Sleipnir Web Server
Hosting at a full gallop.
Sleipnir is the featherweight web server we built from scratch in C to make your sites blisteringly fast. A ~215 KB origin engine, designed to sit behind your reverse proxy and do the real work: serving your static files and WordPress. Switch in minutes, feel the difference instantly.

Native .htaccess support means your WordPress permalinks, redirects, and rewrite rules migrate exactly as they are. No rewriting configs, no broken links.
The problem
Your host is doing too much. Your sites pay for it.
Off-the-shelf origin stacks bloat over time: a heavy application server, a separate process manager, and a base image full of modules you never asked for, each with its own dependencies and config. Dashboards crawl, and a migration that should take minutes breaks permalinks and rules you forgot you had. We got tired of it too, so we built our own.
- Sluggish, layered stacks with a lot to patch
- Migrations that quietly break permalinks and redirects
- Config changes that mean a restart and a blip of downtime
Featherweight. Ferocious.
Lighter than the last photo you took
The entire Sleipnir engine weighs about 215 kilobytes. No bloat, no sprawling dependencies, no mystery layers eating your server alive. Just a lean, self-contained engine that boots in a blink.
The whole engine is lighter than the last photo you took.
| The Sleipnir difference | Sleipnir-powered | Typical host |
|---|---|---|
| Server footprint | ~215 KB, self-contained | Heavy, many dependencies |
| Runtime dependencies | None (one static binary) | Many shared libraries |
| WordPress migration | Bring your .htaccess as-is | Rewrite configs, fix permalinks |
| Config changes | Seamless, zero-drop reloads | Restarts and downtime |
| Architecture | Event-driven, multi-worker | Varies, often layered |
| Built for | Tuned for our users | Everyone, and so no one |
Qualitative on purpose. We have not published benchmarks, so there are no speed multipliers or request-per-second figures here. The 215 KB engine size is real; everything else is about fit, not a leaderboard.
The toolkit
Everything a modern site needs, built in
The full HTTP method set, and the modern WordPress toolkit behind it.
Big uploads, no sweat
Large media and backups stream straight through with bounded memory, instead of buffering the whole file and choking your server.
Full modern toolkit
The WordPress REST API, the block editor, and your plugins get every request they need, with the full HTTP method set: GET, HEAD, POST, PUT, DELETE, PATCH, OPTIONS.
Faster by default
Smart static-file caching, automatic gzip compression, and long-life asset cache headers, all built in and on from the start.
Reachable everywhere
Designed to run behind a reverse proxy and IPv6-ready, so the right visitor reaches the right site and you still see real client IPs.
Locked-down by design
Sensible security headers and dotfile blocking out of the box, so the obvious foot-guns are closed before you start.
Seamless reloads
Configuration changes apply mid-stride, without dropping a single visitor. No restarts, no downtime, no drama.
Faster and safer, by default
Every response carries its weight
Static assets come back compressed and cached for the long haul, sensible security headers are always set, and dotfiles are blocked. None of it is something you have to remember to turn on.
$ curl -I https://example.com/app.css HTTP/1.1 200 OK Content-Encoding: gzip Cache-Control: public, max-age=31536000, immutable X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin $ curl -I https://example.com/.env HTTP/1.1 403 Forbidden # dotfiles blocked by default
Under the hood
Original engineering, tuned for one job
Written from scratch in C
Not a fork or a re-skin. Sleipnir is original software, purpose-built for fast, multi-tenant hosting, and runs on Alpine Linux and musl.
Event-driven and non-blocking
A multi-worker, event-driven core handles many connections without a thread per request, so it stays lean under load.
From-scratch container
Ships as a ~215 KB single static binary in a minimal "from scratch" container. No base image full of packages you did not ask for.
Multi-tenant isolation
Every site is isolated from its neighbors, so one busy or misbehaving site does not become everyone else’s problem.
Built to sit behind a proxy
Designed to run as the origin behind a reverse proxy and speak IPv6, so real client IPs survive the trip and routing stays correct.
Native .htaccess
Rewrites, headers, and access control read straight from .htaccess, the same trick the premium servers charge a premium for.
How it works
The lean origin that does the real work
Requests arrive through your reverse proxy and reach an event-driven Sleipnir worker. Static files come back cached and compressed; anything dynamic streams straight to WordPress and back. Sleipnir is proxy-aware, so your sites still see real client IPs, and it stays focused on one job: serving your sites fast.
- Designed to run behind your reverse proxy
- Proxy-aware, so real client IPs are preserved
- Static files cached and compressed automatically
- Dynamic requests streamed to WordPress, full method set
Bring your WordPress site as-is
You move in. It just works.
Sleipnir reads .htaccess natively, the same capability the premium servers treat as a paid feature. Your permalinks, rewrite rules, redirects, and security rules all run exactly as they are. No rewriting configs, no "it worked on the old setup," no broken links the day after you switch.
- Permalinks, redirects, and rewrite rules carry over unchanged
- Security and access rules apply as written
- No config rewriting and no surprise 404s
# your existing WordPress .htaccess, unchanged RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] Sleipnir reads this natively. Permalinks just work.
See the config
Config you can read at a glance
Global options up top, then one vhost per site. trust_proxy keeps real client IPs intact behind your reverse proxy. This is illustrative, and inside Unicorn Panel it is written and reloaded for you.
# sleipnir.conf · global options + one vhost workers auto server_tokens off trust_proxy on block_dotfiles on vhost domain.com { server_alias www.domain.com listen unix:/run/domain.com.sock root /home/public access_log /home/.upcp/logs/web-access.log error_log /home/.upcp/logs/web-error.log php_fpm /run/domain.com-php.sock }
Why we built it
“Good enough for everyone” means perfect for no one
We did not tune someone else’s web server. We wrote Sleipnir from the ground up in C, for exactly one job: serving your sites fast. Because we own every line, every optimization and fix lands on our schedule, for our users, instead of waiting on a general-purpose project that has to please everybody. That is the difference between a server you configure around and one built for what you actually do.
- One static binary, no runtime dependencies to chase
- Every improvement tuned for our users, not the average of everyone
- Real engineering behind the brand, not a re-skin
# one static binary, nothing else to install $ ls -lh sleipnir -rwxr-xr-x 215K sleipnir $ ldd sleipnir not a dynamic executable # zero runtime deps
Who it is for
Fast for site owners, respected by developers
WordPress owners and bloggers
Speed and zero hassle. Bring your site as it is, watch it fly, and never wrestle with server config again.
Agencies and freelancers
Many client sites that need to be reliable, quick to move, and easy to look good in front of clients.
Developers and founders
A lean, from-scratch engine with the control and headroom you want, and an engineering story you can actually respect.
Switch in minutes
Switching is the easy part
Moving in is the part people dread, so we made it the boring part. Bring your WordPress site as it is, Sleipnir reads your existing .htaccess, and your permalinks, redirects, and rules apply unchanged. You go live without rewriting configs, on your own schedule.
- Bring your files and database as they are
- Your .htaccess and rules apply unchanged
- Go live without rewriting a thing, on your schedule
How to get it
Sleipnir powers every site on Unicorn Panel
Sleipnir is the web engine inside Unicorn Panel. Create a site and the panel serves it with Sleipnir, writes the config, applies your .htaccess, and keeps it updated. There is nothing separate to install or babysit.
Get Unicorn Panel Migrate your sites Explore the Unicorn Stack
Questions
Straight answers
Will my WordPress site break if I switch?
No. Sleipnir reads your existing .htaccess natively, so permalinks, redirects, rewrite rules, and security rules carry over unchanged. You bring the site as it is.
Do I have to change how I work?
No. The WordPress dashboard, block editor, REST API, and your plugins all work as normal, with the full HTTP method set behind them.
Is there downtime when settings change?
No. Sleipnir reloads configuration seamlessly without dropping a single connection, so changes apply mid-stride.
What makes it faster?
A lean, purpose-built, event-driven engine focused on one job, serving your sites, plus built-in static-file caching, compression, and long-life asset headers. It runs as the origin behind your reverse proxy. We describe this qualitatively: we have not published benchmark numbers.
Can it handle big uploads and busy sites?
Yes. Large media and backups stream straight through with bounded memory instead of buffering everything, and each site runs isolated from its neighbors.
Can I download Sleipnir or self-host it?
No. Sleipnir is the proprietary engine inside Unicorn Panel. It powers your sites on the platform rather than being a separate download.
Ready to ride?
Your sites deserve an engine built to outrun the rest. Switching takes minutes, feeling the difference takes seconds.