Get a free website with any plan

See how
APPLICATIONS

Magento 2 admin URL and security

Last updated

IN SHORT

You can find your Magento 2 admin URL in app/etc/env.php or change it using the Magento CLI on your Flashcloud account. Changing the path away from the default admin reduces automated login attacks. Always flush cache and bookmark your new custom URL right away, as Magento does not redirect traffic from the old path.

Your Magento 2 admin panel lives at whatever path you set during installation, typically yourdomain.com/admin unless you changed it. If you're not sure what yours is, check the app/etc/env.php file on your account for the backend => frontName value, or reinstall the admin path with the CLI: bin/magento setup:config:set --backend-frontname="your-custom-path". Renaming it away from the default admin helps reduce automated login attempts.

Finding and changing your admin URL

Magento stores the admin path in app/etc/env.php under the backend array. You can view or edit this file directly through cPanel's File Manager, or over SSH if you have shell access on your plan. To change it safely, use Magento's own CLI command rather than hand-editing the file:

bin/magento setup:config:set --backend-frontname="my-secret-path"
bin/magento cache:flush

Pick something that isn't guessable (not backend, manage, or your domain name). Bookmark the new URL immediately since there's no built-in redirect from the old path once you change it.

PHP version and server stack

Magento 2 is picky about PHP versions, and running the wrong one causes anything from checkout errors to a blank admin screen. Flashcloud's servers run PHP 7.4 through 8.3, with 8.2 as the system default, and you can switch per domain from the PHP Version tile in the portal. If Magento needs a specific version for compatibility with your installed extensions, set it there rather than trying to change it in cPanel.

If you hit upload size limits when installing extensions or media through the admin, that's a separate setting: go into cPanel's MultiPHP INI Editor (under Software) and raise upload_max_filesize and post_max_size for your domain. The PHP Version tile only controls which PHP version runs, not its ini values.

Underneath, requests are served by LiteSpeed rather than nginx. See how we make your site fast for the full breakdown of the caching layers involved.

Locking down admin access

Beyond a non-default URL, a few standard practices matter more for Magento than most CMSes, because the admin panel has direct access to customer and payment data:

  • Use a long, unique admin password, and rotate it if any team member with access leaves.
  • Limit the number of admin accounts and remove ones you no longer need under System > Permissions > All Users in Magento itself.
  • Restrict access at the server level with a password-protected directory on /admin (or whatever you renamed it to) using cPanel's Directory Privacy tool, so even a correct Magento login can't get through without a second, separate password.
  • Keep Magento core and extensions patched. Outdated Magento installs are a common target for automated exploit scans specifically because the admin path and known vulnerabilities are well documented.

If you want to go further, cPanel's IP Blocker in the Security section blocks specific IP addresses from accessing your site entirely.

Malware scanning and firewall

All hosting accounts run Imunify360 as a web application firewall in the background, and the malware scanner lives inside the same Imunify360 tool. These run automatically and don't need Magento-specific configuration, but if you ever see a site flagged or blocked unexpectedly, that's the layer to check first rather than assuming it's a Magento bug.

When to contact support

If you're locked out of the admin panel after a frontname change, can't locate env.php, or suspect the site has been compromised, open a ticket from Support in the portal. Tickets go to real people, not a bot, and if credentials need to change hands securely, use the "Send a password (the safe way)" panel on the ticket form rather than sending anything in plain text over the ticket thread.

Common questions

Where do I find my Magento admin URL if I forgot it?

Check the app/etc/env.php file on your hosting account using cPanel File Manager or SSH. Look for the frontName value inside the backend array to see your active admin path.

Why is my Magento admin panel showing a blank screen?

You are likely running an incompatible PHP version. Change your domain to a supported version between 7.4 and 8.3 using the PHP Version tile in the Flashcloud portal.

How do I change my admin path safely?

Run the bin/magento setup:config:set CLI command with your new frontname rather than editing files manually. Flush the cache immediately afterward, and bookmark the address because Magento does not redirect requests from the old URL.

Why can I not upload extensions or media in the admin panel?

Your upload limits are too low in your PHP configuration. Open cPanel, go to MultiPHP INI Editor under Software, and raise upload_max_filesize and post_max_size for your domain.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.