# Independent Core Panel review checklist

Updated: 2026-09-20

This checklist is meant to make reviews more reproducible. It does not prescribe a verdict. Core Panel is currently classified as pre-production; use an isolated non-production server and do not expose real customer data or secrets.

## Identify the test

- Record the Core Panel version, operating system image, CPU, memory, storage, region, and test date.
- State whether access, a license, services, or compensation were provided and disclose any affiliate relationship.
- Link to the exact documentation, pricing, evidence, and policy pages used.

## Install and operate

- Start from a fresh supported server and record install time, errors, and manual intervention.
- Change initial credentials, enable MFA, store recovery codes offline, and test session revocation.
- Create representative PHP/WordPress, Node.js, and Python workloads only where relevant to the review.
- Create least-privilege MySQL/MariaDB and PostgreSQL users and test permitted and denied access.
- Create DNS records, inspect delegation, exercise DNSSEC only in an appropriate test zone, and record propagation behavior.
- Request and renew a test TLS certificate and record validation failures accurately.
- Test operator, reseller, and site-account boundaries with both allowed and prohibited actions.
- Export a backup, inspect it, restore it to an isolated target, and document recovery time and data loss.
- Review logs, monitoring, firewall rules, audit history, and failure messages.
- Exercise update, rollback, and support workflows without destructive testing against production infrastructure.

## Compare responsibly

- Compare equivalent editions, billing units, account limits, server costs, taxes, support, add-ons, and migration labor.
- Verify third-party prices and capabilities at their primary sources on the publication date.
- Do not generalize the published PostgreSQL reference workload to unrelated hardware or applications.
- Distinguish a developer-run regression suite from an independent security audit or penetration test.
- Publish failures, limitations, and missing controls alongside successful results.

## Evidence and corrections

- Evidence index: https://core-panel.net/research
- Raw manifest: https://core-panel.net/research/manifest.json
- Comparison method: https://core-panel.net/research/comparison-methodology.md
- Security and reporting: https://core-panel.net/security
- Factual correction or evidence request: hello@core-panel.net

Core Panel does not require favorable coverage, backlinks, pre-publication approval, or removal of criticism in exchange for review access. The reviewer retains editorial control.
