Skip to main content
Version: 2.0.1

Customize robots.txt and security.txt

How to control search engine crawling and publish a security contact for your panel


Both OpenPanel and OpenAdmin ship with a default robots.txt (blocks all crawlers) and a security.txt (an RFC 9116 file that tells security researchers how to report a vulnerability). Each app serves its own pair of files, and each has its own override location โ€” replacing them is a matter of dropping a file on disk, there's no editor built into either panel's UI.

AppServed atOverride directoryTakes effect
OpenPanelhttps://yourpanel:2083/robots.txt, /security.txt/etc/openpanel/openpanel/static/After restarting the openpanel service
OpenAdminhttps://yourserver:2087/robots.txt, /security.txt/usr/local/admin/Immediately, no restart

OpenPanelโ€‹

Create the file at /etc/openpanel/openpanel/static/robots.txt and/or /etc/openpanel/openpanel/static/security.txt:

nano /etc/openpanel/openpanel/static/robots.txt

The override is only checked once, at startup, so restart the service to apply it:

cd /root && docker compose up -d openpanel

The same directory also holds the CSS/JS overrides โ€” css/custom.css and js/custom.js under /etc/openpanel/openpanel/static/ โ€” if you're customizing one you may want the others too; see Branding & White-Label.

OpenAdminโ€‹

Create the file at /usr/local/admin/robots.txt and/or /usr/local/admin/security.txt:

nano /usr/local/admin/security.txt

Unlike OpenPanel, OpenAdmin checks this directory on every request, so the change is live as soon as you save the file โ€” no restart needed.

The same directory also accepts a custom.css override for OpenAdmin's own interface.

Verifyโ€‹

curl https://yourpanel:2083/robots.txt
curl https://yourpanel:2083/security.txt

Defaultsโ€‹

If no override file exists, both apps fall back to these built-in defaults.

robots.txt โ€” blocks all crawlers:

User-agent: *
Disallow: /

security.txt:

Contact: mailto:[email protected]
Expires: 2030-12-12T11:00:00.000Z
Preferred-Languages: rs, en
Policy: https://github.com/stefanpejcic/OpenPanel/security/policy

Use these as a starting point โ€” at minimum, update Contact and Policy to point at your own security reporting process before publishing your own security.txt.