Roadmap

260 things, and which are done.

Every item KLYRN Web is building to replace cPanel and DirectAdmin. Each one answers something hosts say they hate about the panels they run today, or keeps something they like.

73 shipped, 5 partly there, 182 planned.

Mail hosting is not in V1. Mailboxes stay with your mail provider; see known issues.

What hosts told us, and the answer

Read from forums, review sites and hosting news in September 2026. The complaints repeat; so do the things people would not give up.

What they hateWhat KLYRN does
Licences priced per account, raised every yearOne flat price per server. The Free edition has no account cap.
A stack of extra licences for isolation and speedResource limits, disk quotas and a tuned nginx with PHP-FPM are in the box.
An interface that looks a decade oldA categorised menu, a search that finds any page, both themes, measured contrast.
Skins removed against users’ wishesThe design evolves in place. Same pages, same addresses, no forced switch.
Updates that take production downSigned updates that roll themselves back, with a health check after each one.
Transfers that stall with a vague errorImports that report every site and every step, and name the file when one fails.
Node apps that return 503 and only root can fixEach app runs as its own service, with logs and a restart the customer can use.
Heavy on a small serverOne binary. We will publish the idle memory of every release.
What they likeHow KLYRN keeps it
Customers already know where things areFamiliar names: File Manager, Databases, Cron Jobs, Backups.
One-click WordPress with stagingInstall, clone, staging, health and plugins, built in.
Per-site PHP versionsSeveral PHP versions side by side, one FPM pool each.
The cPanel backup as the common formatKLYRN imports cPanel and DirectAdmin backups directly.
An API to build onA full REST API, scoped tokens and webhooks.

Email

0 of 20 shipped

  1. PlannedMailboxes per domain (Postfix + Dovecot), quota per boxV2
  2. PlannedIMAP, POP3, SMTP submission with TLS on the site's own certificateV2
  3. PlannedWebmail (Roundcube or SnappyMail), branded with the host's logoV2
  4. PlannedDKIM keys generated per domain, published automatically when DNS is oursV2
  5. PlannedSPF and DMARC records suggested and published in one clickV2
  6. PlannedDeliverability checker: SPF, DKIM, DMARC, PTR, blocklists, with the fix beside eachBefore V1
  7. PlannedForwarders and catch-allV2
  8. PlannedAutoresponders with a date rangeV2
  9. PlannedSpam filtering (Rspamd) with per-mailbox sensitivityV2
  10. PlannedPer-site outbound rate limit; a flood pauses that site onlyBefore V1
  11. Partly thereMail queue view with "stop this site's mail" (sitemail*.go has the queue)Before V1
  12. PlannedAutodiscover/autoconfig for Outlook, Thunderbird, iOSV2
  13. PlannedMobile config profile download for iPhoneV2
  14. PlannedEmail filters (Sieve) with a visual editorV2
  15. PlannedMailing-list alias groupsV2
  16. PlannedMailbox import from IMAP (imapsync) in the migration wizardV2
  17. PlannedPer-mailbox storage graph and "largest folders"V2
  18. PlannedRelay through an external smarthost (SES, Mailgun, Postmark)V2
  19. PlannedDisposable aliases for customersV2
  20. PlannedEmail deliverability score on the site homeV2

DNS

2 of 12 shipped

  1. ShippedCloudflare as a DNS provider
  2. ShippedRecord-level access scoping for customers
  3. PlannedBuilt-in authoritative DNS (PowerDNS) for hosts without CloudflareBefore V1
  4. PlannedNameserver pair setup wizard (ns1/ns2 with glue checks)Before V1
  5. PlannedZone templates per packageBefore V1
  6. PlannedDNS cluster across paired serversV1
  7. PlannedDNSSEC signing and DS record displayV1
  8. PlannedZone import from BIND file and from cPanel/DirectAdmin backupsV1
  9. PlannedPropagation checker from several resolversV1
  10. PlannedProviders: Route 53, DigitalOcean, Hetzner, OVH, BunnyV1
  11. PlannedRecord change history with one-click undoAfter V1
  12. Planned"Point my domain here" guide per registrarAfter V1

Sites and web server

6 of 21 shipped

  1. ShippedSite types: static, PHP, WordPress, Node, proxy
  2. ShippedLaunch: see the site before it exists
  3. ShippedStaging copies
  4. ShippedSite preview before DNS points
  5. Shippednginx vhosts with custom rules
  6. Shipped.htaccess converted on import
  7. PlannedAliases and parked domains shown as first-class, with HTTPS eachBefore V1
  8. PlannedSubdomains in one field on the site pageBefore V1
  9. PlannedRedirects editor (301/302, path and whole domain)Before V1
  10. PlannedPassword-protected foldersBefore V1
  11. PlannedCustom error pagesBefore V1
  12. PlannedPer-site page cache (nginx fastcgi_cache) with purge buttonV1
  13. PlannedBrotli and HTTP/3V1
  14. PlannedHotlink protectionV1
  15. PlannedIP allow and deny per siteV1
  16. PlannedMaintenance mode for any site type, not only WordPressV1
  17. Planned.htaccess live translator: paste rules, see nginx resultV1
  18. PlannedOptional Apache backend for sites that need .htaccess at runtimeV1
  19. PlannedVisual traffic map on the site homeAfter V1
  20. PlannedClone a site to another server in one stepAfter V1
  21. PlannedScheduled site snapshots before risky changesAfter V1

PHP

4 of 10 shipped

  1. ShippedSeveral PHP versions side by side
  2. ShippedFPM pool per version
  3. ShippedExtensions per account
  4. ShippedPHP settings presets
  5. Plannedphp.ini editor with safe ranges and plain-language labelsBefore V1
  6. PlannedPHP error log tail on the site pageV1
  7. PlannedOPcache status and resetV1
  8. PlannedUpgrade advisor: which plugins break on the next PHP versionV1
  9. PlannedionCube and SourceGuardian loadersV1
  10. PlannedPer-site slow-request log with the slowest scriptsAfter V1

WordPress

3 of 13 shipped

  1. ShippedInstall with pinned, checksum-verified WP-CLI
  2. ShippedClone, health, maintenance, plugins and themes
  3. ShippedCredentials handover
  4. PlannedSafe updates: snapshot, update, visual check, roll back on breakBefore V1
  5. PlannedBulk update across all sites of an accountBefore V1
  6. PlannedVulnerability feed on installed plugins (WPScan or Patchstack)V1
  7. PlannedSearch and replace for domain changesV1
  8. PlannedPush staging to live, files or database or bothV1
  9. PlannedObject cache (Redis) toggleV1
  10. PlannedLogin as admin from the panel, no password neededV1
  11. PlannedDebug mode toggle with log viewV1
  12. PlannedVisual regression screenshots before and after updatesAfter V1
  13. PlannedWooCommerce-aware backups (orders never rolled back without warning)After V1

Apps and developers

4 of 14 shipped

  1. ShippedNode apps with release folders and rollback
  2. ShippedGit deploy for sites and containers
  3. ShippedContainers and compose, blue-green deploy
  4. ShippedReverse proxy sites
  5. PlannedPython apps (uWSGI or gunicorn) as a first-class typeBefore V1
  6. PlannedRuby, Go and static-build (Vite, Next export) presetsV1
  7. PlannedBuild command and output folder for static sites from gitV1
  8. PlannedDeploy webhooks from GitHub, GitLab, BitbucketV1
  9. PlannedEnvironment variables editor with secrets hiddenV1
  10. PlannedApp catalogue: Ghost, Nextcloud, Laravel, Drupal, Joomla, MatomoV1
  11. PlannedComposer and npm run from the panelV1
  12. PlannedBrowser terminal limited to the accountV1
  13. PlannedPreview deployments per git branchAfter V1
  14. PlannedRedis, Memcached as per-account servicesAfter V1

Databases

4 of 11 shipped

  1. ShippedMariaDB databases and users
  2. ShippedDatabase console
  3. ShippedConnection kit: .env, wp-config, PDO
  4. ShippedTransfer between servers
  5. PlannedphpMyAdmin or Adminer with single sign-on (cPanel users expect it)Before V1
  6. PlannedImport .sql and .sql.gz with progressBefore V1
  7. PlannedRemote access hosts (allow an IP to connect)Before V1
  8. PlannedPostgreSQLV1
  9. PlannedDatabase size per table and slow query viewV1
  10. PlannedOne-click repair and optimiseV1
  11. PlannedPoint-in-time restore from binary logsAfter V1

Files

3 of 10 shipped

  1. ShippedFile manager confined to the account, with history
  2. ShippedUpload, copy, move, search, preview
  3. PlannedFTP and SFTP accounts per site with folder jailBefore V1
  4. PlannedExtract and compress zip and tar in placeBefore V1
  5. PlannedCode editor with syntax highlightingBefore V1
  6. ShippedThe panel's history folder is left out of the file manager
  7. PlannedPermissions editor with plain wordsV1
  8. PlannedDisk usage explorer (treemap)V1
  9. PlannedDrag and drop foldersV1
  10. PlannedShare a file by expiring linkAfter V1

SSL

2 of 7 shipped

  1. ShippedACME certificates
  2. ShippedCertificate health checks
  3. PlannedWildcard certificates through DNS-01Before V1
  4. PlannedUpload a custom certificate with chain checkBefore V1
  5. PlannedExpiry forecast across the estateV1
  6. PlannedHSTS toggle with preload warningV1
  7. PlannedZeroSSL and Google as ACME fallbacksAfter V1

Backups and restore

5 of 13 shipped

  1. ShippedPer-site backups with SHA-256 manifest
  2. ShippedSchedules and retention
  3. ShippedEncrypted remote copies to S3-compatible storage
  4. ShippedRestore verification
  5. ShippedRewind: pick a moment on a timeline and restore
  6. Partly thereRestore scope: files only or databases only (UI shipped, confirm server path)Before V1
  7. PlannedRestore a single file or folderBefore V1
  8. PlannedRestore a single database tableBefore V1
  9. PlannedTargets: SFTP, Google Drive, Dropbox, OneDrive, BackblazeV1
  10. PlannedCustomer-downloadable full backup in cPanel-compatible formatV1
  11. PlannedIncremental backups (restic or borg)V1
  12. PlannedBackup cost estimate per targetV1
  13. PlannedRestore into a new staging site to inspect firstAfter V1

Migration

4 of 17 shipped

  1. ShippedcPanel import: plan, script, sync, coverage report
  2. ShippedDirectAdmin import
  3. ShippedGeneric SSH import
  4. ShippedServer-to-server moves with cutover
  5. PlannedResumable imports: a stall resumes where it stoppedBefore V1
  6. PlannedLive "watch sites arrive" view with each site's stepsBefore V1
  7. PlannedErrors that name the file and the fix, never "transfer failed"Before V1
  8. PlannedWhole-server import from WHM with root SSH, account list to tickBefore V1
  9. PlannedPre-flight: what will not come across, before anything movesBefore V1
  10. Partly therePlesk import (probe only today)Before V1
  11. PlannedMail importV1
  12. PlannedDNS zone importV1
  13. PlannedCutover planner: lower TTL, sync, switch, verifyV1
  14. PlannedPost-import check: every site answers 200 with the same titleV1
  15. PlannedImport from HestiaCP, CyberPanel, CloudPanel, aaPanelV1
  16. PlannedReseller import with all their customers intactAfter V1
  17. Planned"Try before you move": import a copy without touching DNSAfter V1

Users, resellers, packages

5 of 12 shipped

  1. ShippedAdmin, reseller, customer roles
  2. ShippedPackages enforced as policy
  3. ShippedPackages as a plan shelf with scaled bars
  4. ShippedNew customer + site in one flow
  5. ShippedInvites and suspension
  6. PlannedPackage change preview: what the customer loses before downgradeBefore V1
  7. PlannedLogin as customer, with an audit lineBefore V1
  8. PlannedReseller branding per reseller (own logo, own domain)V1
  9. PlannedReseller limits over their customers in totalV1
  10. PlannedAdd-on packs (extra space, extra sites)V1
  11. PlannedCustomer self-service upgrade through the storefrontV1
  12. PlannedTeams: several people on one customer account with rolesAfter V1

Limits and isolation

2 of 7 shipped

  1. Shippedcgroup limits
  2. ShippedDisk and inode quotas
  3. PlannedPer-account usage graph the customer can read (CPU, memory, I/O)Before V1
  4. Planned"Why is my site slow" answer when a limit was hitBefore V1
  5. PlannedProcess list per account with killV1
  6. PlannedBurst allowance per packageV1
  7. PlannedNoisy-neighbour detection on the admin homeAfter V1

Security

3 of 12 shipped

  1. ShippedTOTP two-factor
  2. ShippedFirewall over ufw
  3. ShippedScoped API tokens, instant revocation
  4. PlannedBrute-force blocking for panel, SSH, mail, WordPress loginBefore V1
  5. PlannedWAF (Coraza with OWASP CRS) per site, on by default in log modeBefore V1
  6. PlannedMalware scan (ClamAV + YARA) with quarantineBefore V1
  7. PlannedPasskeys (WebAuthn) for the panelBefore V1
  8. PlannedCountry blockingV1
  9. PlannedSecurity score per siteV1
  10. PlannedLogin alerts on new deviceV1
  11. PlannedFirewall temp block and allow lists, like CSFV1
  12. PlannedAutomatic hardening report after installAfter V1

Monitoring, logs, insight

4 of 9 shipped

  1. ShippedHealth engine, metrics, resource history
  2. ShippedLogs, audit timeline, diagnostics
  3. ShippedDoctor support bundle with redaction
  4. ShippedPrometheus-style metrics
  5. PlannedUptime checks per site with alertBefore V1
  6. PlannedVisitor stats without third-party scripts (from nginx logs)V1
  7. PlannedError log search across all sitesV1
  8. PlannedStatus page per host, publicV1
  9. PlannedAnomaly alert: traffic spike, error spikeAfter V1

API, CLI, automation

3 of 8 shipped

  1. ShippedREST API with scoped tokens
  2. ShippedLarge CLI with completion
  3. ShippedOutbound webhooks, Slack and Discord formats
  4. PlannedOpenAPI document published with the releaseBefore V1
  5. PlannedWHMCS module (so hosts can switch panel before billing)V1
  6. PlannedBlesta and HostBill modulesV1
  7. PlannedTerraform providerV1
  8. PlannedPlugin system for the UIAfter V1

Billing and storefront

1 of 5 shipped

  1. ShippedProducts, orders, coupons, payments, provisioning
  2. PlannedInvoices with tax (EU VAT, US sales tax)V1
  3. PlannedDunning: reminders, suspend, terminate on scheduleV1
  4. PlannedDomain registration reseller hookV1
  5. PlannedUsage-based add-ons billed automaticallyAfter V1

Multi-server

0 of 4 shipped

  1. Partly thereFleet pairing and moves
  2. PlannedOne login for all servers, estate-wide searchV1
  3. PlannedPlace a new customer on the least-loaded serverV1
  4. PlannedSeparate mail, DNS and web roles per serverAfter V1

Updates and operations

2 of 6 shipped

  1. ShippedSigned self-update with rollback
  2. ShippedOS updates and reboot from the panel
  3. PlannedStable and beta channels a host picks per serverBefore V1
  4. PlannedPost-update health check that rolls back on failureBefore V1
  5. PlannedMaintenance window schedulingV1
  6. PlannedChangelog shown inside the panel after updateV1

Design and ease of use

8 of 19 shipped

  1. ShippedCategorised rail, frosted header, command search
  2. ShippedLaunch with live preview and build log
  3. ShippedRewind timeline
  4. ShippedPlan shelf
  5. ShippedDatabase connection kit
  6. ShippedBoth themes, WCAG AA contrast gate, 44px targets gate
  7. ShippedWhite-label: brand accent, logo, no product name leaks (gate 26)
  8. ShippedNo stranded single words at line ends (text-wrap rules)
  9. PlannedFirst-run setup: hostname, DNS, mail, backups in five screensBefore V1
  10. PlannedEvery empty state tells the next actionBefore V1
  11. PlannedSite home redesigned as a single dashboard: health, traffic, backups, SSLV1
  12. PlannedKeyboard shortcuts sheetV1
  13. PlannedcPanel glossary in search: typing "Addon Domains" finds AliasesV1
  14. PlannedMobile layout for the customer panel audited at 390px on every pageV1
  15. PlannedCustomer onboarding checklist that ticks itselfV1
  16. PlannedUndo toast for reversible actionsV1
  17. PlannedLanguages: German, French, Spanish, Portuguese, Dutch, TurkishAfter V1
  18. PlannedRight-to-left layout (Arabic, Hebrew)After V1
  19. PlannedGuided tours per page, dismissable foreverAfter V1

Speed and footprint

2 of 7 shipped

  1. ShippedSingle Go binary, embedded UI
  2. ShippedBundle weight gate
  3. PlannedIdle RAM measured on each release and printed on klyrn.comBefore V1
  4. PlannedPanel page load budget: first content under 1 s on 3G fastV1
  5. PlannedSite creation budget: WordPress under 10 s (measured 5.5 s on vastrox)V1
  6. PlannedBackup speed budget per GBV1
  7. PlannedPublic benchmark against cPanel on the same VPSAfter V1

Trust, pricing, support

1 of 7 shipped

  1. ShippedFree edition with no account cap
  2. PlannedPrice promise pageBefore V1
  3. PlannedKnown issues page kept currentBefore V1
  4. Partly therePublic roadmap page on klyrn.com (this file, published)V1
  5. PlannedSupport response times publishedV1
  6. PlannedSecurity disclosure policy and hall of fameV1
  7. PlannedThird-party security audit, report publishedAfter V1

Documentation and migration content

1 of 6 shipped

  1. Shipped30-page docs section on klyrn.com
  2. Planned"Moving from cPanel" guide, step by step with screenshotsBefore V1
  3. Planned"Moving from DirectAdmin" guideBefore V1
  4. PlannedcPanel feature map: every cPanel icon and where it lives in KLYRNV1
  5. PlannedVideo walkthroughs of Launch, Rewind, migrationV1
  6. PlannedCommunity forumAfter V1

Accessibility and quality gates

3 of 6 shipped

  1. Shipped26 UI gates run as admin and customer before every deploy
  2. ShippedFocus rings on everything reachable
  3. ShippedReduced motion honoured
  4. PlannedScreen reader pass (NVDA, VoiceOver) on the five main flowsV1
  5. PlannedEnd-to-end test on a clean VPS for every releaseV1
  6. PlannedChaos test: kill services mid-backup, mid-migration, confirm recoveryAfter V1

Customer delight

1 of 4 shipped

  1. ShippedBuild log that ends with "<domain> is live"
  2. PlannedWeekly site report email (uptime, visits, backups) the host can brandV1
  3. PlannedAchievements for onboarding, off by default for hosts that dislike itAfter V1
  4. Planned"Your site's story" timeline: created, first visitor, first backupAfter V1