A default PlayTube deployment ships with sensible defaults for a controlled environment, but the moment it goes live on a public domain it inherits a set of predictable weaknesses. The most common problems reported to our support desk are an exposed config.php file containing plaintext database credentials, world-readable permissions left over from an FTP upload, a login page with no rate limiting, and a complete absence of HTTP security headers. None of these require a compromised server to exploit — they are reachable by anyone who knows the script structure, and PlayTube's directory layout is publicly documented in its CodeCanyon listing.

On Hostiso's managed LiteSpeed stack you operate as an unprivileged hosting user, which actually simplifies hardening: everything below is done through cPanel Jupiter or DirectAdmin Evolution, the File Manager, phpMyAdmin, and .htaccess. You never touch server daemons or global configuration, so there is no risk of breaking neighbouring accounts. The trade-off is that you must lean on per-directory controls rather than firewall rules, and that is exactly where PlayTube's weak points can be closed off.

Protect config.php and fix file permissions

PlayTube stores its database host, username, password, and encryption salts in /assets/init.php (older builds) or /config.php at the document root, depending on version. If this file is ever served as plaintext — which happens when the PHP handler is misassigned, when a .php.bak or .php~ editor backup is left behind, or when a directory listing exposes it — every credential leaks in a single request. The first task is to confirm the file is only ever executed, never displayed.

Open cPanel → File Manager (or DirectAdmin → File Manager), navigate to your PlayTube root under public_html, and enable Show Hidden Files in Settings. Delete any file matching config.php.bak, init.php.save, *.php~, or *.php.orig. These are the artefacts most attackers scan for first.

Next, correct permissions. On CloudLinux the PHP process runs as your own user, so PlayTube does not need loose permissions to write files. Directories should be 755 and PHP files 644. The configuration file itself should be tightened to 600 so only your account's processes can read it. In File Manager, right-click the file, choose Change Permissions, and set it accordingly.

Add a defensive rule to the .htaccess in your document root so the sensitive files can never be requested over HTTP, regardless of handler state:

<FilesMatch "(^config\.php|init\.php|composer\.(json|lock)|\.(bak|save|orig|old|sql|log|ini~)$)">
    Require all denied
</FilesMatch>

# Block editor backups and version control leftovers
RedirectMatch 404 /\.git
RedirectMatch 404 \.(bak|swp|orig)$

# Disable directory browsing
Options -Indexes

The Options -Indexes line stops LiteSpeed from generating an automatic listing when an index file is missing, which otherwise reveals your uploads, themes, and install folder structure. If you still have the PlayTube /install or /upgrade directory present after setup, delete it entirely from File Manager — the installer can rewrite config.php and reset the admin account if reached.

Restrict the admin path and strengthen authentication

PlayTube's control panel lives at /admincp, and its login form has no built-in throttling, which leaves it open to credential stuffing. Because you cannot install a WAF module at the server level, the most effective control is a second authentication layer in front of the directory using cPanel's built-in tooling.

In cPanel Jupiter, open Directory Privacy under the Files section, browse to public_html/admincp, tick Password protect this directory, give it a label, and create a user with a long random password. DirectAdmin users achieve the same result through Password Protected Directories. This forces a browser-level HTTP Basic prompt before the PlayTube login even loads, so automated bots hitting /admincp are rejected before touching PHP.

If your administrative access comes from a fixed IP, you can go further and restrict the panel to that address in an .htaccess placed inside /admincp:

# /public_html/admincp/.htaccess
<RequireAny>
    Require ip 203.0.113.24
</RequireAny>

Replace the sample address with your own; find it via any "what is my IP" lookup. Combine IP allow-listing with Directory Privacy only if your address is genuinely static, otherwise you will lock yourself out.

Inside PlayTube's AdminCP itself, go to Settings → Configuration and enable reCAPTCHA for both login and registration, then supply your Google reCAPTCHA v2 site and secret keys under the relevant fields. Set a strong, unique admin password from Admin → Users and remove any leftover demo or test accounts created during evaluation. Rotate the credentials that were emailed to you during purchase, since those often sit in inboxes for months.

Stop upload and registration abuse

A video platform is an attractive target for spam registrations and malicious uploads. PlayTube writes user content into /upload/ subdirectories, and if PHP execution is allowed there, an attacker who bypasses type checks can drop a webshell. Neutralise that risk by disabling script execution in the upload tree. Place this .htaccess inside /upload:

# /public_html/upload/.htaccess
<FilesMatch "\.(php|php5|php7|phtml|pl|py|cgi|sh)$">
    Require all denied
</FilesMatch>

<IfModule LiteSpeed>
    RemoveHandler .php .phtml
</IfModule>

php_flag engine off

Even if a disguised avatar.php.jpg is renamed, the handler will refuse to run it. On the registration side, open AdminCP → Settings and enable email activation so accounts must confirm before posting, turn on the reCAPTCHA already configured above, and lower the default number of daily uploads and comments per new user. If your build exposes an Anti-Spam or User Limits section, set sensible ceilings there.

You can also cap request size at the account level with a .user.ini in your document root, which the PHP Selector honours on LiteSpeed. This blunts oversized payloads used to exhaust resources while still allowing legitimate videos:

; /public_html/.user.ini
upload_max_filesize = 512M
post_max_size = 520M
max_execution_time = 300
disable_functions = exec,passthru,shell_exec,system,proc_open,popen

The disable_functions line closes the shell primitives that uploaded backdoors rely on. Confirm your legitimate plugins do not need them before applying. Verify the values took effect in cPanel → Select PHP Version → Options, and watch your local error_log in the document root for any function-disabled warnings after deployment.

Add missing HTTP security headers and force HTTPS

PlayTube sends none of the modern browser security headers by default, leaving it exposed to clickjacking, MIME sniffing, and mixed-content downgrades. Add them once in your root .htaccess and every page inherits them:

# Force HTTPS
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]

<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
    Header always set Permissions-Policy "geolocation=(), microphone=()"
</IfModule>

Add the HSTS header only after confirming your SSL certificate is active and every asset loads over HTTPS, since it makes the browser refuse plain HTTP for a full year. Issue a free AutoSSL/Let's Encrypt certificate from cPanel → SSL/TLS Status first. A Content-Security-Policy can also be added, but PlayTube pulls in several third-party players and CDNs, so start in report-only mode and tighten gradually rather than breaking video playback.

After each change, load the site in a private window and confirm playback, uploads, and admin login all still work, then inspect the response headers in your browser's developer tools. The pattern here mirrors the safe, panel-first approach we recommend for other social scripts — see our companion guide on Sngine configuration on shared hosting for the same discipline applied to database and debug settings. Keep a copy of your original .htaccess in File Manager before editing so any misstep is a one-click restore.