unicorn Panel: the panel's own rules are protected, a custom SSH port is detected and kept open, IPv6 counterparts are added automatically, and one command recovers from a bad rule.
7. Per-site bot and access controls. Site owners should be able to block bad bots and AI crawlers, ban addresses, and password-protect staging sites. Unicorn Panel: each site can block AI crawlers and bad bots, ban IPs, allowlist Cloudflare or BunnyCDN, or sit behind basic authentication.
Layer 3: Find malware fast
8. Fleet-wide malware scanning. Infected files need to be found across every server, not checked one box at a time. Unicorn Panel: each host running the scanner reports into one list, with ClamAV and Linux Malware Detect supported. Findings can be quarantined, restored, whitelisted or deleted from the same view, and scans show live progress.
9. Outbound mail protection. A compromised mailbox sending spam can blocklist your whole server. Unicorn Panel: the Hermes mail suite enforces per-mailbox send limits, can auto-suspend a mailbox that bursts past them, and scans outbound attachments for known malware.
Layer 4: Make stolen passwords useless
10. Passkey sign-in. Passkeys are resistant to phishing and credential stuffing. Unicorn Panel: passkey sign-in is built in (it needs the panel on a fully qualified domain name). When we checked in September 2026 for our comparison, cPanel, DirectAdmin and Virtualmin offered TOTP only, while Plesk offered passkeys through a free extension.
11. 2FA that also covers password reset. If reset only needs email access, an attacker with a customer's inbox can take the account. Unicorn Panel: the second factor is also required on password reset.
12. Sessions bound to the browser. A stolen session cookie should not work from another machine. Unicorn Panel: sessions are tied to the browser that created them and checked on every request. Sign-in errors never reveal whether an account exists, repeated attempts hit a cooldown, and disabling 2FA or changing passkeys requires the password again.
13. Collaborators without destructive rights. Developers and staff often need access but should not be able to delete things. Unicorn Panel: collaborators get the owner's tools without the ability to destroy anything.
Layer 5: Protect credentials, keys and data
14. Scoped keys, not shared credentials. Servers in a fleet should not share one root SSH key, and API keys should carry only their owner's permissions. Unicorn Panel: per-account API keys carry exactly that account's access; servers talk over HTTPS with their own per-server keys; file downloads and admin-tool single sign-on use short-lived tokens. More in our API and CLI guide.
15. Encrypted secrets and restorable backups. Backup destination credentials should be encrypted, and backups should live off the server. Unicorn Panel: S3 and BunnyCDN credentials are encrypted at rest with AES-256-GCM and never returned to the browser. Backups can be pushed to S3-compatible storage, SFTP, rsync or another fleet server, and every panel upgrade snapshots state first.
The quick-reference checklist
| # | Protection | Unicorn Panel |
|---|---|---|
| 1 | Container per site | Default |
| 2 | No shared PHP-FPM | Default |
| 3 | Jailed file access | Default |
| 4 | Least-privilege panel | Per-host daemon |
| 5 | Firewall-level brute-force bans | Unicorn Shield |
| 6 | Lockout-safe firewall | Guard rails |
| 7 | Per-site bot and access controls | Built in |
| 8 | Fleet-wide malware scanning | ClamAV, Linux Malware Detect |
| 9 | Outbound mail protection | Hermes limits and auto-suspend |
| 10 | Passkeys | Built in |
| 11 | 2FA on password reset | Built in |
| 12 | Browser-bound sessions | Built in |
| 13 | Non-destructive collaborators | Built in |
| 14 | Scoped keys between servers | Per-server API keys |
| 15 | Encrypted secrets, off-host backups | AES-256-GCM, remote targets |
Operational habits that matter just as much
Software protections work best alongside good habits:
- Keep everything updated. Apply panel and role updates promptly; Unicorn Panel flags new role versions and updates them across the fleet in one action.
- Start from a minimal OS. A small base like Alpine Linux means fewer packages to patch. See a free web hosting control panel built for Alpine Linux.
- Put the panel on a real domain with a valid certificate so passkeys and modern browser security features work.
- Enable 2FA or passkeys for every operator and reseller account on day one.
- Test restores, not just backups.
- Review activity. Sign-in history, per-server activity and the command log show what changed and who changed it.
- Report vulnerabilities responsibly. Unicorn publishes a security policy for disclosures.
Frequently asked questions
What is the most important hosting security control? Tenant isolation. It limits the damage from the most common incident, a single compromised website.
Does Unicorn Panel include malware scanning for free? Yes. Security features, including isolation, Unicorn Shield and malware scanning, are the same on every plan.
Can I use passkeys with an IP-only panel? No. Passkeys need the panel on a fully qualified domain name.
How do servers in a Unicorn fleet authenticate to each other? Over HTTPS with per-server API keys, with no shared root SSH key.
Secure by default, not by upsell
Every protection on this list is part of Unicorn Panel's standard product, including the free tier for two servers. Install it and start from a secure baseline:
wget -qO- https://unicornpanel.com/install | sh
Or try the live demo to see the security views in action.