The panel manages proxy access through a Persian interface
Vodiwalker Panel combines a FastAPI web dashboard, subscription links, connection tracking, administrator accounts, and a Telegram bot. Its source names VLESS over WebSocket, raw TCP, and several XHTTP modes, along with VMess and Trojan routes. Operators can create users, limit traffic and connection counts, group subscriptions, inspect live connections, and issue QR codes from one service.
The audience is narrower than that feature list suggests. The README is 15 short lines of Persian promotion and links to a Telegram channel and an external tutorial video. There are no written install commands, architecture notes, upgrade steps, or English pages. The interface text and many source comments are also Persian. A non-Persian operator would be translating both the runbook and the administrative UI while handling live proxy credentials.
One process holds the web panel, relays, and Telegram control
The application stores links, subscriptions, sessions, administrators, and daily statistics in local state. A Telegram bot exposes creation flows, configuration lists, online users, usage reports, backup actions, and a mini app. The web side has role permissions and scoped administrators. This is a lot of operational authority in one Python service and one persisted data directory.
Versioning inside the repository is inconsistent. The first comment in main.py says 15.0.0, env.example calls the product Professional 17, and the FastAPI application reports 27.3.0. GitHub had no release object on October 2, 2026. Without a tag and changelog tied to the deployed code, an operator cannot use the displayed version to reconstruct an installation with confidence.
What happened when we ran it
Our sandbox installed commit c547e73 in 36 seconds. Pip added 63 packages and used 88 MB on disk. The build step completed in 9 seconds on 3 CPUs with 8 GB of RAM, Python 3.12, Debian, no secrets, and no elevated privileges. That proves the checked-out Python code could be installed and built in the environment we used.
There was no test script or target, so the pipeline skipped tests. The repository has 19 files and about 19,761 lines of source, with no tests directory and 0 CI workflow files. Pip-audit reported 17 known vulnerabilities. The supplied measurement does not name their packages or severities, so claiming a particular exploit path would go beyond the evidence.
Deployment needs more configuration than the README supplies
The sample environment asks for owner credentials, a secret, a persistent data path, a public base URL, public TCP settings, and optional Telegram bot details. The service can create a secret file when no secret is supplied, and it writes application state beside that file. Back up that directory, restrict access to it, and set the owner password before public exposure.
HTTP defaults to port 8000. Raw VLESS TCP uses a separate listener whose source default is 6543, so a platform that only exposes the web port will not carry that traffic. The repository includes a valid-looking Python container recipe, but its filename is Dockerfile.txt. Docker will not select it through the usual default command unless you rename it or pass the file explicitly.
Security controls exist, but there is no automated proof
The source includes hashed passwords, session cookies, failed-login throttling, permission checks, administrator scoping, and Telegram admin validation. Those are useful controls. They are also the kind of controls that need regression tests because a missed dependency on one route can expose owner actions, subscription data, or live connection details.
Our run found 17 known dependency vulnerabilities and no callable test suite. The source grants sessions a 365-day lifetime, according to its SESSION_TTL calculation, which raises the cost of a stolen session token. These facts do not prove the panel has been breached. They do mean an operator should commission a focused authentication and route audit before treating the application as a safe public control plane.
Activity is recent, while release discipline is absent
GitHub showed 1,096 stars, 4 combined open issues and pull requests, and a last push on October 1, 2026. Recent commits touched the Telegram bot, XHTTP code, and connection handling. The two visible open issues were both titled 1, each had a body of No, and neither contained a usable defect report. Stars here say more about attention than support quality.
No license is declared in the repository, so do not assume that public source grants permission to copy, modify, or redistribute it. The missing release, missing CI, absent test target, and 17 audit findings all point the same way: treat Vodiwalker Panel as code to inspect, not an appliance to expose after a 45-second build. The operational alternatives are larger, but their documentation and release trails give you more to verify.

