NodePanel.io

Apply security updates to your servers and sites automatically.

NodePanel installs operating system security updates on each server it manages. Twice a day it also upgrades the web stack and patches vulnerable dependencies in your Git-deployed sites. Every run is reported in the panel.

Start your 7-day trial

Card required. Nothing charged until the trial ends.

Example update noticesAutomatic updates enabled

client-web-01

Security & Updates
Last security run
Today, 06:12
Reboot required
No
client-web-01Applied 4 OS security updates
Completed
portal.examplePatched 1 vulnerable package
Completed
preview.exampleNo known vulnerable dependencies
No change

A failed run is marked for manual review.

Illustrative example of a NodePanel workflow.

What gets updated

What NodePanel updates, and how.

Each list describes what an automatic run does on a server that has the NodePanel agent.

Operating system security updates

Security patches for the server’s operating system, applied about once a day.

  • Installs updates from the operating system’s security channel
  • Uses unattended-upgrades on apt-based systems such as Ubuntu
  • Uses dnf-automatic on dnf-based systems such as AlmaLinux
  • Waits and tries again when another package manager is running
  • Restarts the server when an update requires a reboot

Web stack updates

Newer packages for the software that serves your sites, installed twice a day.

  • Upgrades Nginx, Node.js and npm
  • Upgrades each PHP version installed on the server, with its extensions
  • Upgrades only packages that are already installed
  • Restarts services that are still running the old version

Dependency patches for Git-deployed sites

Known vulnerabilities in a site’s Composer and npm packages, checked twice a day.

  • Runs composer audit and npm audit against the site’s lock files
  • Updates only the packages an advisory flags
  • Leaves a site with no advisories untouched
  • Restores the previous lock file if the update fails or a Laravel app no longer starts
  • Reports npm packages that need a major version change instead of forcing them
  • Never runs database migrations

In practice

See what was updated and what needs your attention.

The updates run without you. The panel records each run, so you can check the result and deal with a run that failed.

  1. Check a server’s update status

    Open the server’s overview and read the Security & Updates panel. It shows whether automatic updates are enabled, when the last security run finished, whether a reboot is pending and the last update error.

  2. Read the update notices

    Each run adds a notice to the bell in the panel and an entry in the activity log. The notice says what was applied, such as the number of vulnerable packages patched on a site. A failed run is marked for manual review.

  3. Update WordPress from its own page

    WordPress sites update through WordPress. On a site’s WordPress page, switch automatic core updates on or off, and update core, plugins or themes when you choose. You can also check the core files against the WordPress.org checksums.

Try NodePanel

Start with one server.

Connect a server, then check its Security & Updates panel after the first update run.

Start your 7-day trial

Card required. Nothing charged until the trial ends.