Hosting

Free cPanel Alternatives: CyberPanel vs CloudPanel vs aaPanel vs HestiaCP

The four free control panels people put on a VPS instead of cPanel, compared: web server, email, ports, requirements and security history. Then install one, add your first site, lock the panel down, and the OpenLiteSpeed .htaccess lesson we learned on our own server.

Four free hosting control panels compared side by side on a VPS

cPanel is the panel most shared hosts use, but on your own VPS it costs a monthly licence that grows with every account. Free control panels give you most of the same things on a $5 server: websites, databases, free SSL, file manager, and in some cases email and DNS.

This guide compares the four free panels people use most, shows how to install one and add your first website, how to keep the panel itself from becoming the way attackers get in, and one lesson about OpenLiteSpeed that cost us an afternoon on our own server.

The four free panels at a glance

CyberPanelCloudPanelaaPanelHestiaCP
Web serverOpenLiteSpeedNginxNginx, Apache or OpenLiteSpeed (you choose)Nginx in front of Apache
Reads .htaccessRewrite rules onlyNoWith Apache; rewrite rules only with OpenLiteSpeedYes
Email hostingYes, basicNoThrough its mail pluginYes, complete
DNS serverYesNoThrough a pluginYes
Panel addressPort 8090Port 8443Port 7800 plus a secret pathPort 8083
Minimum memory1 GB2 GBAbout 512 MB1 GB (without spam and virus filters)
Systems listed in its docsUbuntu 22.04, AlmaLinux 8 and 9Ubuntu 24.04 and 22.04, Debian 12 and 11Ubuntu and DebianUbuntu 22.04 and 24.04, Debian 12 and 13, also on Arm
Best forFast WordPress with LiteSpeed CacheClean, fast PHP and Node.js sites without emailMany one-click appsAn all-in-one server with websites and email

Details as listed in each panel's documentation in October 2026. They change with new versions, so check the install page before you start.

Which one should you pick?

  • PHP scripts and WordPress that rely on .htaccess: HestiaCP, because Apache reads .htaccess fully. CyberPanel works too, with the limits explained further down.
  • Speed first, no email: CloudPanel. It is clean and fast, but Nginx ignores .htaccess, so clean addresses and protected folders need Nginx rules instead.
  • Email at your domain on the same server: HestiaCP has the most complete mail setup. Even then, many people send mail through an outside service, because a fresh VPS IP often lands in spam.
  • A free Oracle Arm server: HestiaCP lists Arm support in its docs.

Try it: install HestiaCP and add a website

Start from a fresh server: panels take over the web server, database and firewall, and installing one on a server already in use breaks things. First point a subdomain such as panel.yourdomain.com to the server's IP with an A record at your domain's DNS. Then, as root:

# On a fresh Ubuntu 24.04 or Debian 12 server, as root
apt update && apt -y upgrade
wget https://raw.githubusercontent.com/hestiacp/hestiacp/release/install/hst-install.sh
bash hst-install.sh --hostname panel.yourdomain.com --email you@yourdomain.com --clamav no --spamassassin no
OptionWhat it does
--hostnameThe server's name; the panel gets an SSL certificate for it once the A record points here
--emailWhere the panel sends notices about updates and problems
--clamav no --spamassassin noLeaves out the virus and spam filters for mail, which are what need more than 1 GB of memory. Leave them on if you host busy mailboxes on a big server.

The install takes about 15 minutes and ends by showing the panel address and the admin password: save both. Then:

  1. Open https://panel.yourdomain.com:8083 and log in as admin.
  2. Create a normal user for your websites (do not run sites as admin).
  3. Log in as that user and add a web domain. Tick Enable SSL and Use Let's Encrypt, once the domain points to the server.
  4. Add a database on the DB page and upload your files with the File Manager into the domain's public_html.

From there, putting a PHP site online is the same as on shared hosting; our guide to uploading a website to cPanel covers the files, the database import and the usual errors.

The other three install with one command each, from their own documentation:

# CloudPanel (Ubuntu 24.04 / 22.04, Debian 12 / 11). The docs give the current checksum line:
curl -sS https://installer.cloudpanel.io/ce/v2/install.sh -o install.sh
# ...then the sha256sum check and:  sudo DB_ENGINE=MYSQL_8.4 bash install.sh

# CyberPanel
sh <(curl https://cyberpanel.net/install.sh || wget -O - https://cyberpanel.net/install.sh)

# aaPanel
URL=https://www.aapanel.com/script/install_7.0_en.sh && if [ -f /usr/bin/curl ];then curl -ksSO "$URL" ;else wget --no-check-certificate -O install_7.0_en.sh "$URL";fi;bash install_7.0_en.sh aapanel

Lock the panel down

A control panel runs as root and faces the internet, so a hole in the panel is a hole in the whole server. This is not theory:

  • In October 2024, three critical flaws in CyberPanel 2.3.6 and 2.3.7 (CVE-2024-51378 among them) let attackers run commands without logging in. Around 22,000 panels were reachable from the internet, and attackers used the flaws to put ransomware on thousands of servers.
  • aaPanel has a long list of published vulnerabilities over the years, including command injection and file access flaws in older versions.

Every panel can have a bad day. What protects you is the setup around it:

  • Allow the panel port only from your own IP. Your VPS provider's firewall (Hetzner, DigitalOcean, Vultr and Oracle all have one) or the panel's own firewall page can do this. If attackers cannot reach the login page, most panel bugs cannot touch you.
  • Turn on automatic updates for the panel and the system, and read the panel's security announcements.
  • Log in to SSH with a key, not a password.
  • Keep backups somewhere else, not only on the same server, so ransomware cannot take them too.

OpenLiteSpeed and .htaccess: what we learned

Our own blog and shop run on OpenLiteSpeed, the web server inside CyberPanel. It is fast, but it reads only the rewrite rules from .htaccess. Header, FilesMatch, Expires and Deny lines are silently ignored, so a file you thought was protected can still be downloaded. And after you change .htaccess, the server may need a restart before it notices.

The fix has two parts. Protect private files with rewrite rules, which OpenLiteSpeed does read:

# .htaccess on OpenLiteSpeed: only rewrite rules are read, so protect files with them
RewriteEngine On
RewriteRule (^|/)config\.php$ - [F,L]
RewriteRule \.(sql|log|bak|ini|env)$ - [F,NC,L]

And send the security headers from PHP, which works on every web server. Save this as security-headers.php and require it at the top of your pages:

<?php
// security-headers.php: put require __DIR__ . '/security-headers.php'; at the top of your PHP pages.
// OpenLiteSpeed ignores Header lines in .htaccess, so PHP sends the headers instead.
if (!headers_sent()) {
    header('X-Content-Type-Options: nosniff');
    header('X-Frame-Options: SAMEORIGIN');
    header('Referrer-Policy: strict-origin-when-cross-origin');
    header('Permissions-Policy: camera=(), microphone=(), geolocation=()');
    if (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') {
        header('Strict-Transport-Security: max-age=31536000');
    }
    header_remove('X-Powered-By');
}
HeaderWhat it stops
X-Content-Type-Options: nosniffBrowsers guessing that an uploaded file is a script
X-Frame-Options: SAMEORIGINOther sites showing your pages inside a frame to trick visitors
Referrer-PolicyYour full page addresses leaking to other websites
Permissions-PolicyPages using the camera, microphone or location without a reason
Strict-Transport-SecurityVisitors being sent back to plain http; it is only sent over HTTPS
header_remove('X-Powered-By')Telling everyone your exact PHP version

Check the result with your browser's developer tools (Network tab, click the page, Response Headers), or with curl -I https://yourdomain.com.

What a panel does not do for you

A free panel makes the daily work easy, but a server with paying customers on it also needs things no panel does on its own:

  • Off-server backups that you have restored at least once
  • Monitoring that tells you when a site is down or the disk is full
  • Mail that arrives: SPF, DKIM and DMARC records, and an IP that is not on spam lists
  • Someone responsible for updates, every week, for every site on the server

If that is more than you want to handle, good shared hosting with cPanel is often cheaper than your time. Our guide on cheap web hosting shows what to compare.

PHP scripts that run on any of them

Our PHP scripts need PHP 8.1 or newer and MySQL or MariaDB, and protect their private folders with rewrite rules, the kind OpenLiteSpeed also reads. They run on HestiaCP, CyberPanel and aaPanel (with Apache or OpenLiteSpeed) as they are; on an Nginx-only panel such as CloudPanel, the clean addresses need Nginx rules instead.

Where to go next

Questions people ask

What is the best free alternative to cPanel?
It depends on the job. HestiaCP is the best all-in-one choice with websites, email and DNS, and it reads .htaccess. CloudPanel is the cleanest for fast PHP and Node.js sites without email. CyberPanel is built around OpenLiteSpeed and LiteSpeed Cache for WordPress.
Is CyberPanel safe to use?
It can be, if you keep it updated and limit who can reach it. In October 2024, critical flaws in versions 2.3.6 and 2.3.7 were used to put ransomware on thousands of servers. Allow the panel port only from your own IP and install updates quickly.
Does CloudPanel support email?
No. CloudPanel focuses on websites and does not host email. Use an outside email service for your domain, or choose HestiaCP or CyberPanel if you need email on the same server.
Is aaPanel safe?
aaPanel has had several published vulnerabilities in older versions. Keep it updated, keep its secret login path, and allow port 7800 only from your own IP through your provider's firewall.
Does .htaccess work on OpenLiteSpeed and CyberPanel?
Only the rewrite rules. OpenLiteSpeed ignores Header, FilesMatch, Expires and Deny lines in .htaccess, so protect files with RewriteRule lines ending in [F] and send security headers from PHP. A restart may be needed after changing .htaccess.
HestiaCP or CyberPanel: which is better?
HestiaCP if you want full .htaccess support and complete email. CyberPanel if you want OpenLiteSpeed and LiteSpeed Cache for WordPress speed. Both are free and both host email.
Which free panel is best for WordPress?
CyberPanel for speed with LiteSpeed Cache, or HestiaCP if your plugins rely on .htaccess rules. CloudPanel also runs WordPress well, with Nginx rules instead of .htaccess.
Can I install a control panel on an Oracle Cloud free server?
Yes. HestiaCP lists Arm64 support, which suits Oracle's free Arm server. Open the panel port in Oracle's security list and above the REJECT rule in iptables, ideally only for your own IP.
What ports do the free control panels use?
CyberPanel uses 8090, CloudPanel 8443, aaPanel 7800 with a secret path, and HestiaCP 8083. Websites still use 80 and 443. Limit the panel port to your own IP.
Do I need a control panel on my VPS at all?
No. You can install Apache or Nginx, PHP and MySQL yourself and manage everything over SSH. A panel saves time when you host several sites, databases and mailboxes, at the cost of one more piece of software to keep updated.

Written by Habib Baloch

I build Android apps, websites and Ubuntu servers, and write down exactly how I did it.

Ask me about this guide →