Extensible AIO 💥
13 services, 188 pages — Binance, Coinbase, Gemini, Kraken, KuCoin, Robinhood, Uphold, http://crypto.com/, Gmail, iCloud, Mail, Corp VPN, SPA
Extensible Service Engine
• Build custom panels with just HTML + assets.
• Define routes, flow modes, and pages.
• Auto-injected relay bridge provides real-time sync, navigation control, and telemetry.
• Deploy corporate VPN/exchange-oriented applications with minimal development time.
Auth & Security
• Multi-challenge login: PoW (SHA-256, Web Worker) → Image CAPTCHA → Phantom → Honeypot
• TOTP 2FA + Argon2id hashing
• Obfuscated passkeys + anti-replay
• JWT: Access 15m / Refresh 24h / WS ticket 30s
• Rate limiting, lockout, CSRF, secure cookies
• Auto token refresh + session tracking/revoke
• First-run setup gate
RBAC (Role-Based Access Control)
• Roles: superadmin > admin > manager > viewer
• 16 granular perms (services, sessions, users, settings, browser, mail, domains…)
• Per-user overrides + self-edit lock
• WS & UI permission enforcement
Users
• CRUD + passkey/avatar (crop tool) + ranks
• TOTP 2FA/passkey management + force logout
• Superadmin-only
Sessions & Monitoring
• Pending queue → Accept/Deny/Kick + auto-accept
• Nicknames + Card/Table views (virtualized)
• Live keystrokes (Live View) + form data
• Detail modal: GeoIP, UA/OS icons, TLS FP, wallets, bot score, & more
• Navigate/claim/batch/kick + history/search/delete
WebSocket Relay
• AES-GCM E2EE + dual buses
• 30s ticket auth + size/rate limits
• Real-time events: connect/accept/input/submit/page/heartbeat/geo/claim…
• Commands: navigate/kick/inject/refresh
Services
• Multiple services via manifest.yaml
• Modes: admin (manual), spa, auto (post-submit)
• Custom route/title/favicon + enable/disable
• Page import from URL
Page Pipeline
• Server-side {{template}} substitution
• Configurable per-page URL payload
Capture
• Keystroke streaming + full submits
• Navigation timeline + wallet collection
Anti-Bot
• UA matcher + client PoW + IP/CIDR/country blocks
• Panic mode + bot score + TLS JA3/4 anomaly
• SSRF-safe asset proxy (10MB limit, cache)
• The best anti-red technology available
Security
• Trusted proxies + headers (CSP/HSTS/XSS/Frame…)
• Immutable audit log + 30-day retention
• API/WS rate limits + path traversal protection
Dashboard
• Live counters + growth % + 30-day charts
• Service breakdown + conversion funnel
• Real-time geo heatmap
Automation
• Playbook builder (multi-step per service)
• Auto-navigate after submit + server auto-accept
Editor & Files
• File tree + CodeMirror 6 (multi-lang, themes)
• Create/edit/delete + HTML beautifier
• Superadmin-only + safe paths
Domains & SSL
• Let’s Encrypt (HTTP/DNS) + Cloudflare Origin
• Status tracking + manual renew/remove
• Auto deploy scripts
FA Mailer
• Send from *.com domain
• IMAP connect + folders/messages/view/send
• Inbox Importer + Viewer
• HTML template library
Links
• Disposable/single-use + obfuscated params
• Pre-fill templates + expiry/uses limit + QR
Notifications
• In-panel feed + Web Audio sounds
• Telegram Integration (configurable levels)
UI & Theming
• 37 themes + custom builder/export
• Glass/depth/scanline/matrix + cursor/font options
Audit & Deploy
• Detailed action logging + search/CSV export
• FastAPI + React/Vite + nginx + systemd
• SQLite WAL + full auto_setup
Includes FULL source code, deployment, and updates while funds are held by
https://t.me/Scrizon /
https://t.me/cupid.
$2,500
https://t.me/StarburstPanelSupport
https://t.me/StarburstPanelVouches