Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🚀 IM-Register

The Ultimate, Database-Free ISPmanager Registration Portal

Developed by Andy Goldau | © 2026 PanelLayer (Subdomain LTD) & GoMaKe UG

📦 Product Page: IM-Register  |  🧪 Live Demo: Demo  |  🌐 Project: PanelLayer


IM-Register is an incredibly robust, secure, and fully-featured self-service registration portal built specifically for ISPmanager. Designed from the ground up for maximum security, beautiful UI/UX, and GDPR compliance, it requires zero database setup (100% flat-file logic) and handles user creation flawlessly through the native ISPmanager API.

DISCLAIMER: This software is provided "as is" without any warranty of any kind. IM-Register is an independent software solution and is not affiliated with, endorsed by, or sponsored by ISPsystem (ISPmanager) or its affiliates.


✨ Enterprise-Grade Features

🛡️ Unrivaled Security & Privacy

  • k-Anonymity Password Checks: Integrates the Have I Been Pwned API directly in the client’s browser using the Web Crypto API. Only the first 5 characters of a SHA-1 hash are transmitted—your plaintext password never leaves your browser.
  • Advanced Rate-Limiting (Token Bucket): Fully protects the ISPmanager API against brute-force and DDoS spam attacks using a highly efficient, session-independent Token Bucket algorithm based on cryptographically hashed IPs.
  • No Database Required: Works strictly with local flat files (JSON/PHP). All sensitive log files (audit.log.php, used_codes.php) are completely locked down and unreadable from the web, regardless of whether your webserver is Apache, LiteSpeed, or NGINX.
  • Strict Content Security Policy (CSP): Ships with hardened HTTP response headers (CSP, HSTS, X-Frame-Options) out of the box, mitigating XSS and iframe-injection attacks.

🌐 Internationalization & UX

  • Multiple Languages: Comes fully translated into 12 languages (English, German, French, Spanish, Russian, and more).
  • Responsive Dark/Light Mode: Automatically adjusts its premium UI to the system preferences of your users.
  • Live Password Checklist: A real-time, side-by-side interactive UI element that instantly visually validates password complexity requirements.
  • Fail-open DNS MX Checks: Automatically verifies the existence of mail servers (MX records) for the email domains entered during registration to prevent bot signups, featuring built-in caching.

🤖 Ultimate Anti-Bot Protection

Forget spam. We support natively integrated setups for:

  • hCaptcha
  • reCAPTCHA (Google)
  • Cloudflare Turnstile
  • Altcha (Proof-of-Work, 100% GDPR compliant)
  • MTCaptcha

🎟️ Exclusive Access Modes

  • Invite-Only Mode: Optionally lock your registration portal so only users with pre-generated, single-use, or multi-use invitation codes can join your platform.

🚀 Installation & Setup

  1. Upload & Extract: Upload the contents to any PHP 8.x web directory.
  2. Prepare Config: Rename config-blank.php to config.php.
  3. Configure: Open config.php and enter your:
    • ISPmanager Host, Port, and API Credentials
    • User Template (Preset) for new users
    • Desired Captcha Provider Keys
    • Security toggles (HIBP, Invite-Mode, Audit Logging)
  4. Generate a Salt: Replace the default LOG_IP_SALT in config.php with a random 32-character string to ensure IP pseudonymization in your audit logs. (openssl rand -hex 16)
  5. Done: The required data/ and logs/ folders (including their .htaccess protections) are included in the repository. The script will populate them upon the first registration.

⚠️ ISPmanager Username Restrictions

To ensure maximum compatibility and avoid API errors, IM-Register enforces the following username rules:

  • Lowercase letters and digits only (a-z, 0-9) — no special characters
  • Length: 4–8 characters

This is enforced both client-side (JS validation) and server-side (PHP regex /^[a-z0-9]{4,8}$/).

📄 License & Attribution

This project is licensed under the MIT License.

Developer: Andy Goldau
Copyright: © 2026 IM-Register by PanelLayer, a brand of Subdomain LTD and managed on behalf of GoMaKe UG. All rights reserved.
Product Page: https://im-register.panellayer.com/
Live Demo: https://demo.im-register.panellayer.com/
Project: https://panellayer.com/

The above copyright notice, the developer attribution, and the permission notice must be included in all copies or substantial portions of the Software.

About

Modern, database-free ISPmanager registration portal built for PHP 8. Native API account creation, Token Bucket protection, k-Anonymity password check, 12 languages, multi-captcha support, invite-only mode, and full GDPR compliance out of the box.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages