The Ultimate, Database-Free ISPConfig Registration Portal
Developed by Andy Goldau | © 2026 PanelLayer (Subdomain LTD) & GoMaKe UG
📦 Product Page: ISP-Register | 🧪 Live Demo: Demo | 🌐 Project: PanelLayer
ISP-Register is an incredibly robust, secure, and fully-featured self-service registration portal built specifically for ISPConfig. Designed from the ground up for maximum security, GDPR compliance, and styled 1:1 after the official ISPConfig 3 control panel interface, it requires zero database setup (100% flat-file logic) and handles client creation flawlessly through the native ISPConfig Remote API (JSON-RPC over cURL – no php-soap extension required).
DISCLAIMER: This software is provided "as is" without any warranty of any kind. ISP-Register is an independent software solution and is not affiliated with, endorsed by, or sponsored by ISPConfig or its developers.
- k-Anonymity Password Checks: Integrates the Have I Been Pwned API directly in the client's browser using the Web Crypto API. Only the first 5 characters of a SHA-1 hash are transmitted—your plaintext password never leaves your browser.
- Advanced Rate-Limiting (Token Bucket): Fully protects the ISPConfig API against brute-force and DDoS spam attacks using a highly efficient, session-independent Token Bucket algorithm based on cryptographically hashed IPs.
- No Database Required: Works strictly with local flat files (JSON/PHP). All sensitive log files (
audit.log.php,used_codes.php) are completely locked down and unreadable from the web, regardless of whether your webserver is Apache, LiteSpeed, or NGINX. - Strict Content Security Policy (CSP): Ships with hardened HTTP response headers (CSP, HSTS, X-Frame-Options) out of the box, mitigating XSS and iframe-injection attacks.
- 22 Supported Languages: Comes fully translated into 22 languages (English, German, Bulgarian, Brazilian Portuguese, Croatian, Czech, Dutch, Finnish, French, Greek, Hungarian, Indonesian, Italian, Japanese, Polish, Portuguese, Romanian, Russian, Spanish, Swedish, Slovak, and Turkish).
- Official ISPConfig 3 Theme: Styled pixel-perfect after the clean, iconic ISPConfig 3 login panel with light gray background, official monitor SVG logo, and branded UI controls.
- Live Password Checklist: A real-time, side-by-side interactive UI element that instantly visually validates password complexity requirements.
- Fail-open DNS MX Checks: Automatically verifies the existence of mail servers (MX records) for the email domains entered during registration to prevent bot signups, featuring built-in caching.
Forget spam. We support natively integrated setups for:
- hCaptcha
- reCAPTCHA (Google)
- Cloudflare Turnstile
- Altcha (Proof-of-Work, 100% GDPR compliant)
- MTCaptcha
- Invite-Only Mode: Optionally lock your registration portal so only users with pre-generated, single-use, or multi-use invitation codes can join your platform.
ISP-Register connects to ISPConfig via its JSON-RPC Remote API (/remote/json.php) using a dedicated Remote API user. No php-soap extension is needed – all calls are made via standard PHP cURL.
Authentication flow for each registration:
POST /remote/json.php?login→ obtains asession_idPOST /remote/json.php?client_add→ creates the client accountPOST /remote/json.php?logout→ cleans up the session
The new client's ISPConfig login URL is your panel address at port 8080 (e.g. https://your-server.com:8080). All user types (Admin, Reseller, Client) log in through the same interface; ISPConfig restricts features based on the account type automatically.
- Log into your ISPConfig panel.
- Navigate to System → User Management → Remote Users.
- Click Add new user.
- Set a username and a strong password.
- Under Functions, enable at minimum:
- Client functions (
client_add,client_get, etc.) - Client delete functions (
client_delete_everything- required ifDEMO_MODEis enabled)
- Client functions (
- Optionally restrict the allowed IP to your webserver's IP for extra security.
- Upload & Extract: Upload the contents to any PHP 8.x web directory.
- Configure: Copy
config-blank.phptoconfig.php(if not present) and enter your:- ISPConfig Host & Port (
ISP_HOST,ISP_PORT– default: 8080) - Remote API credentials (
ISP_REMOTE_USER,ISP_REMOTE_PASS) - Reseller ID (
ISP_RESELLER_ID– use0for admin-owned clients) - Desired CAPTCHA provider keys
- Security toggles (HIBP, Invite-Mode, Audit Logging)
- ISPConfig Host & Port (
- Generate a Salt: Replace the default
LOG_IP_SALTinconfig.phpwith a random 32-character string to ensure IP pseudonymization in your audit logs. - Done: The system automatically creates and protects the necessary
data/andlogs/folders upon the first registration.
If you enable DEMO_MODE, expired accounts are deleted automatically via cron_cleanup.php using client_delete_everything. The script stores the client_id (returned by ISPConfig after creation) in data/demo_accounts.json and uses it for deletion.
Add to crontab:
*/30 * * * * php /path/to/public_html/cron_cleanup.php >> /dev/null 2>&1This project is licensed under the MIT License.
Developer: Andy Goldau
Copyright: © 2026 ISP-Register by PanelLayer, a brand of Subdomain LTD and managed on behalf of GoMaKe UG. All rights reserved.
Product Page: https://isp-register.panellayer.com/
Live Demo: https://demo.isp-register.panellayer.com/
Project: https://panellayer.com/
The above copyright notice, the developer attribution, and the permission notice must be included in all copies or substantial portions of the Software.