Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

CorePanel - a safe and modern web hosting control panel

2»

Comments

  • cloudblastcloudblast Member, Patron Provider

    looks severely vibe coded, which models you guys even use to take out things like that?

    I believe the newer ones like opus 5.5 or grok 4.7 don't even produce things like those

    Thanked by 1zejjnt
  • MikeAMikeA Patron Provider, Veteran

    What is the benefit of your custom web server compared to Nginx + WAF or LiteSpeed? Does it support all htaccess options for Apache?

  • @MikeA said: What is the benefit of your custom web server compared to Nginx + WAF or LiteSpeed?

    Claude said it was faster, that's why

    Thanked by 2forest zejjnt
  • plmplm Member, Patron Provider

    @matheny said:

    @plm said: the web server is ours too

    but.... why?

    CoreHTTPd was launched eight years ago under the name PxShield and has served more than 800,000 domains to date. We designed it from the ground up to feature a native WAF, native Early Hints, and native WebP image conversion. Additionally, we introduced .htaccess compatibility over the past year.

    Why:
    https://www.corepanel.net/corehttpd
    https://www.corepanel.net/blog/we-had-to-build-our-own-web-server
    https://www.corepanel.net/blog/we-measured-the-page-cache

  • plmplm Member, Patron Provider
    edited September 29

    @MikeA said:
    What is the benefit of your custom web server compared to Nginx + WAF or LiteSpeed? Does it support all htaccess options for Apache?

    CoreHttpd isn't new. It has been in production for eight years with the name "PxShield". The main difference is that security, caching and .htaccess handling are built into the server itself, not added as separate layers.

    vs Nginx + WAF:

    • Your .htaccess files keep working. Nginx ignores them, so every site migrated from cPanel needs its rules rewritten by hand. CoreHttpd reads them directly.
    • The WAF is part of the server, not a module next to it. There's no ModSecurity build or rule set to keep in sync. SQLi/XSS blocking is on in every edition, including the free one.
    • No vhosts and no certbot. Adding a domain in the panel is the whole job. Certificates are issued and renewed automatically, and reloads don't drop connections.

    vs LiteSpeed:

    • No separate web server license. It comes with the panel, including the free edition.
    • A page cache without plugins or LSCache (Pro). In our measurements a WordPress page went from 248 ms to 1.6 ms TTFB, and the cache clears when you publish. Sites already using W3TC or WP Super Cache get their cached files served straight from disk, without touching PHP.

    vs all three:

    • It never runs as root. Apache, Nginx and LiteSpeed start as root and then drop privileges. CoreHttpd runs unprivileged from the first instruction, in its own SELinux domain, with no write access to customer files and no PHP in its own process.
    • HTTP/2, HTTP/3, WebP and Early Hints are on by default, with no modules to add.

    Does it support all Apache .htaccess options?

    No, and on purpose. It covers what real sites use: we tested it against a corpus of real .htaccess files from WordPress, WHMCS, PrestaShop, Wordfence and password-protected directories.

    • Supported: mod_rewrite, Allow/Deny/Require, Files/FilesMatch, IfModule, Basic auth with your existing .htpasswd, and Redirect/RedirectMatch.
    • Not applied: Header, ErrorDocument, DirectoryIndex and Expires*. php_value never worked under PHP-FPM anyway.
    • Blocked on purpose: AddHandler can't make an uploaded .gif run as PHP, a classic attack path.

    Nothing is skipped silently. A per-site report shows every line as applied, no effect, not applied (with the reason) or failed. After migrating, you know exactly what changed.

    Docs: https://corepanel.net/docs/web/htaccess

  • @plm, is corepanel security audited by third party?

    Since nobody has posted YABS from your demo server yet, I guess it's secure, but we have seen a lot of panels with really bad security issues, and each month there is providers that advertise here on LET that get hacked.

    If it has been properly audited it will shut up 99% of the critics.

  • @xvps said: If it has been properly audited it will shut up 99% of the critics.

    "Claude, audit this like a professional auditor" does not count, of course.

    Thanked by 3xavcon Obelous zejjnt
  • @xvps said:
    @plm, is corepanel security audited by third party?

    Since nobody has posted YABS from your demo server yet, I guess it's secure, but we have seen a lot of panels with really bad security issues, and each month there is providers that advertise here on LET that get hacked.

    If it has been properly audited it will shut up 99% of the critics.

    The way the panel looks and OP using AI to write its replies, do you really think it has been audited? Pretty sure it was one prompt shot "go make panel and ui" with zero sense of how UI should look, its total slop.

  • plmplm Member, Patron Provider

    @xvps said:
    @plm, is corepanel security audited by third party?

    Not yet. An external audit is planned.

    CorePanel isn't our first security product. At Pyxsoft we've been building security software for years, and the panel is built so that no single hole hands over the server. The panel you log into doesn't run as root. Anything that needs root goes through a separate local service that only accepts a short list of admin tasks, so a bug in the web panel doesn't turn into a root shell. Every account runs PHP as its own user in its own FPM pool, with homes at 0700. A hacked site is blocked from running shell commands, and it can only see its own web files, not the rest of the server, not even its own mail or SSH keys. Behind that, SELinux stays enforcing, while most other panels tell you to turn it off.

    Thanked by 1xvps
  • @plm said: CorePanel isn't our first security product. At Pyxsoft we've been building security software for years

    That's not necessarily a good thing, you know that right?

    Thanked by 1zejjnt
  • MikeAMikeA Patron Provider, Veteran
    edited September 29

    @plm said:

    @MikeA said:
    What is the benefit of your custom web server compared to Nginx + WAF or LiteSpeed? Does it support all htaccess options for Apache?

    CoreHttpd isn't new. It has been in production for eight years with the name "PxShield". The main difference is that security, caching and .htaccess handling are built into the server itself, not added as separate layers.

    vs Nginx + WAF:

    • Your .htaccess files keep working. Nginx ignores them, so every site migrated from cPanel needs its rules rewritten by hand. CoreHttpd reads them directly.
    • The WAF is part of the server, not a module next to it. There's no ModSecurity build or rule set to keep in sync. SQLi/XSS blocking is on in every edition, including the free one.
    • No vhosts and no certbot. Adding a domain in the panel is the whole job. Certificates are issued and renewed automatically, and reloads don't drop connections.

    vs LiteSpeed:

    • No separate web server license. It comes with the panel, including the free edition.
    • A page cache without plugins or LSCache (Pro). In our measurements a WordPress page went from 248 ms to 1.6 ms TTFB, and the cache clears when you publish. Sites already using W3TC or WP Super Cache get their cached files served straight from disk, without touching PHP.

    vs all three:

    • It never runs as root. Apache, Nginx and LiteSpeed start as root and then drop privileges. CoreHttpd runs unprivileged from the first instruction, in its own SELinux domain, with no write access to customer files and no PHP in its own process.
    • HTTP/2, HTTP/3, WebP and Early Hints are on by default, with no modules to add.

    Does it support all Apache .htaccess options?

    No, and on purpose. It covers what real sites use: we tested it against a corpus of real .htaccess files from WordPress, WHMCS, PrestaShop, Wordfence and password-protected directories.

    • Supported: mod_rewrite, Allow/Deny/Require, Files/FilesMatch, IfModule, Basic auth with your existing .htpasswd, and Redirect/RedirectMatch.
    • Not applied: Header, ErrorDocument, DirectoryIndex and Expires*. php_value never worked under PHP-FPM anyway.
    • Blocked on purpose: AddHandler can't make an uploaded .gif run as PHP, a classic attack path.

    Nothing is skipped silently. A per-site report shows every line as applied, no effect, not applied (with the reason) or failed. After migrating, you know exactly what changed.

    Docs: https://corepanel.net/docs/web/htaccess

    I was expecting a real reply, not an AI generated one. That's unfortunate! And your response also has contradictory statements.

    Thanked by 1forest
  • @MikeA said: Nothing is skipped silently.

    Thanked by 1zejjnt
  • plmplm Member, Patron Provider
    edited September 29

    sorry @MikeA, I can explain it easily:

    • LiteSpeed: You pay for it separately and get the same as what you have in CorePanel, free.
    • nginx + WAF: You set something up that you then don’t know how to maintain. You also lose .htaccess

    Regarding .htaccess: It’s compatible, in terms of what it’s actually used for.

  • doghouchdoghouch Member
    edited September 30

    i signed in just to look at the OP’s profile and to have ‘fun’ with the panel (in an isolated environment ofc, his ‘simulated’ demo is a letdown)

    edit: but yes, i agree - don’t run random/untrusted scripts without reading it etc.

    Thanked by 1zejjnt
  • @plm said:
    sorry @MikeA, I can explain it easily:

    • LiteSpeed: You pay for it separately and get the same as what you have in CorePanel, free.
    • nginx + WAF: You set something up that you then don’t know how to maintain. You also lose .htaccess

    Regarding .htaccess: It’s compatible, in terms of what it’s actually used for.

    Limit user same with cloudlinux?
    For ip site can this panel create ip site

    Thanks

  • Logged in the demo. And bam... something went wrong

  • @cloudblast said: I believe the newer ones like opus 5.5 or grok 4.7 don't even produce things like those

    The UI/UX feels similar to GLM.

  • @NameBig said:
    2026 should be declared as the year of the vibe-coded cPanel alternative.

    Its the reason why investors went short in SAAS companies.

    Thanked by 1NameBig
  • TrKTrK Veteran

    I realised I don't hate AI vibe coded fun little projects but can't say same for everything else..... Why would anyone want to discuss anything with anyone relying heavily on AI just to reply....... Sigh....

  • NameBigNameBig Member, Patron Provider
    edited September 30

    @TrK said:
    I realised I don't hate AI vibe coded fun little projects but can't say same for everything else..... Why would anyone want to discuss anything with anyone relying heavily on AI just to reply....... Sigh....

    No serious host will use someone else's vibe coded panel when they can build their own vibe-coded panel, giving them control over their own one.

    I believe that the best approach to sell a web hosting control panel is to start your own hosting brand and use that panel in production, this way the product will have been well tested, and the buyer will have confidence. For example, SPANEL, KEYHELP, STACKCP, and FASTPANEL run web hosting brands with their own panels before introducing web hosting panel to the market.

    ~Vikas

    Thanked by 2AK_KWH zejjnt
  • @NameBig said:

    @TrK said:
    I realised I don't hate AI vibe coded fun little projects but can't say same for everything else..... Why would anyone want to discuss anything with anyone relying heavily on AI just to reply....... Sigh....

    No serious host will use someone else's vibe coded panel when they can build their own vibe-coded panel, giving them control over their own one.

    I believe that the best approach to sell a web hosting control panel is to start your own hosting brand and use that panel in production, this way the product will have been well tested, and the buyer will have confidence. For example, SPANEL, KEYHELP, STACKCP, and FASTPANEL run web hosting brands with their own panels before introducing web hosting panel to the market.

    ~Vikas

    I also doubt any serious host is going to replace a proven setup with some random vibe coded panel just because it looks nice. If they are going to vibe code something anyway, they may as well build around their own infra and requirements.

    Thanked by 1zejjnt
  • xavconxavcon Member

    @itzsenu said:

    @NameBig said:

    @TrK said:
    I realised I don't hate AI vibe coded fun little projects but can't say same for everything else..... Why would anyone want to discuss anything with anyone relying heavily on AI just to reply....... Sigh....

    No serious host will use someone else's vibe coded panel when they can build their own vibe-coded panel, giving them control over their own one.

    I believe that the best approach to sell a web hosting control panel is to start your own hosting brand and use that panel in production, this way the product will have been well tested, and the buyer will have confidence. For example, SPANEL, KEYHELP, STACKCP, and FASTPANEL run web hosting brands with their own panels before introducing web hosting panel to the market.

    ~Vikas

    I also doubt any serious host is going to replace a proven setup with some random vibe coded panel just because it looks nice. If they are going to vibe code something anyway, they may as well build around their own infra and requirements.

    it doesn't even look nice, its a broken ugly piece of slop lol. zero thought went into design

    Thanked by 1zejjnt
  • zejjntzejjnt Member

    @Alyx said:
    Does anyone keep track of all the slop panels released here?

    Yeah; like this

  • itzsenuitzsenu Member
    edited October 1

    @xavcon said: it doesn't even look nice, its a broken ugly piece of slop lol. zero thought went into design

    Who said it looks good? I meant even if it does look good, they’re probably just gonna vibe code it themselves or stick with a well reputed one.

    @zejjnt said: Does anyone keep track of all the slop panels released here?

    Who’s gonna volunteer to make “Code Review Horror Show” or “The Vibe Disaster Archive”?

    Thanked by 2zejjnt rpqu
This discussion has been closed.