76 SMM Panels, One Piece of Software

We read the public pages of 84 SMM panels in one thirteen-minute window. Of the 76 that answered, 54 run the same vendor's software — and the same four fingerprints say so independently.

By Published Updated Last reviewed 8 min read

Forty-nine SMM panels serve the same captcha key. Not a similar one: the identical string key_1jhlt1fhm00b2s721es, baked into the page template, calling the same vendor’s endpoint. You can read it in the HTML of any of them without an account, and we have kept a copy of all forty-nine pages so you do not have to take our word for which.

That is the sharpest single tell in a survey we ran on 9 September 2026, between 20:26:05 and 20:38:54 UTC. We asked eighty-four SMM panel domains for four public things each — robots.txt, the homepage, the public service catalogue and the favicon — and then looked up where each one resolved, which network announced it, and who issued its certificate. Seventy-six answered. Nothing was ordered, no account was created, no form was submitted, and no page behind a login was requested.

The finding: 54 of the 76 panels we could read run one vendor’s product. That is 71% of the readable sample, and four independent fingerprints agree on it.

What “the same software” means, and what it does not

The word “same” is doing a lot of work in that sentence, so here is exactly what was measured. Four separate tells identify the dominant family, each derived from stored bytes by a script you can run yourself:

Independent fingerprints for the dominant software family, 9 September 2026
FingerprintPanels
Serves assets from the vendor’s asset host, storage.perfectcdn.com52
Serves the vendor’s build artefact odzrsnmblt1it35c.js50
Serves the identical hard-coded vendor captcha key49
Carries a per-customer tenant folder on the vendor’s asset host50

Three further build artefacts are each served by 34 panels. The classification never rests on how a page looks; every panel in fingerprints.csv carries the literal string that classified it, in a column named software_evidence.

Frameworks were deliberately kept out of the count. Three panels set a Laravel session cookie, two serve Next.js paths, one runs WordPress. Those are recorded and then excluded, because two panels written in Laravel are no more “the same panel” than two websites written in PHP. Counting them would have inflated the headline and meant nothing.

The part that resists the easy story

The obvious conclusion from “71% run one product” is that the market is a handful of operators wearing many names. Our own data argues against that, and it is the most important thing on this page.

The vendor gives each customer a tenant folder on its asset host, and the folder name appears in the panel’s own stylesheet and script URLs. We could read that id on 50 panels. All 50 are distinct. No two panels in this corpus share one. Fifty panels, fifty separate vendor accounts. That is what fifty businesses buying the same software licence looks like, not what one business with fifty storefronts looks like.

An earlier pass of this analysis said otherwise, and the correction is worth stating because it shows how easy the wrong answer was. That pass reported four pairs of panels sharing a tenant account. On inspection, three of the four were a screenshot pasted into a service description — an image served out of some other panel’s tenant folder, sitting in the middle of a product listing — and the fourth was a favicon on one side against a content image on the other. The tenant count now only counts the id when it appears on the panel’s own chrome: its stylesheet, script bundle, favicon or manifest. Seven panels in this corpus embed an image from a different tenant’s folder, and they are listed separately in the data.

The catalogues point the same way. We could read a machine-readable service list from 43 of the 76 and recorded 120,523 service rows, a median of 1,933 per panel. Comparing every pair on the set of service names they list — lowercased, stripped of emoji, with digit runs normalised so that a service id or a “50K/Day” speed does not defeat a match — no pair came anywhere near identical. The highest overlap we observed between any two catalogues was 0.47, one pair exceeded 0.30, and nine pairs exceeded 0.10 out of 903 pairs compared. Same shopfront software, genuinely different shelves.

Where they sit

Infrastructure tells the same story a second time, and it is the story of one hosting platform rather than one owner.

Of the 84 candidates, 44 resolve inside a single OVH /24, 152.228.155.0/24. Forty-eight panels share an IP address with at least one other panel, six of them on 152.228.155.65 alone. Fifty of the 84 use the same nameserver pair, dns1 and dns2.cloudns.net, which is that platform’s default. By announcing network: 50 panels sit behind OVH and 20 behind Cloudflare, with the remaining thirteen networks holding one or two each.

On a multi-tenant hosted platform, that is the expected result of many customers buying the same product — not a discovery about who owns what. Read alongside fifty distinct tenant ids, the honest reading is one platform with many customers.

The strongest evidence this method can collect would have been a TLS certificate naming two surveyed panels, because a shared certificate means somebody controls both domains at once. We found none. Every certificate in this corpus covers one domain and its www. That absence is reported here rather than quietly dropped, because a survey that only publishes the evidence it found is not a survey.

Our own two panels are in this sample

Novamya is published by Utta, which builds and maintains the websites of two panels in this market: smmlaunch.com and adderpanel.com. Both are in the eighty-four, labelled as publisher-owned in the data, and neither is an exception to anything above.

Both run the same vendor software as the majority. Both sit in the same /24 as forty-two other panels. Both serve the same hard-coded vendor captcha key as forty-seven others. If this page reads as an argument that panels are interchangeable at the software layer, that argument applies to our publisher’s two exactly as it applies to everyone else’s, and we would rather write that sentence ourselves than have a reader find it in the CSV.

What a buyer should take from this

The practical consequence is narrow and, we think, useful. If you are choosing between panels on the basis of the interface, the dashboard, the “features” list, the API documentation or the look of the order form, you are in most cases comparing the same product, configured by different people. Those things are the vendor’s, not the operator’s.

What actually differs between two panels running identical software is the part the software does not supply: the price, the catalogue, who is behind the support desk, whether an order is fulfilled, and what happens when it is not. Our price survey a week earlier found the same service name priced at $0.13 on one panel and $20.00 on another — a 153.8× spread for an identical string. Two panels can be the same software and still be nothing like the same purchase.

It also explains a smaller thing that puzzles buyers. Panels feel familiar when you move between them because they are familiar: the ordering flow, the vocabulary in the service names, the way “Min order” and “Max order” and “Rate per 1000” are laid out. That is not an industry convention that emerged by agreement. It is a template.

What this survey cannot tell you

Four limits, stated plainly, because each of them is a question a reader will reasonably have.

It says nothing about ownership. Shared software identifies a vendor. Shared hosting identifies a platform. Neither identifies a person, and this page names no business as anything other than a customer of a widely-sold product.

It says nothing about delivery. Nothing was ordered. A panel running excellent software may deliver nothing, and a panel running a dated template may be the most reliable operator in the market. This method cannot reach that question, and the research page lists it among the things we have not yet done.

Eight panels refused us, and that shaped the sample. Six answered 403 to our truthful research user-agent, all six behind Cloudflare, and two failed to connect at all. We did not retry disguised as a browser. That decision cost us data — several of those hosts answered the earlier price survey, which used a desktop Chrome string — and the cost is in the dataset rather than engineered around. Those eight are in the denominator of “84 candidates” and out of the denominator of “76 we could read”.

Thirty-three of the 76 published no machine-readable catalogue to us. Some redirect their services URL to the homepage; others build the table in JavaScript we did not execute. They count towards every software and infrastructure figure here and towards none of the catalogue figures.

The sample is also not the market. It is 84 domains assembled from the price survey’s fifteen, the ten that survey had to exclude, twenty search queries, and the outbound links of public panel directories — which turned out to be the weakest source, because the two largest directories mask the domains they rank and sell the real names by subscription. Every figure here is of the form “across the panels we could read on 9 September 2026”, and that is the only form it supports.

The data

Everything above is published under novamya.com/data/panel-software-survey/: every response as it was served, the response headers beside each one, a fetch log with a SHA-256 per body, the fingerprint table with the evidence string for each classification, the derived clusters, the aggregate figures, and the two scripts. analyse.py never touches the network — run it against pages/ and it rebuilds every number on this page offline.

What each file holds
FileContents
fingerprints.csvOne row per panel: software family and the literal string that classified it, tenant id, resolved IPs, announcing ASN, nameserver provider, TLS issuer and SAN count, catalogue extractor and row count, pricing currency, support channels.
clusters.jsonThe derived groupings — by software family, by infrastructure, by catalogue overlap — each with the evidence that produced it.
stats.jsonEvery aggregate quoted above, exactly as the script emitted it.
fetchlog.tsvOne row per request: URL asked for, URL that answered after redirects, status, bytes, Server and X-Powered-By, SHA-256 of the body, UTC timestamp. This is where the two-second rate limit and the thirteen-minute window can be checked.
infra.jsonlDNS, reverse DNS, ASN and TLS observations, each with its own timestamp.
method.mdHow the 84 were chosen, what was excluded and why, how each fingerprint is taken, and section 6: what the evidence supports and what it does not.
pages/Every response as served, gzipped, with its headers.

It is released under Creative Commons Attribution 4.0. Cite it as:

Novamya (2026). 76 SMM panels, one piece of software. Dataset. https://novamya.com/data/panel-software-survey/

If a figure here is wrong we want to hear it, and it will be dated and recorded on the corrections page like every other correction we have made. The standing rules this was collected under are on the research and data page, and the wider argument these numbers feed into — what a panel is, and what you are actually choosing between — is in the social media growth guide and in what an SMM panel is.