Open Source Projects
Built by Tuxxin - free to use, open to contributions
Become a Sponsor
Tuxxin's open source projects are built and maintained in our spare time. Your sponsorship helps keep the lights on - enabling faster development, better documentation, and new features.
- Fund active development of iNetPanel
- Support the TiCore PHP framework
- Keep tools free for small businesses
iNetPanel - Hosting Control Panel
A modern, self-hosted hosting control panel for managing domains, SSL, databases, and more.
iNetPanel is Tuxxin's flagship open-source hosting panel - now publicly released. Built on our custom TiCore PHP framework, it provides a clean, fast interface for managing web hosting environments without the bloat of commercial alternatives.
SECURITY (GHSA-mcpc-fxm3-3973, reported by nullsleuth): the setup wizard staged three files for privileged sudo cp in world-writable /tmp under fixed names. A local unprivileged user could pre-create the path as a symlink and have the root cp copy a root-only file into a world-readable destination. All staging moves to /var/lib/inetpanel/staging (owner-only 0700) with unlink-then-O_EXCL writes. Affects fresh installs only; the wizard is locked after setup.
FIXED (#24): MultiPHP could never install any PHP version. The installer pins every version except the panel's own to Pin-Priority -1, which in APT means 'never install' — so 'apt-get install php8.3-fpm' returned 'has no installation candidate' on every fresh install. MultiPHP now lifts the block for the requested version only, for the duration of the run, leaving the pin's real job (stopping phpmyadmin dragging in a second PHP stack) intact.
FIXED: panel_update deleted its own Apache origin config on every nightly run. /etc/cron.d entries do not inherit PATH from /etc/crontab, so apache2ctl and the a2* helpers were unreachable and a failed configtest was misread as 'my config is broken'.
FIXED: per-domain PHP version switching was broken — its pool copy and removal matched no sudoers rule, so the vhost was repointed at an FPM socket that was never created. Now delegated to multiphp_manage.
HARDENING: hosted sites no longer serve dot-files (.git, .env) or directory listings, existing vhosts included. Static-asset cache headers added (conservative: fonts 30d, images 7d, CSS/JS 1h, HTML untouched). Both sudoers writers now validate with visudo before installing, and four unrestricted root grants (sed, usermod, dpkg, apt-get) were removed after verifying each unused. mod_remoteip is configured at install instead of up to a week later. Backup-restore no longer generates shell scripts to run through a wildcard sudo grant.
Public Repositories
View on GitHubSelf-hosted hosting control panel using Cloudflare Zero Trust Tunnels to securely route multiple domains from a single machine, even on a residential ISP without opening firewall ports. Includes SSL, Multi-PHP, DB, DNS, Backups, WireGuard management and more.
A Lightweight, Self-Hosted Dynamic QR Code Tracking & Management System
The official curlhub.sh CLI — a tiny, security-hardened curl wrapper (fail-closed allowlist, forced HTTPS, per-user token auth).
Future home of the WorldIP.io SDK (IP / ASN / range / org lookup, PTR + forward DNS). Coming soon.
Official client SDKs for the Webshot screenshot API — capture any URL as PNG, JPG, WebP, or PDF. JavaScript/TypeScript, Python, PHP.
Lightweight Twilio Voice call router in PHP featuring automatic holiday closures, business hours logic, and voicemail routing.