v1.0.14UpcomingNot released yet, and subject to change
- NClone an existing website to a new domain. Create a Website now has a Clone tile alongside Static HTML, PHP, and WordPress. Pick the source site from a searchable dropdown, toggle what gets copied (files, URLs, paths, linked databases, cron jobs, SSH keys), and the panel builds the clone in the background. Progress streams live into the Create screen with a one-line status plus a View details log, and the whole process keeps running even if you close the tab. WordPress sites use WP-CLI search-replace so serialised data stays valid when the domain changes. Clones can target the source server (fastest) or any other server in your fleet, with the source streaming directly to the target over the panel's cross-server tunnel.
- EMailbox menu reorganised. The mailbox kebab menu was getting crowded. Change password, Set quota, and View DKIM key now live under a Settings submenu, and a new Spam settings submenu groups Whitelist with the new Defaults modal.
- NPer-mailbox spam thresholds. Open any mailbox, go to Spam settings then Defaults, and set your own Junk and Reject scores for that one mailbox. Leave a field blank to keep the server-wide default. Useful for a mailbox that needs to be more strict (an executive address) or more lenient (a role mailbox that receives bulk mail).
- FMailboxes created on the primary panel no longer appear twice. On a primary panel that also runs the Hermes mail role, a newly created mailbox was being shown twice on the Emails page because the create and sync paths were writing two separate rows. New mailboxes land once, and any existing duplicates are cleaned up on the next sync tick.
- EGlobal search now ranks closer matches first. When you typed a keyword in the top-right search, up to three matching websites, domains, databases, emails and users were returned in whatever order the database happened to pick. If you had unicornpanel.com plus five subdomains, searching unicorn could bury the apex under its own subdomains. Results are now ordered by relevance (exact match, then starts with, then contains) with the shorter name winning ties, and the per-category limit has been bumped from three to five so the row you want almost always appears.
- EFilter the Servers list by role. Fleets with many servers often only need to see the ones running a specific role. A new All roles filter above the server list lets you pick one or more roles (MariaDB, Hermes, NGINX, and so on) and show only the matching servers.
- FMailbox sparkline tooltip now shows the real hourly count. Hovering a bar on the Sent or Received sparkline on the Emails page used to show the ten-minute average for that hour instead of the hourly total. If a mailbox sent 18 messages in one hour, the tooltip read 3 sent (18 divided by six ten-minute samples). The tooltip now reads 18 sent, and the twenty-four hourly values add up to the Sent or Received total shown above the sparkline.
v1.0.135th October 2026
- ECustom cache purge is now instant and query-string aware. The Custom option on the Website Cache card now hands each pattern straight to the proxy's purge endpoint. One path per line, add a trailing
* to purge every URL that starts with it. / purges the homepage, /products/* purges every page under /products/, /* purges everything cached on the site. Pages with query strings (?utm_source=... and the like) are now covered by a matching prefix pattern.
- EDatabase admin tools now support MySQL, PostgreSQL, and Mimir. Reconcile Orphans, Process List, Size Ranking, Schema Anomalies, Optimize All, and Analyze All on the server Tools page used to assume MariaDB only. Each tool now opens with an engine dropdown that only lists the engines actually installed on that server. Size Ranking and Schema Anomalies cover Mimir too (walking each tenant that uses it and showing which tenant owns each row), while Optimize, Analyze, and Process List stay engine-specific since Mimir does not expose those operations.
- FMail now works over IPv6. On dual-stack servers running the Hermes mail role, SMTP, submission, SMTPS, IMAP, IMAPS, and ManageSieve were only accepting connections over IPv4 even though every other service on the panel was already dual-stack. Mail daemons now bind on both families, and existing installs are patched automatically on upgrade.
- NFive new audit tools under Servers then Tools. SSL Audit flags expiring, mismatched, self-signed, or orphan certificates (and cleans up orphan cert files for you). Mail Deliverability Audit checks SPF, DKIM, DMARC, MX and reverse DNS for every mailbox domain. DNS Zone Audit confirms your registrar still points at your panel nameservers and that SOA serials match across them. Orphan Disk Audit shows files on disk that no longer belong to a panel row (container homes, backups, vhost configs, DNS zones). Resource Leader Board ranks the top ten tenants by CPU, memory, disk space, disk read, disk write, inodes, and bandwidth over the last seven days.
- EOne Test Web Server Configs tool covers every engine. The old Test NGINX Config card is replaced with a single Test Web Server Configs tool. By default it runs the config check on every web server installed on that host (NGINX, Apache, Sleipnir, OpenLiteSpeed) one after another, or you can pick a single engine from the dropdown. OpenLiteSpeed now gets a real config test instead of being skipped.
- FTest PHP-FPM Configs no longer complains about static sites. The output used to show a Missing PHP config line for every static site on the server, which looked alarming but was just noise. Static sites are now skipped silently, so the output only shows the sites that actually run PHP.
- FHermes settings file is no longer accumulating duplicate section headers. Every save on the Settings then Hermes Mail Suite page used to append another copy of the managed-section header to umail.conf, so a long-running install could end up with the same header repeated ten or more times. The writer now keeps a single copy, and the upgrade tidies files that had already stacked up.
- PChangelog is easier to scan. Each entry on the Update page now carries a coloured pill (New, Enhanced, Fixed, Security, Polish) above its text, with bolded headlines and inline code snippets rendered properly instead of flattened to plain text.
- PUpcoming releases are labelled as such. A release listed in the changelog that is ahead of what the panel can actually pull now shows as Upcoming update instead of Update available, so you do not try to install a version that is not yet live.
v1.0.122nd October 2026
- NClear specific URLs from the website cache. On a cached site, click Clear next to the Website Cache card and pick Custom. Paste one URL pattern per line, use
* for wildcards. Patterns match the full cached URL, so /cart, /products/*, or example.com/* all work. Clear All still does what it always did.
- NMail routing moved into a submenu on each mailbox. The mailbox kebab menu was getting long. Aliases, Forwarders, Vacation responder, and Whitelist now live under one Mail routing entry so the top-level menu is cleaner.
- FLicense page shows your real plan caps. Reseller plans used to display Servers and Accounts as
1 / ∞ regardless of the cap on your plan. The page now shows the actual numbers your license includes (for example 1 / 10 servers, 4 / 50 accounts).
- FDeleting a Mimir database works even when its site is gone. If a Mimir-backed site had already been removed, the matching database row refused to delete and sent a daily failure email. The delete now recognises the missing site and removes the orphan row cleanly, and the daily cron stops alerting on it.
- FWeb Apps page shows what is actually installed. On a fresh primary, phpMyAdmin and phpPgAdmin showed as Installed with an Update prompt even though nothing had been installed yet. Install state is now read from a real install marker, so fresh panels correctly show Not Installed until you click Install.
- FSupport role can now use Login As. Support accounts could not impersonate customers from the Users page even though the button was visible to them. They can now Login As any customer or reseller, matching the behaviour of Owner and SuperAdmin.
- FSupport role Users page shows the whole customer list. The Users page and the sidebar counter used to show only the Support account itself. Support now sees every customer, reseller, and collaborator on the panel, same as Owner.
- FServer picker in Packages hides decommissioned servers. The Accessible Servers list on the Add/Edit Package screen was including servers that had been decommissioned or soft-deleted. Only live, usable servers show up now.
- STightened who can edit and promote accounts. A sweep across the Users and Account endpoints to make sure the panel enforces its own tier rules at every write path. Only an Owner can create or demote another Owner, Resellers can only create Customers and Collaborators, and no tier can edit an account at or above its own.
- SFewer admin details exposed to tenant accounts. Several admin-only pages and the Servers list used to return more server detail than non-admin users needed. Customers and Resellers now see only the servers that host their own resources, with admin-only fields stripped.
- SDisabling an account signs it out immediately. Previously a disabled account kept its browser session alive for up to 24 hours. Disable now revokes every active token right away. Login paths outside the password form (passkey, impersonation) also refuse disabled accounts.
- SInvite links now rate-limited. The Accept Invite page gets the same per-IP throttle the login and password reset pages have had for a while, so a bad actor cannot sit on the endpoint hammering invite tokens.
- SPanel headers tightened. The panel now sends Strict-Transport-Security and Permissions-Policy headers, and no longer advertises its web server in the response. Shows a cleaner security audit without affecting how the panel works.
v1.0.1129th September 2026
- FRestoring an incremental website backup now puts your site back to the exact state it was in on that date. Since 1.0.9, restoring a daily was only applying that day's changes on top of whatever was currently on disk, giving you a broken part-site. The restore now walks the whole chain from the last full backup up to the one you picked, in order.
- NRestore any file from any backup, even ones that have not changed in weeks. The file picker now shows every file that was on your site as of the backup date, not just files that changed in that specific archive. Restoring one unchanged file only reads the older archive that contains it, not every archive since.
- NRestore preview shows the chain of archives being walked. Before you confirm a restore, a card explains how many archives will be applied and how many bytes total, so you know what to expect.
- FDelete local files after remote transfer now actually removes them. The toggle under Settings then Backups had been silently keeping the local copy since 1.0.9. It now purges each backup from local disk once every enabled remote target confirms. Download and restore fetch the archive back from remote automatically when needed, so nothing changes on your side except reclaimed disk.
- FDeleting a Mimir database on a secondary server now works. Delete used to fail with a container-not-found error on any server that only ran Mimir databases. The delete now targets the tenant's own database container correctly.
- SHardened tenant isolation around Mimir database operations. Tightened how tenant-provided configuration values are passed through to database tooling. Closed at every affected code path.
v1.0.1028th September 2026
- FForce HTTPS, Force WWW, and Force non-WWW now actually redirect visitors. These toggles were silently doing nothing since 1.0.0. The upgrade regenerates every site's config so the fix takes effect across your fleet automatically.
- NCap how many Collaborators a customer or reseller can add. Set the number in Settings then Packages, next to Max customers. Zero disallows Collaborators. Existing Collaborators are kept when a cap is lowered later.
- FUsers page stays visible for accounts that can only add Collaborators. A customer whose sub-account limit is zero can still add Collaborators when their package allows it. Add User now shows the right message and picks the right cap.
- EMalware scanner is quieter on real photos. Broken-image detections that fired constantly on phone camera exports and product photos are turned off. Actual threats keep getting detected.
- ENew packages default Max cache size to 256MB. Previously it was unlimited, which is not a sensible default for a disk cache.