Available
34 current platform items already represented in the product direction.
PanelConfig development is organized around foundation, PCAdmin, PCUser, PCCLI, API, integrations, installer, documentation, security, polish, and release packaging
34 current platform items already represented in the product direction.
11 active content, trust, documentation, API, PCCLI, and polish priorities.
28 practical operator improvements planned for future releases.
19 items being evaluated carefully before commitment.
Roadmap items show product direction, active priorities, and upcoming platform work.
Provider-side dashboard for reviewing accounts, services, usage indicators, security signals, release state, and operational records from the administrator surface.
Customer-facing dashboard for domains, websites, DNS, email, databases, SSL, files, FTP, backups, cron jobs, logs, and support-oriented hosting tasks.
Operational records are kept around jobs, service events, security events, login history, API requests, file operations, and account activity so teams can review what happened later.
Track multiple servers, nodes, roles, health status, service state, and account placement from a provider-level inventory view.
Introduce node registration, node health, job assignment, and safer multi-node operation once single-server workflows are mature.
Review deeper runtime isolation models for providers that want container, VM, or bare-metal account strategies.
Database and user management for PostgreSQL alongside MySQL, with pgAdmin linking
Database resources, database users, and grants are present for customer hosting and provider review workflows.
Guided installers for popular PHP applications with version tracking per website
Website records, document roots, runtime settings, redirects, subdomains, logs, and application-related records are present in the platform direction.
Subdomain records are available as part of the website and domain workflow for customer hosting operations.
Redirect records are available for common website routing and domain transition workflows.
S3-compatible, SFTP, and FTP remote targets with per-account retention policies
Backup and restore records are available for tracking backup jobs, restore decisions, schedules, and operational backup history.
Add verification records that prove a backup archive exists, can be read, and matches expected account resources.
Add restore previews that show affected files, databases, email, DNS, and account settings before a restore is started.
Provider operators can review and manage users from PCAdmin while preserving role-aware access boundaries.
Hosting account records are available for provider workflows including ownership, status, domains, limits, and related hosting resources.
Package and plan-style records support hosting account limits, product organization, and provider-facing account assignment.
Add a focused reseller management area for reseller accounts, customer ownership, package visibility, and provider oversight.
Build a provider metrics page over existing usage and health records so operators can review pressure trends without searching multiple modules.
Optional isolated runtime profiles per website for teams that want container-level separation
Domain records and DNS zone resources are available across the panel and API foundations for provider and customer workflows.
DNS zones and records are represented as first-class resources so A, MX, TXT, SPF, DKIM, DMARC, and related records can be reviewed and documented.
SSL certificates and SSL order records are available for tracking certificate status, provider information, and operational SSL workflows.
Add guided SSL troubleshooting for DNS mismatch, HTTP challenge failure, rate limits, and expired authorization states.
Email account records are available alongside aliases, forwarders, filters, routing, and authentication records for hosting-provider mail workflows.
SPF, DKIM, and DMARC concepts are represented so providers can document and review mail authentication requirements.
Add better diagnostics for SPF, DKIM, DMARC, MX records, mailbox quota, routing, and service state.
FTP account records are available to support scoped file access and customer file-management workflows.
File operations can be represented as reviewable operational records instead of invisible file actions.
Cron job records are available as part of the customer and provider automation surface.
Job records support background work and auditable operations across tasks that should not run as uncontrolled web requests.
The cli/pc entrypoint provides a server-side command interface for selected read, health, job, SSL, backup, repair, and service workflows.
Expand documentation and internal planning for account, DNS, SSL, backup, service, job, and troubleshooting command coverage.
Add safe PCCLI coverage for creating, inspecting, suspending, unsuspending, package-changing, and reviewing hosting accounts with audit records.
Add PCCLI commands for DNS zone creation, record edits, zone export, and rebuild workflows after validation and audit handling are in place.
Add command coverage for scheduled backups, remote backup queues, verification, restore planning, and storage review.
API tokens and token request records provide the foundation for programmable access and integration workflows.
The current API v1 folder contains many read-oriented JSON resources for accounts, domains, DNS, websites, email, databases, backups, security, services, health, and jobs.
Plan write endpoint behavior, token scope enforcement, idempotency, audit logging, and job handoff before exposing broader mutation endpoints.
Expose carefully scoped account creation, suspension, unsuspension, package changes, and limit updates through the API after permission enforcement is ready.
Expose DNS record creation, update, and deletion through the API with validation, audit logs, and safer error messages.
Expose SSL request, renewal, and retry workflows through queued API operations instead of long-running web requests.
Add a single scope-checking layer for API endpoints so stored token scopes are consistently enforced across resources.
Add idempotency keys for sensitive automation requests so billing systems and deploy scripts can safely retry without duplicating work.
Add outbound webhooks with signing, retry handling, delivery logs, and event filters for automation systems.
Expand OpenAPI output to cover current and future resources with examples, error formats, pagination, and scope requirements.
Security events, login history, firewall rules, IP blocks, WAF rules, malware scan records, and audit logs are represented as provider-reviewable records.
Server-side command handling is structured around allowlisted command patterns instead of arbitrary command input.
The application includes rate-limit helpers used around login and API request flows to reduce repeated abusive attempts.
Form submission flows use CSRF validation helpers to protect state-changing web actions.
Explain authentication, CSRF, prepared statements, audit logs, command allowlists, token handling, file safety, and responsible disclosure without fake certification claims.
Add TOTP-based two-factor authentication with recovery codes and role-aware enforcement for owner and operator accounts.
Add downloadable provider review reports covering failed logins, API activity, high-risk changes, malware findings, and firewall activity.
Review configurable policies for password rules, API token age, failed login response, operator approvals, and high-risk change control.
Under review: a more formal vulnerability reporting workflow, triage notes, and public security update process.
The installer surface and installation records provide a foundation for self-hosted setup, install state, checks, and reinstall safety.
Document first-login, hostname, DNS, firewall, SSL, backup, email, and security checks after installation.
Under review: a controlled update command that can verify package integrity, show release notes, and stop before risky changes.
The documentation portal uses database-backed categories and articles for product, operator, API, and PCCLI guidance.
The blog system supports categorized product and operations writing for providers, agencies, resellers, developers, and server administrators.
Expand beginner-to-advanced guides for PCAdmin, PCUser, PCCLI, API, security, installation, troubleshooting, and provider workflows.
Keep API docs aligned with the actual available endpoint files, token behavior, request logging, and rate limiting so developers can trust the examples.
Document current PCCLI commands separately from planned command families and keep command examples aligned with cli/pc behavior.
Under review: guided walkthroughs for installation, DNS, SSL, email authentication, backup restore, and PCCLI automation.
Changelog records are stored in the database and displayed publicly so releases can be explained with operational detail.
Release audit records provide a place to track packaging and readiness checks before a release is shipped.
Improve package update flow with checks, release notes, rollback notes, and readiness validation before updates are applied.
Public pricing and install pages explain PanelConfig plans, installation direction, and setup expectations.
Public status and security pages exist to explain availability boundaries, incident communication, and security practices with clear trust and communication practices.
Improve changelog, roadmap, status, security, documentation, blog, and API pages so reviewers understand the product maturity and current boundaries.
Show service records and incident history clearly while avoiding fake uptime numbers or external monitoring claims that the code does not support.
Publish a structured roadmap that separates available, in-progress, planned, future, and under-review work.
Add a dedicated PCUser usage page over account, disk, inode, bandwidth, website, email, and backup usage records.
Create an integrations hub for DNS providers, backup targets, security tools, app installers, billing systems, and deployment workflows.
Add provider integration direction for domain verification, zone discovery, and DNS record synchronization.
Add S3-compatible, SFTP, FTP, or provider-specific remote backup destinations with retention controls.
Document and later expose safer account provisioning patterns for WHMCS, HostBill, Blesta, and custom provider portals.
Under review: event export and response workflows for external security tools without sending unnecessary customer data.
Under review: backup provider connectors with destination tests, retention records, and restore validation.
Add DNS troubleshooting helpers that explain authoritative nameservers, resolver delay, stale records, and SSL dependency.
Create historical views for CPU, RAM, disk, load, inode usage, and account pressure so providers can spot issues early.
Create a managed library of hosting templates, website recipes, security baselines, and application profiles.
Add guided onboarding tasks for new providers: install review, hostname, DNS, SSL, packages, first account, backup policy, and security review.
Support per-reseller branding, panel domains, customer-facing identity, and scoped customer ownership where the provider model requires it.
Add exportable audit evidence packs for providers that need customer-facing operational proof without claiming external certification.
Review a provider-managed app catalog with controlled versions, install tasks, updates, and rollback notes.
Review customer-facing analytics for support tickets, failed operations, restore requests, SSL issues, and common self-service friction.
Under review: a safe WHMCS workflow that creates accounts through approved API paths and tracks job outcomes without direct database writes.
Under review: HostBill-oriented provisioning, suspension, unsuspension, and package-change flows using scoped API tokens.
Under review: Blesta-friendly account lifecycle integration with clear error handling and audit visibility.