Web hosting management, simplified.Light. Fast. Complete.
enconf is the modern alternative to Plesk. Manage servers, sites, email, DNS, backups and WordPress — all in one lightweight hosting control panel. Ready in just 5 minutes, uses under 75 MB RAM.
apt install -y curl)Web hosting management, rethought
Built for hosts who value efficiency, transparency and full control.
Transparent pricing
All features included in every plan — WordPress staging, reseller system, encrypted backups. No hidden fees, no invoice surprises.
Minimal resource usage
Under 75 MB RAM for API and agent. More capacity for your customer websites — a decisive advantage especially on VPS servers.
Real customer isolation
Every customer gets their own Linux user, dedicated PHP-FPM pool and isolated directories. OS-level security, not just file-level.
Everything your server needs
From WordPress to disaster recovery — enconf delivers a complete hosting toolkit in one lightweight interface.
WordPress Toolkit
Install, stage, update and SSO-login — for all your WordPress sites.
Learn more →WordPress migration
Take over complete WordPress instances from any host — without FTP, SSH or database access. The wp-admin login is all it takes.
Learn more →Joomla Toolkit
Install Joomla 5, manage extensions and use staging environments.
Learn more →PrestaShop Toolkit
Install PrestaShop 8, manage modules, admin SSO and shop scan directly from the panel.
Learn more →Email hosting
Mailboxes, aliases, forwarders and lists, spam protection with rspamd — plus professional deliverability: DKIM, SPF/SRS and ARC sealing for forwardings. All integrated.
Learn more →DNS & SSL
PowerDNS zones, Let’s Encrypt wildcard certificates and automatic renewal.
Learn more →Security
Customer isolation, nftables firewall, fail2ban.
Learn more →Backup & DR
Encrypted backups to S3, FTP or local — with full disaster recovery.
Learn more →All the basics included — in every plan
From multi-PHP to modern anti-spam — the tools of daily operation are included at no extra cost.
Config drift? One click rebuilds it.
enconf re-renders Nginx, TLS, Postfix, Dovecot, DNS and the firewall transactionally from the database — with service test and automatic rollback.
Detect drift automatically
The panel diffs on-disk config against DB truth and shows per file which parts were edited manually.
Transactional one-click repair
Nine repair functions per domain (TLS, vhosts, pools, mail-SNI, DNS, firewall, orphans, backup snapshots). Service test failed? Automatic rollback to the last good state.
Dry-run with byte-diff
See exactly what would change beforehand — file by file, byte by byte. No production surprises.
Site Doctor: finds problems before your customers do
Automatic per-site diagnosis right in the customer area — with one-click fixes and background monitoring.
Detects problems automatically
SSL expiry, malware, WordPress vulnerabilities, stopped PHP service, 5xx errors, PHP errors, slow requests, full storage and inodes — all checked continuously.
One-click fixes
Detected problems can be fixed directly — e.g. restart the PHP service — no SSH, no support ticket. Includes details on PHP errors.
Background monitoring & history
Runs automatically in the background and reports new problems immediately — with history, so nothing is missed.
Security per site — not per customer.
If one site of a customer is compromised, their other sites stay untouched. Plesk, cPanel and Enhance share a single Linux user across all sites of the same customer — in enconf every site gets eight dedicated isolation layers.
| Layer | enconf | Plesk | cPanel | Enhance |
|---|---|---|---|---|
| Linux user + UID | ✓per site | per customer | per account | per customer |
| PHP-FPM pool | ✓per site | per customer | per account | per customer |
| open_basedir + disable_functions | ✓per site | per customer | per account | per customer |
| Dedicated /tmp directory | ✓per site | partial | ✗— | per customer |
| AppArmor profile | ✓per site | ✗— | ✗— | ✗— |
| systemd cgroup (RAM / CPU / tasks) | ✓per site | ✗— | ✗— | partial |
| ProFTPD chroot | ✓per site | per customer | per account | per customer |
| Separate access logs | ✓per site | per customer | per account | per customer |
Eight independent layers, rendered fresh from the DB on every site provisioning. That is real defense in depth.
Detailed comparisons: enconf vs. Plesk, cPanel, CloudPanel, ISPConfig, KeyHelp · all comparisons →
Security you can verify.
Defense in depth across independent layers — visible in real time in the Security Advisor, with SBOM, signed updates and EU CRA evidence.
Defense in depth
A dedicated Linux user per website, isolated PHP-FPM pools, AppArmor in enforce mode and systemd resource slices. Every layer must be broken on its own.
Live security score
The Security Advisor continuously runs hardening checks per server and shows in real time which layers are active — proven, not just claimed.
Supply chain & EU CRA
SBOM (CycloneDX), signed APT updates, a CVE feed (OSV/Debian) and automatic security updates — including a CRA cockpit for EU Cyber Resilience Act evidence.
See SSL issues before the customer calls.
The TLS health dashboard detects SAN drift, survives Let's Encrypt rate limits with exponential backoff and live-probes every certificate against the real endpoint.
SAN drift detection
When DNS records and certificate SANs drift apart, the panel shows +N missing and −N orphan domains — with one-click reissue.
Live probe of every cert
Wrong cert served or TLS handshake broken? Visible immediately — before the end user notices.
Rate-limit backoff
Exponential wait (1 → 2 → 4 → 24 h) plus per-site advisory lock prevent Let's Encrypt bans on reissue storms. Triple-layered ACME safety.
Complete email hosting — with modern anti-spam
Postfix + Dovecot + rspamd — professional deliverability and spam protection, included in every plan.
Mailboxes & webmail
Mailboxes, aliases, forwarders, distribution lists, catch-all and autoresponders. SOGo webmail with groupware (calendars & contacts) and IMAP migration of existing mailboxes — on Postfix + Dovecot.
Anti-spam & blocklists
Modern spam protection with rspamd: RBL/URIBL blocklists, greylisting and rate limiting — no surcharge, in every plan.
Deliverability & security
DKIM, SPF/SRS, DMARC and ARC sealing — set up via wizard, plus SSL for mail. Emails land in the inbox, not in spam.
Extend your panel with extensions
Install additional features with one click — right from the panel.
Container Hosting (Docker)
Containers per website — rootless with Podman, isolated and reachable only via the site’s own domain proxy. With package limits and a CVE gate on deploy (Grype). No Docker daemon in the core.
AvailableUptime Monitor
Monitors servers, websites and services around the clock and alerts you in real time on downtime — with history and status right in the panel.
AvailableExtension SDK
Build your own extensions in Go or as HTTP service — with sidebar entries, settings tabs, dashboard widgets and per-plan permissions.
Developer Guide →Open architecture — new features can be added without core changes.
Works with your billing system
Provisioning modules for popular billing panels — plus a complete REST API for custom integrations.
WHMCS
Automatic account creation, suspension, termination and package changes directly from WHMCS.
FOSSBilling & BoxBilling
One module for both — same server manager interface, full lifecycle automation.
Blesta
Provisioning module for Blesta 5.x/6.x — account creation, suspension and package changes across the full lifecycle.
Manage everything in one place
Customers, websites, domains, email, databases and DNS — in one clear, fast interface.
Documentation, changelog, developer guide.
Frequently asked questions
What is enconf?
Is enconf a Plesk alternative?
Which servers and operating systems are supported?
Can I migrate from Plesk?
How do I install enconf?
curl -fsSL https://get.enconf.com | bash. The script auto-configures web server, PHP, databases, mail server, DNS and all other components.How much does enconf cost?
Is there a REST API?
Your first project online in 5 minutes.
14-day free trial · No credit card · Made in Germany, GDPR-compliant