New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
CorePanel - a safe and modern web hosting control panel
This discussion has been closed.
Comments
looks severely vibe coded, which models you guys even use to take out things like that?
I believe the newer ones like opus 5.5 or grok 4.7 don't even produce things like those
What is the benefit of your custom web server compared to Nginx + WAF or LiteSpeed? Does it support all htaccess options for Apache?
Claude said it was faster, that's why
CoreHTTPd was launched eight years ago under the name PxShield and has served more than 800,000 domains to date. We designed it from the ground up to feature a native WAF, native Early Hints, and native WebP image conversion. Additionally, we introduced .htaccess compatibility over the past year.
Why:
https://www.corepanel.net/corehttpd
https://www.corepanel.net/blog/we-had-to-build-our-own-web-server
https://www.corepanel.net/blog/we-measured-the-page-cache
CoreHttpd isn't new. It has been in production for eight years with the name "PxShield". The main difference is that security, caching and .htaccess handling are built into the server itself, not added as separate layers.
vs Nginx + WAF:
vs LiteSpeed:
vs all three:
Does it support all Apache .htaccess options?
No, and on purpose. It covers what real sites use: we tested it against a corpus of real .htaccess files from WordPress, WHMCS, PrestaShop, Wordfence and password-protected directories.
Nothing is skipped silently. A per-site report shows every line as applied, no effect, not applied (with the reason) or failed. After migrating, you know exactly what changed.
Docs: https://corepanel.net/docs/web/htaccess
@plm, is corepanel security audited by third party?
Since nobody has posted YABS from your demo server yet, I guess it's secure, but we have seen a lot of panels with really bad security issues, and each month there is providers that advertise here on LET that get hacked.
If it has been properly audited it will shut up 99% of the critics.
"Claude, audit this like a professional auditor" does not count, of course.
The way the panel looks and OP using AI to write its replies, do you really think it has been audited? Pretty sure it was one prompt shot "go make panel and ui" with zero sense of how UI should look, its total slop.
Not yet. An external audit is planned.
CorePanel isn't our first security product. At Pyxsoft we've been building security software for years, and the panel is built so that no single hole hands over the server. The panel you log into doesn't run as root. Anything that needs root goes through a separate local service that only accepts a short list of admin tasks, so a bug in the web panel doesn't turn into a root shell. Every account runs PHP as its own user in its own FPM pool, with homes at 0700. A hacked site is blocked from running shell commands, and it can only see its own web files, not the rest of the server, not even its own mail or SSH keys. Behind that, SELinux stays enforcing, while most other panels tell you to turn it off.
That's not necessarily a good thing, you know that right?
I was expecting a real reply, not an AI generated one. That's unfortunate! And your response also has contradictory statements.
sorry @MikeA, I can explain it easily:
Regarding .htaccess: It’s compatible, in terms of what it’s actually used for.
i signed in just to look at the OP’s profile and to have ‘fun’ with the panel (in an isolated environment ofc, his ‘simulated’ demo is a letdown)
edit: but yes, i agree - don’t run random/untrusted scripts without reading it etc.
Limit user same with cloudlinux?
For ip site can this panel create ip site
Thanks
Logged in the demo. And bam... something went wrong
The UI/UX feels similar to GLM.
Its the reason why investors went short in SAAS companies.
I realised I don't hate AI vibe coded fun little projects but can't say same for everything else..... Why would anyone want to discuss anything with anyone relying heavily on AI just to reply....... Sigh....
No serious host will use someone else's vibe coded panel when they can build their own vibe-coded panel, giving them control over their own one.
I believe that the best approach to sell a web hosting control panel is to start your own hosting brand and use that panel in production, this way the product will have been well tested, and the buyer will have confidence. For example, SPANEL, KEYHELP, STACKCP, and FASTPANEL run web hosting brands with their own panels before introducing web hosting panel to the market.
~Vikas
I also doubt any serious host is going to replace a proven setup with some random vibe coded panel just because it looks nice. If they are going to vibe code something anyway, they may as well build around their own infra and requirements.
it doesn't even look nice, its a broken ugly piece of slop lol. zero thought went into design
Yeah; like this

Who said it looks good? I meant even if it does look good, they’re probably just gonna vibe code it themselves or stick with a well reputed one.
Who’s gonna volunteer to make “Code Review Horror Show” or “The Vibe Disaster Archive”?