Feature Suggestions

Please provide here your suggestion for new functionality for Plesk. We encourage you to review and vote for suggestions of others. The top-ranked suggestions are likely to be included in the next versions of Plesk.

Please write in English so that voters from all over the world can read and support your request.

For technical assistance, contact Plesk support
For questions, bug reports, discussions and free assistance, check our Forum, Google+ community and Facebook page
For additional information, see Documentation and Knowledge Base
Follow us on Twitter for more news on Plesk development

Off-topic posts will be removed from here

I suggest you ...

(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. 155 votes
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      I agree to the terms of service
      Signed in as (Sign out)

      We’ll send you updates on this idea

      21 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
    • Block the IP of the selected country in Firewall

      Firewall should be able to block the IP of the selected country. I have a lot of traffic from the IP 5.10. *. *

      148 votes
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service
        Signed in as (Sign out)

        We’ll send you updates on this idea

        14 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
      • Add subdomains in one Let's Encrypt certificate

        Add subdomains to one Let's Encrypt certificate.

        Why?

        Because Let's Encrypt has currently limit 5 certificates / 7 days on one domain.

        Example: in one Let's Encrypt cerftificate will be this DNS names: example.com; www.example.com; sub1.example.com; sub2.example.com

        I think it will be helpful if you can simply add your own domains and subdomains in Let's Encrypt Certificate.

        Thanks!

        121 votes
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service
          Signed in as (Sign out)

          We’ll send you updates on this idea

          14 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
        • Maldet for linux inside Plesk

          Hello,

          is better if such as "wordpress toolkit" you implement this software in plesk https://www.rfxn.com/projects/linux-malware-detect/ + ClamAV (is more faster the maildect search).

          With this way, anyone can scan our website from malware. And after scan, the user need to have an notify via email or directly into plesk. This inscrease the security of website and also increase the plesk security.

          I use it somethimes for scan all website into our web hosting, and I found it very usefull for prevent serius problem of botnet, hacked website etc.

          I hope that you can consider to implement this function.

          Regards

          79 votes
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service
            Signed in as (Sign out)

            We’ll send you updates on this idea

            3 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
          • SAN support in Plesk Let's Encrypt

            If you have a lot of subdomains, you may want to combine them into a single certificate, up to a limit of 100 Names per Certificate. Combined with the above limit, that means you can issue certificates containing up to 2,000 unique subdomains per week. A certificate with multiple names is often called a SAN certificate, or sometimes a UCC certificate.

            letsencrypt allow this as mentioned on https://letsencrypt.org/docs/rate-limits/

            Plesk team should implement this feature as soon as possible

            72 votes
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service
              Signed in as (Sign out)

              We’ll send you updates on this idea

              14 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
            • Windows Fail2Ban

              The new security option for plesk 12 is Fail2Ban, but it is only for Linux version.

              There is an opensorce for windows.

              http://www.digitalruby.com/securing-...icated-server/

              I suggest to Parallels Team include this.

              43 votes
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service
                Signed in as (Sign out)

                We’ll send you updates on this idea

                open discussion  ·  7 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
              • Yubikey

                Add two-factor-auth for YubiKey.

                43 votes
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service
                  Signed in as (Sign out)

                  We’ll send you updates on this idea

                  7 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                • Create daily md5-hashes of the web-content of a domain, to quickly identify tampering or hacking.

                  Let Plesk on every night optionally create/compare md5-hashes from all files in the domains storage-space (web,httpdoc,ftp) and update this in a simple list (database), sortable by date of last change, size, number of changes. Indicating "changed files in the last xx days" to have a time-window to drill down.

                  In addition, accumulate all vhosts together into a seperate "Admin-View", where ALL domains are put together alphabetically.

                  Add an additional button "snapshot", so one could create a list of all webfiles on request. For example, when an incident has been cleaned, then click "snapshot" and then wait some time to see…

                  33 votes
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service
                    Signed in as (Sign out)

                    We’ll send you updates on this idea

                    3 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                  • change password next login

                    Ask user to change password at next login screen after reset.
                    We the providers could generate a temp password (customer asks for a reset), and after the first login screen, plesk will force ask from the client to change our temp password.

                    30 votes
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service
                      Signed in as (Sign out)

                      We’ll send you updates on this idea

                      2 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                    • Fail2ban setting findtime per Jail

                      In Fail2ban (great idea to include it in plesk!) settings you can set "Time interval for detection of subsequent attacks" (findtime) in general. But it would be interesting this setting per Jail.
                      Why?
                      you could have 2 jail with same filter but different findtime. Example:
                      Jail 1) 5 failures in 600 seconds: 1800 seconds ban
                      Jail 2) 30 failures in 86400 seconds: 604800 seconds ban

                      There are bots that detect if you have some protection fail2ban or similar and it will adapt, login attempt every 300 seconds for example. Jail 1 no detect this attack, but Jail 2 yes.

                      28 votes
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service
                        Signed in as (Sign out)

                        We’ll send you updates on this idea

                        open discussion  ·  7 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                      • Support HPKP

                        I'd like to see HPKP integrated into the SSL certificate management of Plesk. This would allow, in combination with standard Nginx/Apache config, for a strongly recommended and worthwhile security element to be added to hosted sites.

                        Testing tool
                        https://securityheaders.io

                        More info
                        https://scotthelme.co.uk/hpkp-http-public-key-pinning/

                        24 votes
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service
                          Signed in as (Sign out)

                          We’ll send you updates on this idea

                          1 comment  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                        • DDOS Protection

                          What about DDOS Protection in Plesk?

                          24 votes
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service
                            Signed in as (Sign out)

                            We’ll send you updates on this idea

                            4 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                          • Temporary FTP accounts (with expire date)

                            It would be great to have ftp account with an expire date.
                            A sort of temporary ftp accounts.

                            This becomes really usefull when you need to share your ftp details temporary with a webdeveloper, or somebody else to maintain of check an website.

                            I always make a new FTP account for this sort of events, but then forget to delete them. It would be real nice if you could set a expire date that the account automaticly blocks itself after that date is past.

                            24 votes
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service
                              Signed in as (Sign out)

                              We’ll send you updates on this idea

                              2 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                            • fail2ban now supports IPv6 - please upgrade

                              At some time you closed the request "fail2ban for IPv6" stating that fail2ban does not support it. That was no doubt correct at the time - but now it does, see https://github.com/fail2ban/fail2ban/tree/0.10

                              I'm seeing a lot of warnings in the fail2ban log on my dual stack servers, like this:

                              66:1000:b01c:10ab:0:1: [Errno -9] Address family for hostname not supported

                              and my log checking software is complaining to me about the overly long fail2ban log.

                              See also: https://ctrl.blog/entry/fail2ban-ipv6

                              Thanks! Tim.

                              20 votes
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service
                                Signed in as (Sign out)

                                We’ll send you updates on this idea

                                3 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                              • Update nginx with a newer version of openSSL

                                Update nginx to be linked against a more recent version of openssl, so that TLSv1.2 and mmore secure cipher suites are supported

                                19 votes
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service
                                  Signed in as (Sign out)

                                  We’ll send you updates on this idea

                                  0 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                • Naxsi - web application firewall for Nginx

                                  Naxsi is an open source, high performance, low rules maintenance, Web Application Firewall module for Nginx

                                  https://code.google.com/p/naxsi/

                                  18 votes
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service
                                    Signed in as (Sign out)

                                    We’ll send you updates on this idea

                                    0 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Add extra detail to Fail2Ban

                                    I was just looking at the banned ip addresses on my server and thought it would be nice to have a time and date stamp listed next to the banned ip and jail used.

                                    And maybe add log sizes for the Fail2Ban logs.

                                    Kind regards

                                    Lloyd

                                    14 votes
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service
                                      Signed in as (Sign out)

                                      We’ll send you updates on this idea

                                      3 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Possibility to force SSL on Webmail

                                      Some users don't know why they should enter https:// if they have to access webmail, they use http://
                                      http is insecure. Easpecially in combination with unencrypted wireless connections.
                                      Actually you have to go into the plesk code to set this function somewhere. Why does plesk provide the webmail-login insecure by default?
                                      If you have setup an Domain Certificate, at least then plesk should offer the option to force ssl on accessing webmail.mydomain.??

                                      12 votes
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service
                                        Signed in as (Sign out)

                                        We’ll send you updates on this idea

                                        1 comment  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                      • Add ip manually to fail2ban

                                        It is not possible to add an ip manually to fail2ban trough Plesk interface. Sometimes you detect an offending ip address which you want to ban from your system, before it is detected by recidive rule.

                                        12 votes
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service
                                          Signed in as (Sign out)

                                          We’ll send you updates on this idea

                                          1 comment  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Allow Let's Encrypt to validate over 80 or 443 (not just 80)

                                          We're very excited to see Let's Encrypt in Plesk 17, it makes secure sites much, much easier. However, port 80 is not open on a number of our servers for security reasons and it would appear the Plesk coding for the API to Let's Encrypt forces the use of port 80. Let's Encrypt supports validation of domains over 80 OR 443, but Plesk is requiring 80. The only workaround is to open 80 to the world so it can be validated since Let's Encrypt does supply a list of public IP's their traffic could source from.

                                          12 votes
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service
                                            Signed in as (Sign out)

                                            We’ll send you updates on this idea

                                            0 comments  ·  Security  ·  Flag idea as inappropriate…  ·  Admin →
                                          ← Previous 1 3 4 5 6
                                          • Don't see your idea?

                                          Feedback and Knowledge Base