In development

QuroPanel is under active development. Follow the roadmap and join the first public testing group.

QuroPanel
Follow development

Open source · Self-hosted · API-first

Run hosting, servers and billing from one open platform.

QuroPanel gives hosting providers, resellers, developers and customers a shared place to manage servers, websites, domains, email, billing, deployments, security and support.

First production deployment with Hostiquro. Not yet available for general production use.

Manage servers, services, accounts and clusters without mixing root tools into the customer panel.

Why this is being built

Hosting software should not force a bad choice.

Many smaller providers end up choosing between expensive licenses, disconnected free tools or modified copies they cannot safely update. QuroPanel is being built as another option: open code, clear updates and one system that can run on infrastructure you control.

Inspect what you run

The source, dependencies and release history should be visible.

Keep a clean update path

Security fixes should not depend on hiding an unlicensed installation.

Use the parts you need

Start with one server, then add resellers, billing, deployments or a wider cluster without replacing the platform.

Who it is for

Four jobs, one platform.

Hosting providers

Manage servers, packages, customers, billing, security and support without joining several separate systems.

  • Fleet and cluster management
  • Reseller hierarchy with real limits
  • Billing and provisioning in one resource model
  • Security findings tied to the affected account

Familiar where it helps

Familiar where it helps. Cleaner where it matters.

Customers already know to look for Files, Domains, Email and Databases in a hosting panel. QuroPanel keeps those categories, but avoids presenting every possible tool as one endless wall of icons.

  • Familiar naming kept, with the older term in a tooltip — Domain Aliases, formerly Parked Domains
  • A tools view for people who know hosting panels, and a per-site view for people who think in websites
  • Tools outside the package are shown disabled with the reason, not hidden
  • Search-first tool discovery, with favourites and recents

Order to service

A paid order should become a working service without manual copying.

QuroCommerce and the provisioning engine share the same service records. When an order is approved, the platform creates the account, assigns the package, configures DNS, issues SSL and records every step.

1Order
2Payment
3Risk check
4Server selection
5Account created
6DNS
7SSL
8Backup
9Customer access

Planned for 0.1 onwards. The provisioning engine, drivers and desired-state reconciliation are specified but not yet built.

QuroDeploy

From repository to a working deployment.

Connect GitHub, GitLab or another repository. Choose a branch, add the required environment values and let QuroPanel build a preview before anything reaches production.

Explore QuroDeploy
Commit 8f42ab1
 Repository downloaded
 Dependencies installed
 Environment checked
 Building application
 Security scan
 Health check
 Production release

Everything it manages

The modules a hosting operation actually needs.

  • Websites and domains
  • Subdomains and aliases
  • DNS zone editor
  • DNSSEC
  • SSL and ACME automation
  • Wildcard certificates
  • File manager
  • SFTP and SSH keys
  • Git repositories
  • MySQL and MariaDB
  • PostgreSQL
  • Redis
  • phpMyAdmin and Adminer
  • Mailboxes and forwarders
  • Spam filtering
  • DKIM, SPF and DMARC
  • Webmail
  • WordPress toolkit
  • Staging and cloning
  • One-click app installer
  • PHP version per domain
  • Node.js and Python
  • Laravel deployment
  • Background workers
  • Cron and scheduled tasks
  • Backups and restore testing
  • Off-site and immutable backups
  • Malware and vulnerability scanning
  • WAF and firewall
  • Resource metrics
  • Access and error logs
  • Audit trail
  • Packages and feature sets
  • Reseller hierarchy
  • White-label branding
  • Billing and invoicing
  • Domain registration
  • Payment gateways
  • Support tickets
  • Knowledgebase
  • Public API and webhooks
  • CLI and native apps

QuroShield

Security findings should lead to an action.

Firewall decisions, WAF events, malware scans, file changes, vulnerabilities, login activity and Cloudflare protection all point back to the server, account or website they affect.

Suspicious upload
Scan
Quarantine
Protect site
Create incident
Notify owner
Restore clean version
View the security architecture

Built on tools that are already trusted

Rather than inventing a security stack, QuroPanel orchestrates established open-source tooling and keeps the findings in one place.

  • nftables, CrowdSec and Coraza with the OWASP Core Rule Set
  • ClamAV and YARA for malware and web shells
  • Wazuh for file integrity and central events
  • Trivy, OSV-Scanner and Gitleaks in the deployment path
  • OpenBao for secrets, never the application database

Native applications

Use the browser for the platform. Use native apps when the operating system matters.

The Android, iOS and desktop applications are planned as native tools rather than WebView wrappers, so background transfers, push notifications, biometric approval, live metrics and system tray alerts behave the way the platform expects.

QuroPanel Client

Android, iPhone, iPad — Services, websites, files, domains, email, WordPress, backups and billing, in a task-focused native app.

QuroPanel Reseller

Android, iPhone, iPad — Customers, packages, orders, revenue and branding, with biometric confirmation on high-risk actions.

QuroPanel Ops

Android, iPhone, iPad — A read-first operations and approvals app for administrators, NOC and security staff.

QuroDeploy

Android, iPhone, iPad — Projects, deployments, live build progress, logs and environment variables.

QuroDesk

Windows, macOS, Linux — The full desktop control center: dual-pane file manager, terminal, database tools and local-to-server deployment.

QuroMonitor

Windows, macOS, Linux — NOC wallboard with auto-rotating dashboards, multi-screen layouts and kiosk mode.

QuroSync

Windows, macOS, Linux — Background folder sync with resumable transfers, ignore patterns and conflict detection.

QuroCLI

Windows, macOS, Linux — The `quro` binary: login, deploy, logs, domains, backups and CI/CD mode.

See all 14 applications

What it runs on

Standard components, managed properly.

QuroPanel does not reinvent the web server, the database or the mail stack. It installs, configures, secures and monitors the software the industry already runs.

Nginx
Apache
PHP
MariaDB
PostgreSQL
Redis
Node.js
Python
Docker
Podman
WordPress
Laravel
Git
Cloudflare
Let's Encrypt
Ubuntu
Linux
Prometheus

Open source

Open source should mean usable, not deliberately incomplete.

The self-hosted core is intended to include what is needed to run a hosting operation. Managed hosting, professional support, migrations and enterprise services can fund the project without adding artificial account limits to the community edition.

Self-hosted

Run it on your own infrastructure, with no phone-home requirement.

Public roadmap

What is planned, what is being built and what is still an idea.

Signed releases

Verified packages with an SBOM, not an unsigned archive.

Plugin SDK

Gateways, registrars, drivers and integrations as extensions.

Community translations

Starting with English and Bangla.

No licence server in the core

No hidden check that can disable your installation.

The final licence is expected to be AGPL-3.0 for the core with permissive SDKs, but it is being reviewed before release. Nothing is final until it is published here.

Where the project is

Honest status, updated as it changes.

Specified

Product scope frozen across 13 documents

0.1

Next milestone: internal alpha

Pre-1.0

Not ready for production use

Hostiquro

First production deployment

Questions

Frequently asked

Is QuroPanel free?
QuroPanel is being developed as an open-source, self-hosted platform. Final licensing and release terms will be published before the first public build.
Is QuroPanel ready for production?
Not yet. The project is under active development and will first be tested with Hostiquro. This site labels alpha, beta and stable releases as they happen, and it will not describe QuroPanel as production-ready before it is.
Does QuroPanel replace cPanel and WHM?
That is the long-term scope. QuroPanel keeps server administration, reseller and customer work in separate workspaces rather than combining every permission in one interface.
Does it include billing?
QuroCommerce is planned to cover products, orders, invoices, recurring services, domains, payments, provisioning and customer management — in the same resource model as the hosting side, not as a bolted-on second system.
Does QuroPanel provide hosting?
No. QuroPanel is software. Hostiquro is a hosting provider that will use it, and will be its first production deployment.
Can I connect Cloudflare?
Multi-account Cloudflare integration is part of the platform plan, including OAuth, zone mapping, DNS, SSL, cache and security controls — without sharing a global API key.
Will there be mobile and desktop apps?
Yes. The planned ecosystem includes native Android, iOS, Windows, macOS and Linux applications, plus a CLI and a server agent. They are native builds rather than WebView wrappers.
Can resellers use their own branding?
QuroReseller is designed for custom logos, colours, domains, email templates, invoices and customer applications, within limits the provider defines.

Follow the build

The roadmap shows what is specified, what is being built and what is still only planned.

View the roadmap

Contribute

Drivers, integrations, translations and documentation are all places to start.

How to contribute

Report a security issue

Responsible disclosure, with a stated response commitment.

Disclosure policy