Open source · Self-hosted · API-first
Run hosting, servers and billing from one open platform.
QuroPanel gives hosting providers, resellers, developers and customers a shared place to manage servers, websites, domains, email, billing, deployments, security and support.
First production deployment with Hostiquro. Not yet available for general production use.
Manage servers, services, accounts and clusters without mixing root tools into the customer panel.
Give resellers control over customers, packages and branding while keeping provider limits intact.
A familiar hosting workspace for websites, domains, files, mail, databases, backups and security.
Handle products, orders, recurring billing, domains, provisioning and customer accounts in the same resource model.
Build and deploy Laravel, PHP, Node.js, Python, Vue, Nuxt, React and static applications.
Bring firewall events, malware findings, vulnerabilities, Cloudflare and incident actions into one security view.
Why this is being built
Hosting software should not force a bad choice.
Many smaller providers end up choosing between expensive licenses, disconnected free tools or modified copies they cannot safely update. QuroPanel is being built as another option: open code, clear updates and one system that can run on infrastructure you control.
Inspect what you run
The source, dependencies and release history should be visible.
Keep a clean update path
Security fixes should not depend on hiding an unlicensed installation.
Use the parts you need
Start with one server, then add resellers, billing, deployments or a wider cluster without replacing the platform.
Who it is for
Four jobs, one platform.
Hosting providers
Manage servers, packages, customers, billing, security and support without joining several separate systems.
- Fleet and cluster management
- Reseller hierarchy with real limits
- Billing and provisioning in one resource model
- Security findings tied to the affected account
Resellers
Create packages, sell under your own brand and manage customers without gaining access to the provider's root infrastructure.
- Your own logo, colours, domain and invoices
- Package and feature-set control
- Customer billing and support
- Branded native apps
Customers
Files, domains, email, databases, backups and WordPress stay where users expect to find them.
- Familiar hosting tool categories
- WordPress install, staging and updates
- Email with real deliverability status
- Backups you can restore yourself
Developers
Connect a repository, set the environment, create a preview and move a tested release into production.
- Git deployment with preview environments
- Build logs and runtime logs
- Workers, queues and scheduled jobs
- One-click rollback
Product workspaces
One platform. Separate workspaces for separate jobs.
Root operations, reseller management, customer hosting and billing each have real boundaries between them — not one interface with every permission switched on.
QuroAdmin
Server and fleet administration
Manage servers, services, accounts and clusters without mixing root tools into the customer panel.
Explore QuroAdminQuroReseller
Reseller and master reseller management
Give resellers control over customers, packages and branding while keeping provider limits intact.
Explore QuroResellerQuroControl
Customer hosting control panel
A familiar hosting workspace for websites, domains, files, mail, databases, backups and security.
Explore QuroControlQuroCommerce
Billing, orders, domains and provisioning
Handle products, orders, recurring billing, domains, provisioning and customer accounts in the same resource model.
Explore QuroCommerceQuroDeploy
Git deployment, applications and WordPress
Build and deploy Laravel, PHP, Node.js, Python, Vue, Nuxt, React and static applications.
Explore QuroDeployQuroShield
Security, monitoring and incident response
Bring firewall events, malware findings, vulnerabilities, Cloudflare and incident actions into one security view.
Explore QuroShieldQuroSupport
Tickets, knowledgebase and operations
Keep tickets connected to the customer, service, invoice, server and incident that caused the conversation.
Explore QuroSupportFamiliar where it helps
Familiar where it helps. Cleaner where it matters.
Customers already know to look for Files, Domains, Email and Databases in a hosting panel. QuroPanel keeps those categories, but avoids presenting every possible tool as one endless wall of icons.
- Familiar naming kept, with the older term in a tooltip — Domain Aliases, formerly Parked Domains
- A tools view for people who know hosting panels, and a per-site view for people who think in websites
- Tools outside the package are shown disabled with the reason, not hidden
- Search-first tool discovery, with favourites and recents
Order to service
A paid order should become a working service without manual copying.
QuroCommerce and the provisioning engine share the same service records. When an order is approved, the platform creates the account, assigns the package, configures DNS, issues SSL and records every step.
Planned for 0.1 onwards. The provisioning engine, drivers and desired-state reconciliation are specified but not yet built.
QuroDeploy
From repository to a working deployment.
Connect GitHub, GitLab or another repository. Choose a branch, add the required environment values and let QuroPanel build a preview before anything reaches production.
Explore QuroDeployCommit 8f42ab1
✓ Repository downloaded
✓ Dependencies installed
✓ Environment checked
● Building application
○ Security scan
○ Health check
○ Production release
Everything it manages
The modules a hosting operation actually needs.
- Websites and domains
- Subdomains and aliases
- DNS zone editor
- DNSSEC
- SSL and ACME automation
- Wildcard certificates
- File manager
- SFTP and SSH keys
- Git repositories
- MySQL and MariaDB
- PostgreSQL
- Redis
- phpMyAdmin and Adminer
- Mailboxes and forwarders
- Spam filtering
- DKIM, SPF and DMARC
- Webmail
- WordPress toolkit
- Staging and cloning
- One-click app installer
- PHP version per domain
- Node.js and Python
- Laravel deployment
- Background workers
- Cron and scheduled tasks
- Backups and restore testing
- Off-site and immutable backups
- Malware and vulnerability scanning
- WAF and firewall
- Resource metrics
- Access and error logs
- Audit trail
- Packages and feature sets
- Reseller hierarchy
- White-label branding
- Billing and invoicing
- Domain registration
- Payment gateways
- Support tickets
- Knowledgebase
- Public API and webhooks
- CLI and native apps
QuroShield
Security findings should lead to an action.
Firewall decisions, WAF events, malware scans, file changes, vulnerabilities, login activity and Cloudflare protection all point back to the server, account or website they affect.
Built on tools that are already trusted
Rather than inventing a security stack, QuroPanel orchestrates established open-source tooling and keeps the findings in one place.
- nftables, CrowdSec and Coraza with the OWASP Core Rule Set
- ClamAV and YARA for malware and web shells
- Wazuh for file integrity and central events
- Trivy, OSV-Scanner and Gitleaks in the deployment path
- OpenBao for secrets, never the application database
Native applications
Use the browser for the platform. Use native apps when the operating system matters.
The Android, iOS and desktop applications are planned as native tools rather than WebView wrappers, so background transfers, push notifications, biometric approval, live metrics and system tray alerts behave the way the platform expects.
QuroPanel Client
Android, iPhone, iPad — Services, websites, files, domains, email, WordPress, backups and billing, in a task-focused native app.
QuroPanel Reseller
Android, iPhone, iPad — Customers, packages, orders, revenue and branding, with biometric confirmation on high-risk actions.
QuroPanel Ops
Android, iPhone, iPad — A read-first operations and approvals app for administrators, NOC and security staff.
QuroDeploy
Android, iPhone, iPad — Projects, deployments, live build progress, logs and environment variables.
QuroDesk
Windows, macOS, Linux — The full desktop control center: dual-pane file manager, terminal, database tools and local-to-server deployment.
QuroMonitor
Windows, macOS, Linux — NOC wallboard with auto-rotating dashboards, multi-screen layouts and kiosk mode.
QuroSync
Windows, macOS, Linux — Background folder sync with resumable transfers, ignore patterns and conflict detection.
QuroCLI
Windows, macOS, Linux — The `quro` binary: login, deploy, logs, domains, backups and CI/CD mode.
What it runs on
Standard components, managed properly.
QuroPanel does not reinvent the web server, the database or the mail stack. It installs, configures, secures and monitors the software the industry already runs.
Open source
Open source should mean usable, not deliberately incomplete.
The self-hosted core is intended to include what is needed to run a hosting operation. Managed hosting, professional support, migrations and enterprise services can fund the project without adding artificial account limits to the community edition.
Self-hosted
Run it on your own infrastructure, with no phone-home requirement.
Public roadmap
What is planned, what is being built and what is still an idea.
Signed releases
Verified packages with an SBOM, not an unsigned archive.
Plugin SDK
Gateways, registrars, drivers and integrations as extensions.
Community translations
Starting with English and Bangla.
No licence server in the core
No hidden check that can disable your installation.
The final licence is expected to be AGPL-3.0 for the core with permissive SDKs, but it is being reviewed before release. Nothing is final until it is published here.
Where the project is
Honest status, updated as it changes.
Product scope frozen across 13 documents
Next milestone: internal alpha
Not ready for production use
First production deployment
Questions
Frequently asked
Is QuroPanel free?
Is QuroPanel ready for production?
Does QuroPanel replace cPanel and WHM?
Does it include billing?
Does QuroPanel provide hosting?
Can I connect Cloudflare?
Will there be mobile and desktop apps?
Can resellers use their own branding?
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy