Ace-Host™ Guide · Updated 2026

Host WordPress on OpenLiteSpeed + MariaDB, with Free HTTPS

A copy-paste walkthrough from a blank Ubuntu cloud server to a live, secure WordPress site in about 30 minutes, on a stack that leaves a default cPanel/Apache setup behind, with a built-in admin panel.

Need the server first? See Ace-Host cloud servers →
Ubuntu 24.04 ~30 minutes Free Let's Encrypt SSL LiteSpeed Cache + HTTP/3

WordPress runs on roughly two of every five websites on the internet — and the single biggest thing separating a fast one from a slow one is the web server underneath it. This guide uses OpenLiteSpeed, the free, open-source edition of the LiteSpeed web server, paired with MariaDB and a free Let's Encrypt certificate. You'll go from a fresh server to a live, HTTPS-secured WordPress site you fully own.

Every command below is meant to be copied and pasted in order. Alongside each step you'll find a short "why this matters" note — skim past them if you're a veteran, or read them if you want to understand what you're actually doing instead of just pasting blindly.

Why OpenLiteSpeed for WordPress?

Most shared hosting — cPanel included — still runs on stock Apache, often with no full-page cache at all. OpenLiteSpeed wins for WordPress specifically, for four concrete reasons:

  • LiteSpeed Cache (LSCache) — a server-level, full-page cache built into the web server and controlled by the official WordPress plugin. It's dramatically faster than the bolt-on PHP caching plugins bolted onto a default cPanel/Apache setup, because the cache lives in the server itself, not in PHP.
  • HTTP/3 and QUIC, out of the box — the newest, fastest transport protocols are on by default, so visitors on flaky mobile connections still get a snappy site.
  • An event-driven engine that holds thousands of simultaneous connections on modest RAM — unlike Apache's one-process-per-connection model, which is why a stock cPanel box runs out of headroom so much faster.
  • A built-in admin panel, free — the WebAdmin console handles virtual hosts, SSL, PHP settings, and logs from your browser, no config-file editing required. For a single site, that alone covers most of what people pay a cPanel license for.

The short version: for the same hardware, an OpenLiteSpeed + LSCache WordPress site typically serves far more traffic, far faster, than the same site on a default cPanel/Apache setup — at no software cost, and without a cPanel license. That's the whole reason this stack exists.

Before you start

You'll need three things:

  • A cloud server running a fresh Ubuntu 24.04 install (its packaged MariaDB is 10.11, the version WordPress recommends; 22.04 ships 10.6, which reached end of life in July 2026), with root (or sudo) SSH access. 1 GB RAM works for a single site; 2 GB+ is comfortable. An Ace-Host cloud server is an ideal home for this: the hardware under you is ours, built from components we've tested and burned in before production, and so is the network it sits on, routed on our own ASN. Same family owners since 2003.
  • A domain name you control, so you can point it at the server and issue a real SSL certificate.
  • Five minutes of patience. That's it.
1

Point your domain and connect

In your DNS provider, create two A records pointing at your server's public IP address — one for the bare domain and one for www:

DNS records
# Type   Name   Value
A        @      YOUR_SERVER_IP
A        www    YOUR_SERVER_IP

Give DNS a few minutes to propagate, then connect to your server over SSH and bring it fully up to date:

your computer → server
ssh root@YOUR_SERVER_IP
apt update && apt upgrade -y

Why update first? A fresh image is rarely fully patched. Running updates now means every package you install next pulls the current, security-patched version — and you avoid chasing weird bugs later.

2

Install OpenLiteSpeed

OpenLiteSpeed isn't in Ubuntu's default repositories, so add LiteSpeed's official repo, then install the server and start it:

server
wget -O - https://repo.litespeed.sh | sudo bash
apt update
apt install openlitespeed -y
systemctl enable --now lshttpd

Confirm it's running:

server
systemctl status lshttpd --no-pager

Ace-Host tip: OpenLiteSpeed installs to /usr/local/lsws/. Its admin dashboard listens on port 7080 and a default demo site on 8088 — remember those two numbers, you'll use them shortly.

3

Install PHP (the LiteSpeed build)

OpenLiteSpeed uses its own PHP build called LSPHP, which talks to the server over the fast LSAPI protocol instead of PHP-FPM. Install PHP 8.4 plus the modules WordPress wants. Both 8.3 and 8.4 run WordPress fine, but 8.3 left active support at the end of 2025 and its security fixes stop a full year before 8.4's do — on a server you're building today, take the longer runway:

server
apt install lsphp84 lsphp84-common lsphp84-mysql lsphp84-curl \
  lsphp84-imagick lsphp84-opcache lsphp84-intl -y

Why these modules? mysql lets WordPress talk to the database, curl powers updates and API calls, imagick handles image resizing, opcache caches compiled PHP for speed, and intl covers internationalization. Together they also clear WordPress's Site Health warnings, so your dashboard comes up green.

4

Install and secure MariaDB

MariaDB is the open-source database that stores everything WordPress remembers. Install it, start it, then run the built-in hardening wizard:

server
apt install mariadb-server mariadb-client -y
systemctl enable --now mariadb
mysql_secure_installation

When the wizard asks, answer like this: switch to unix_socket auth (or set a root password), then Y to remove anonymous users, Y to disallow remote root login, Y to drop the test database, and Y to reload privileges.

Heads up: say yes to every prompt in the wizard. Each one closes a default hole — anonymous logins, a throwaway test database, remote root access — that attackers actively scan for. Skipping them is the most common way a brand-new database gets compromised.

5

Create the WordPress database

Open the database shell and create a dedicated database and user for this one site. Replace ChangeMe_Strong#Pass with a long random password:

server
mysql -u root -p
MariaDB shell
CREATE DATABASE wordpress DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
CREATE USER 'wp_user'@'localhost' IDENTIFIED BY 'ChangeMe_Strong#Pass';
GRANT ALL PRIVILEGES ON wordpress.* TO 'wp_user'@'localhost';
FLUSH PRIVILEGES;
EXIT;

Why a separate user? Giving WordPress its own user with rights to only its own database is the principle of least privilege. If that one site is ever compromised, the damage is contained to a single database instead of your entire server. Veterans: this is also what lets you host multiple isolated sites cleanly later.

6

Set a password and open the WebAdmin

Set your OpenLiteSpeed dashboard login:

server
/usr/local/lsws/admin/misc/admpass.sh

Before you open that console in a browser, turn on the firewall. Replace YOUR_HOME_IP with your own public IP address:

server
ufw allow OpenSSH
ufw allow 80,443/tcp
ufw allow 443/udp
ufw allow from YOUR_HOME_IP to any port 7080 proto tcp
ufw enable

Why the firewall goes here and not at the end. A fresh server has no firewall, so the moment you set that password, port 7080 is an admin login facing the entire internet. It is also the exact component LiteSpeed's advisory for CVE-2026-31386 (16 March 2026) says to put behind a firewall or a VPN: anyone who reaches that console with valid admin credentials can run commands as the server. Restrict the port first and a guessed password has nothing to knock on. Ports 80 and 443 stay open to everyone — that's your website, and Let's Encrypt needs port 80 in Step 9. The 443/udp line is what lets the HTTP/3 promised above actually reach visitors: OpenLiteSpeed turns QUIC on by default, but QUIC travels over UDP, and a firewall that only opens TCP quietly drops every browser back to HTTP/2.

Now visit https://YOUR_SERVER_IP:7080 and log in with the username and password you just set. Your browser will warn about the certificate on this admin port — that's expected; continue anyway.

Ace-Host tip: the rest of the setup happens in this point-and-click WebAdmin console — no more config-file editing required. If you prefer the command line for everything, every screen here maps to a file under /usr/local/lsws/conf/, but the GUI is faster and harder to typo.

7

Download WordPress and point your site at it

Back in your SSH session, download the latest WordPress into the server's web directory and hand ownership to the web-server user:

server
cd /usr/local/lsws/Example/html
wget https://wordpress.org/latest.tar.gz
tar -xzf latest.tar.gz
chown -R nobody:nogroup wordpress

Then, in the WebAdmin console (port 7080), make two small changes and restart:

  • Virtual Hosts → Example → General: set Document Root to $VH_ROOT/html/wordpress/
  • Listeners → Default → View → Example mapping: add your domain (e.g. yourdomain.com) so the server answers for it on port 80
  • Click the green Graceful Restart button (top right) to apply

What just happened? You told OpenLiteSpeed two things: where your site's files live (the document root) and which domain should serve them (the listener mapping). That's the entire job of a web server in two settings.

Go straight on to Step 8. Once that restart finishes, the WordPress installer is live on your domain, and whoever reaches it first gets to finish it. That can be a stranger who points it at a database of their own. Bots scan for half-finished installs like this one. So do Step 8 now, not after a break. If your domain shows a login screen, or says WordPress or wp-config.php already exists, instead of asking you to choose a language, someone got there first. Stop, and start again on a freshly installed server: anything they uploaded could run on this one.

8

Finish the install in your browser

Open http://yourdomain.com in a browser. WordPress's famous five-minute installer appears. Choose your language, then enter the database details from Step 5:

WordPress installer
Database Name      wordpress
Username           wp_user
Password           ChangeMe_Strong#Pass
Database Host      localhost
Table Prefix       wp_

Pick a site title, create your admin account with a strong, unique password, and click install. You now have a live WordPress site.

Don't reuse a password here. Your WordPress admin login is the single most attacked door on the whole server. Use a long, unique passphrase and, once you're in, add a two-factor authentication plugin. This one habit prevents the overwhelming majority of WordPress break-ins.

9

Turn on free HTTPS with Let's Encrypt

A live site isn't done until it's encrypted. Install Certbot and issue a free certificate for both your domain and its www version:

server
apt install certbot -y
certbot certonly --webroot \
  -w /usr/local/lsws/Example/html/wordpress \
  -d yourdomain.com -d www.yourdomain.com

Certbot saves your certificate to /etc/letsencrypt/live/yourdomain.com/. Now wire it into OpenLiteSpeed in the WebAdmin console:

  • Listeners → Add: create a listener named SSL, Port 443, Secure = Yes, then save and map your domain to the Example virtual host
  • On that listener's SSL tab, set:
OpenLiteSpeed SSL settings
Private Key File    /etc/letsencrypt/live/yourdomain.com/privkey.pem
Certificate File    /etc/letsencrypt/live/yourdomain.com/fullchain.pem

Hit Graceful Restart. Then make HTTPS the default by adding a redirect under Virtual Hosts → Example → Rewrite → Rewrite Rules:

Rewrite rules
RewriteCond %{HTTPS} !on
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]

Let's Encrypt certificates are short-lived by design, and getting shorter, so Certbot renews them automatically. What it won't do on its own is tell OpenLiteSpeed, which keeps serving the old certificate from memory until it restarts. Give Certbot a deploy hook that reloads OpenLiteSpeed after every successful renewal, then rehearse a renewal:

server
printf '#!/bin/sh\n/usr/local/lsws/bin/lswsctrl restart\n' \
  > /etc/letsencrypt/renewal-hooks/deploy/openlitespeed
chmod +x /etc/letsencrypt/renewal-hooks/deploy/openlitespeed
certbot renew --dry-run

Why a file and not a flag? Certbot only remembers options from a renewal that actually happens, and a --dry-run saves nothing and skips deploy hooks. So certbot renew --deploy-hook … --dry-run passes its test and never installs the reload. Certbot runs anything in renewal-hooks/deploy/ on every real renewal.

Ace-Host tip: if your DNS is on Cloudflare, you can instead use acme.sh with the Cloudflare API for fully hands-off DNS-validated certificates — handy if you run several sites. Either way, the certificate is free and trusted by every browser.

10

Switch on speed and lock the doors

This is the payoff step — and the one generic guides skip. In your WordPress dashboard, go to Plugins → Add New, search LiteSpeed Cache, install and activate it. It auto-detects OpenLiteSpeed and turns on server-level full-page caching, image optimization, and HTTP/3 delivery.

Why this matters most: LSCache is the reason you chose this stack. With it active, repeat visitors are served a fully-rendered page straight from the web server, skipping PHP and the database entirely. It's the difference between a site that buckles under a traffic spike and one that shrugs it off.

Finally, one last hardening touch. Your firewall has been up since Step 6 — confirm it still reads the way you left it, with 7080 restricted to your own address:

server
ufw status verbose

Then disable the in-dashboard file editor so a compromised login can't rewrite your site's code — add this line to /usr/local/lsws/Example/html/wordpress/wp-config.php, above the comment that says That's all, stop editing! Don't just append it to the end of the file: the file's last line loads WordPress and every plugin, so a setting pasted after it arrives too late for them:

wp-config.php
define('DISALLOW_FILE_EDIT', true);

WordPress itself ships security releases that matter just as much: CVE-2026-87902, fixed in 7.1.2 in September 2026, was exploited within days. Our security news covers the ones worth acting on.

The one update Ubuntu won't do for you. Ubuntu's automatic security updates cover Ubuntu's own packages only. OpenLiteSpeed and LSPHP came from LiteSpeed's repository in Steps 2 and 3, and a repository you add yourself is skipped until you configure it in. That matters: OpenLiteSpeed 1.9.0 (April 2026) fixed remotely exploitable flaws in the HTTP/3 engine your firewall opened 443/udp for. Put a monthly reminder on your calendar to run apt update && apt upgrade -y && systemctl restart lshttpd.

That's it — you're live. You now have a WordPress site running on OpenLiteSpeed + MariaDB, encrypted with a free auto-renewing certificate, accelerated by LSCache and HTTP/3, behind a firewall.
  • Server: OpenLiteSpeed (admin on :7080)
  • Database: MariaDB, least-privilege user
  • HTTPS: Let's Encrypt, auto-renewing
  • Speed: LiteSpeed Cache + QUIC

Prefer point-and-click? The 1-click alternative

Everything above gives you total control — and total responsibility. If you'd rather manage sites, email, DNS, SSL, and backups from a clean dashboard instead of the command line, run your cloud server with the Enhance control panel. It installs the whole stack for you and turns site creation into a few clicks, while you keep the full power of a real server underneath.

$0.15/mo per website
That's the entire control-panel cost.Using our license, the Enhance panel is just 15¢ per month, per website — and like cPanel, that fee never applies to addon or parked domains. For comparison, cPanel's own Solo license — one account, cloud or VPS only — lists at $29.99 a month after its January 2026 increase. One site on Enhance? Fifteen cents.

Enhance gives you a modern dashboard with one-click WordPress installs and migrations, automatic SSL, scheduled backups with one-click restore, DNS management, email, and built-in security — every site in its own container, brute-force protection, and a ModSecurity web application firewall with pre-configured OWASP rules. It's the convenience people love about shared hosting, sitting on top of a server you actually own.

Why a cloud server beats shared hosting

Shared cPanel hosting is affordable because the machine is shared: your site draws from one pool of CPU, memory, and disk alongside every other account on the server, usually on stock Apache with whatever caching the host has configured. For many sites that's the right trade. Many hosts cap each account, but the caps only divide one machine: a busy neighbor — a runaway script, a traffic spike — still shares your disks and database server, and you can't tune the server to fit your site.

A cloud server changes that. The root access is yours, the stack is your call, and on Dedicated CPU plans the cores are reserved for you alone. With Enhance handling the panel for pennies, you give up almost none of the convenience. Here's the honest comparison:

What you getTypical shared hostingCloud server + Enhance
Dedicated CPU coresNo — shared with other accountsYes, on Dedicated CPU plans
Noisy-neighbor riskCapped per account on many hosts; still one shared machineLower — your own server; zero CPU contention on Dedicated CPU
Security isolationAccount-level, shared kernelYour own server: your OS, your root
Root & full controlNoYes
Choose your PHP / stackA PHP version from the host's list; the stack is theirsYour call
Scale up without migratingRe-platform to a new planResize in place
Full-page cachingWhatever the host set upBuilt-in LSCache, tuned by you
Server admin panelPaid cPanel licenseFree WebAdmin, included
Control-panel costBundled (you pay anyway)$0.15/mo per site
Who answers supportFirst tier, then a handoffA real system administrator

The bottom line: for not much more than a serious shared plan, a cloud server gives you a server of your own, real security isolation, and full control — the three things shared hosting structurally can't offer. Add Enhance for 15¢ a site and you keep the easy dashboard too. That's why we build it this way.

Ready to build it? Spin up an Ace-Host cloud server, or talk to a system administrator who will set the whole thing up with you. Paying for a cPanel license somewhere else today? Here is what moving off cPanel involves.

Frequently asked questions

Is OpenLiteSpeed really free?

Yes. OpenLiteSpeed is the free, open-source edition of the LiteSpeed web server, with no license fee and no traffic limits. The LiteSpeed Cache plugin for WordPress is free too. You only pay for the server it runs on.

Is OpenLiteSpeed faster than a typical cPanel/Apache shared host?

For WordPress specifically, usually yes — because of LiteSpeed Cache. LSCache is a server-level full-page cache built into the web server itself, something a default cPanel/Apache setup doesn't have unless someone installs and tunes a caching plugin. On identical hardware, the cached OpenLiteSpeed site typically handles far more concurrent visitors than the same site on stock Apache.

Does OpenLiteSpeed replace cPanel entirely?

Not entirely, but it covers a lot of it. The free WebAdmin console handles virtual hosts, SSL, PHP configuration, and logs — the server-management side cPanel exists for — with no license fee. For a single site, most people don't miss cPanel. If you want cPanel-style conveniences on top — one-click installs, email, DNS, scheduled backups, multi-site management — that's what Enhance is for, at $0.15/month per site instead of a cPanel license.

How much RAM do I need to run WordPress on a cloud server?

A single WordPress site runs comfortably on 1 GB of RAM, and 2 GB gives you headroom for traffic spikes, image processing, and a few plugins. Because OpenLiteSpeed is event-driven and LSCache offloads most requests, you can host more on less than you'd expect.

Do I need a control panel like Enhance or cPanel?

No — this guide sets everything up without one. A panel just makes ongoing management (new sites, SSL, backups, email, DNS) point-and-click instead of command-line. On a cloud server, Enhance does that for $0.15/month per website, with no per-server fee.

Will my Let's Encrypt certificate renew automatically?

Yes. Certbot installs a scheduled renewal that runs in the background, and the deploy hook in Step 9 reloads OpenLiteSpeed so the fresh certificate goes live automatically. You don't have to touch it.

Can I host more than one WordPress site on the same server?

Absolutely. Repeat the database and virtual-host steps for each site, or let Enhance manage multiple isolated sites for you. A single cloud server can comfortably host many WordPress sites — and you keep every one of them on infrastructure you control.

Build It on Infrastructure
That Won't Let You Down.

Run this stack on an Ace-Host cloud server — fast storage, end-to-end redundant power and network, and a real system administrator on every ticket. Add Enhance for $0.15/mo and skip the command line entirely.