Your Magento 2 admin panel lives at whatever path you set during installation, typically yourdomain.com/admin unless you changed it. If you're not sure what yours is, check the app/etc/env.php file on your account for the backend => frontName value, or reinstall the admin path with the CLI: bin/magento setup:config:set --backend-frontname="your-custom-path". Renaming it away from the default admin helps reduce automated login attempts.
Finding and changing your admin URL
Magento stores the admin path in app/etc/env.php under the backend array. You can view or edit this file directly through cPanel's File Manager, or over SSH if you have shell access on your plan. To change it safely, use Magento's own CLI command rather than hand-editing the file:
bin/magento setup:config:set --backend-frontname="my-secret-path" bin/magento cache:flush
Pick something that isn't guessable (not backend, manage, or your domain name). Bookmark the new URL immediately since there's no built-in redirect from the old path once you change it.
PHP version and server stack
Magento 2 is picky about PHP versions, and running the wrong one causes anything from checkout errors to a blank admin screen. Flashcloud's servers run PHP 7.4 through 8.3, with 8.2 as the system default, and you can switch per domain from the PHP Version tile in the portal. If Magento needs a specific version for compatibility with your installed extensions, set it there rather than trying to change it in cPanel.
If you hit upload size limits when installing extensions or media through the admin, that's a separate setting: go into cPanel's MultiPHP INI Editor (under Software) and raise upload_max_filesize and post_max_size for your domain. The PHP Version tile only controls which PHP version runs, not its ini values.
Underneath, requests are served by LiteSpeed rather than nginx. See how we make your site fast for the full breakdown of the caching layers involved.
Locking down admin access
Beyond a non-default URL, a few standard practices matter more for Magento than most CMSes, because the admin panel has direct access to customer and payment data:
- Use a long, unique admin password, and rotate it if any team member with access leaves.
- Limit the number of admin accounts and remove ones you no longer need under System > Permissions > All Users in Magento itself.
- Restrict access at the server level with a password-protected directory on
/admin(or whatever you renamed it to) using cPanel's Directory Privacy tool, so even a correct Magento login can't get through without a second, separate password. - Keep Magento core and extensions patched. Outdated Magento installs are a common target for automated exploit scans specifically because the admin path and known vulnerabilities are well documented.
If you want to go further, cPanel's IP Blocker in the Security section blocks specific IP addresses from accessing your site entirely.
Malware scanning and firewall
All hosting accounts run Imunify360 as a web application firewall in the background, and the malware scanner lives inside the same Imunify360 tool. These run automatically and don't need Magento-specific configuration, but if you ever see a site flagged or blocked unexpectedly, that's the layer to check first rather than assuming it's a Magento bug.
When to contact support
If you're locked out of the admin panel after a frontname change, can't locate env.php, or suspect the site has been compromised, open a ticket from Support in the portal. Tickets go to real people, not a bot, and if credentials need to change hands securely, use the "Send a password (the safe way)" panel on the ticket form rather than sending anything in plain text over the ticket thread.