Features
Every module, by workspace.
This is the full specified feature set. Status is shown honestly — almost everything is planned, because the software is being built now.
Everything below is specified in detail across the project documentation. Nothing here is claimed as shipped — QuroPanel is pre-1.0.
QuroAdmin
Server and fleet administration
Server overview
Planned- Load, CPU, memory, swap, disk and inode use
- Service status, failed services and restart history
- Network throughput and active connections
- RAID and SMART health where the hardware reports it
- Pending updates and reboot-required state
Account functions
Planned- Create, modify, suspend, unsuspend and terminate accounts
- Change package, owner, primary domain or username
- Login as customer, with the original actor kept in the audit log
- Bulk operations and account notes
- Disk, bandwidth and resource limits per account
Services and runtimes
Planned- Nginx, Apache compatibility mode and reverse proxy
- PHP-FPM pools and a PHP version per domain
- Node.js, Python, Ruby, Go and Java runtimes
- MariaDB, MySQL, PostgreSQL and Redis
- Config validation before every reload, never after
Fleet and clusters
Planned- Node roles: web, app, mail, DNS, database, cache, backup
- Drain, cordon and maintenance mode
- Capacity planning and workload placement
- Rolling and canary updates with rollback
QuroReseller
Reseller and master reseller management
Customer management
Planned- Create, suspend, unsuspend and transfer customers
- Change package, reset password, schedule termination
- Customer 360: services, domains, invoices, tickets, usage
- Login as customer with a fully audited session
Packages and feature sets
Planned- Resource limits: disk, inodes, bandwidth, CPU, RAM, I/O
- Feature sets kept separate from resource packages
- Add-ons, upgrade and downgrade paths
- Overselling policy set by the provider, not the reseller
White-label
Planned- Logo, favicon, colours and login screen
- Customer portal domain and support links
- Branded email templates and invoices
- Branded native apps, built from one codebase
Hierarchy
Planned- Provider → master reseller → reseller → customer
- Child resellers within the parent's allocation
- Ownership tree, usage reports and audit history
QuroControl
Customer hosting control panel
Websites and domains
Planned- Addon domains, subdomains, aliases and redirects
- Document roots, wildcard domains and preview URLs
- DNS zone editor with record history and rollback
- SSL status, forced HTTPS and HSTS
Files
Planned- File manager with preview, code editor and search-in-files
- Upload, compress, extract and restore from trash
- SFTP and SSH keys, scoped per directory
- Malware status shown against the file that carries it
Databases
Planned- MySQL, MariaDB and PostgreSQL
- Database wizard, users and per-host access
- phpMyAdmin, Adminer and pgAdmin
- Connection strings, import, export and repair
- Mailboxes, forwarders, aliases and autoresponders
- Filters, spam settings and quarantine
- SPF, DKIM and DMARC status with a deliverability score
- Delivery tracking that names the actual failure reason
QuroCommerce
Billing, orders, domains and provisioning
Catalog and orders
Planned- Products, plan variants and configurable options
- Domain search, transfer or use-an-existing-domain at checkout
- Coupons, tax, multi-currency and terms snapshots
- Idempotent checkout with duplicate-payment prevention
Billing
Planned- Invoices, credit notes, refunds and partial payments
- Wallet balance, proration and upgrade credits
- Dunning ladder, grace periods and late fees
- A transaction ledger, not a single invoice table
Domains
Planned- Register, transfer, renew and auto-renew
- Multiple registrar accounts with TLD-based routing
- Auth codes, WHOIS privacy, DNSSEC and glue records
- Registrar inventory reconciliation
Provisioning
Planned- One queueing path from paid order to working service
- Drivers for QuroPanel, cPanel/WHM, DirectAdmin, Plesk and more
- Desired-state reconciliation that reports configuration drift
- Every action queued, idempotent, retriable and audited
QuroDeploy
Git deployment, applications and WordPress
Deployment
Planned- GitHub, GitLab and Bitbucket, or a plain SSH repository
- Branch environments and preview deployments per commit
- Zero-downtime release with the previous one kept for rollback
- Deployment approvals before anything reaches production
Build
Planned- Framework and package-manager detection
- Locked-dependency installs in an isolated workspace
- Secret and dependency scanning before the release goes live
- Build logs, cache control and failed-build diagnosis
Runtime
Planned- Node, Python, PHP, Go, Java and static sites
- Workers, queues, scheduled jobs and WebSockets
- Health checks that gate the upstream switch
- Rootless containers where isolation matters
WordPress
Planned- Install, import, clone and stage
- Transactional updates: snapshot, update, smoke test, roll back
- Core checksum verification and vulnerability notices
- Object cache, page cache and scheduled backups
QuroShield
Security, monitoring and incident response
Host and edge
Planned- nftables policy generated from structured rules, not raw input
- CrowdSec behaviour detection with firewall remediation
- Coraza WAF running the OWASP Core Rule Set
- Cloudflare WAF, rate limits and origin protection
Detection
Planned- ClamAV and YARA for malware and web shells
- File-integrity monitoring that separates expected deploys from unexplained changes
- Vulnerability scanning across OS packages and dependencies
- Secret scanning before a deployment is allowed through
Response
Planned- Quarantine, block, suspend or revoke straight from a finding
- Automated playbooks with a human approval step
- Incident timeline with the evidence attached
- Post-incident report and corrective actions
Audit
Planned- Immutable audit log: actor, original actor, resource, result
- Impersonation always recorded against the real administrator
- Retention policy and external SIEM delivery
- No passwords or session tokens are ever written to a log
QuroSupport
Tickets, knowledgebase and operations
Helpdesk
Planned- Departments, priority, assignment and followers
- SLA timers with escalation before a breach, not after
- Canned responses, macros, merge and split
- Every ticket linked to its service, domain, invoice and server
Knowledgebase
Planned- Versioned articles with draft, review and publish
- Contextual help surfaced inside the panel
- Public and private articles, reseller-branded
Safe access
Planned- Customer-authorised, time-limited support sessions
- View-only mode and approval-required privileged access
- A reason is required, and the real actor is always recorded
- Secret fields stay masked during impersonation
Operations
Planned- Incident queue, maintenance tasks and migration queue
- Backup, payment and provisioning failure queues
- Public status page updates from the same incident record
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy