Known Limitations (Beta)
operators running a WHost 1.0.0 beta.
This page lists what the current beta release does not do yet, or does differently from what the panel might suggest. Each entry says what you see and what to do instead. An entry leaves this page with the release that changes it; the release notes say so.
Installation
Install with --webserver=nginx or --webserver=nginx_apache. The
installer refuses apache, openlitespeed and litespeed before it changes
anything. OpenLiteSpeed and LiteSpeed Enterprise are switched on after the
installation under Plugins in the admin panel.
Debian 12 cannot run this release. The agent needs Python 3.12, which Debian 12 does not package; the installer recognises Debian 12 and stops before changing anything. See Supported Operating Systems.
SELinux runs in Permissive mode on AlmaLinux, Rocky Linux and CentOS Stream. WHost ships no SELinux policy yet. The installer switches a host that enforces SELinux to Permissive, now and for the next boot, and says so (see SELinux on the RHEL family). Running with SELinux enforcing is planned after the beta.
Accounts and plans
Traffic (bandwidth) is not counted per account. The plan field "Bandwidth" is stored, but WHost does not measure each account's monthly traffic and does not enforce the limit: the account's traffic gauge in the admin panel and on the customer's dashboard always shows 0. Only the server's total network traffic is measured. If you bill by traffic, take the numbers from the web server's access logs for now.
Usage counters. On the admin panel's account page the domain count is always 1, whatever the account holds. On the customer's dashboard the addon-domain allowance shown is one higher than the number that can still be added, because the plan's domain limit counts the primary domain too.
Reseller accounts (experimental). Suspending a reseller suspends its customers' websites, cron jobs and logins, but their FTP users, mailboxes and Node.js / Python applications stay active. Suspend a customer account directly when all of its services must stop.
Web servers
Our test servers run nginx and nginx + Apache. The configuration WHost writes for servers that run Apache alone or OpenLiteSpeed differs as follows:
- No automatic HTTP → HTTPS redirect. A site with a certificate answers
on both
http://andhttps://; nginx-based setups redirect with301. Add the redirect in the site's.htaccessif you need it. (The Apache HTTPS site still sends the HSTS header.)
Ubuntu 22.04 loads the WAF rule set without one file. Ubuntu 22.04 ships
libmodsecurity 3.0.6, which cannot read REQUEST-922-MULTIPART-ATTACK.conf of
the OWASP Core Rule Set 3.3.7 (the file needs 3.0.8). That file is set aside
as REQUEST-922-MULTIPART-ATTACK.conf.disabled and the rest of the rule set
is loaded. What is left out are the rule set's checks of the headers inside
multipart request bodies (file uploads and forms). The engine version itself
predates the fixes to multipart request parsing that ModSecurity 3.0.8
released (CVE-2022-48279); Ubuntu's 3.0.6-1 package carries no backport of
them (September 2026). Where the WAF matters, use Ubuntu 24.04 (libmodsecurity
3.0.12) or the RHEL family, whose EPEL package (3.0.15 on Rocky Linux 9) reads
the whole rule set; the agent puts the file back at its next start once the
engine can read it. The WAF page shows the WAF as inactive, with a note,
whenever nginx has not loaded the rule set.
nginx does not check the agent's certificate on the panel's internal
connection. nginx hands panel and API requests to the agent on
127.0.0.1:2000 without verifying the agent's certificate. Ports below 2001
can only be opened by root, so no process of a hosting account can take the
agent's place on that port, not even while the agent restarts. A separate
internal certificate for this connection is planned after the beta.
Client panel
Subdomains and redirects cannot be edited in the client panel. The row
offers delete only; remove the entry and add it again with the new values.
A redirect can also be changed in place through the API
(PUT /api/v1/client/redirects/{id}).
Webmail has no server-side filters or vacation replies. Mail filters and automatic replies are not available on the server; the webmail's own Filters screen is hidden.
Backups
A scheduled backup interrupted by an agent restart runs again from the start. When the agent is stopped while a scheduled backup is running (an operator restart, a package upgrade that restarts it, a crash), the run is repeated from the beginning at the next start instead of continuing.
Experimental areas
These work in our tests, but not every path has been measured on every supported system yet; treat them as experimental during the beta and report what you find:
- Node.js and Python application hosting
- Migration from cPanel and DirectAdmin over SSH; the other sources the wizard offers (Plesk, HestiaCP, CyberPanel, CloudPanel, CWP and another WHost server) have not been measured yet
- Reseller accounts
- White label
No restore from an uploaded backup file. Migrate over SSH. The Migration page has no Upload tab and the upload endpoints refuse.
API and PHP SDK
- An API key cannot change an account's password or the server's root
password (
403 HMAC_FORBIDDEN_FOR_CREDENTIAL_MUTATION); the account owner changes it in the panel. This is a design decision, not a gap. - The PHP SDK is a download from this site, not a Packagist package; some of its accessors answer only a signed-in panel session. See the PHP SDK page.
Reporting
Report what you find with a support ticket from your wisecp.com client area
(or [email protected] when you cannot open one) and add the WHost version
(Updates page, or GET /api/v1/system/update/status →
current_version), the operating system and what you did.
Our support team is here around the clock for anything you can't find above.