Skip to content
HisarBlok
Menu
TR

Content management system · PHP + SQLite

One CMS instead of thirty plugins.

The moment you save in the admin, HisarBlok writes your pages to disk as plain HTML. When a visitor opens a page, no code runs on the server. What WordPress needs plugins for (SEO, a sitemap, forms, backups, languages, search, two-factor sign-in, a forum, members and statistics) comes in the core.

Features Docs Source code

Version 0.13.1 · AGPL-3.0-or-later · In development · Source code coming soon

On the left an admin page edited as blocks, on the right the index.html, blog/index.html and sitemap.xml files written when it is saved

Static by default, dynamic by exception

The admin is dynamic and sits behind a login; the site visitors see is nothing but files.

Visitors run no code

Opening a page serves a ready HTML file, with a pre-compressed copy beside it. No queries, no caching plugin, no cache to clear.

Saved means published

The page you save is written at once; lists, tag pages, the sitemap and feeds follow from a build queue in the background. The admin does not wait.

One narrow door

Genuinely dynamic work such as forms, comments, forum posts and member sign-in goes through go.php and get.php only: rate limits, a token bound to the page, no session or cookie for visitors.

In the box, no plugins

What WordPress installs as separate plugins is part of the core here, built by one team to one standard. A module you do not want is switched off per site with one button.

SEO and sitemap

JSON-LD, OpenGraph, a description per page, one h1, an XML sitemap, RSS and Atom feeds, 301 redirects.

Speed

The CSS a page uses sits inside the page; images get 480/960/1440 px WebP and AVIF copies, srcset and the right loading order.

Forms and comments

A form builder added as a block; comments under pages and posts, approved first. Spam protection without puzzles.

Backup and restore

Single-file backups with a SHA-256 for every file, a restore that checks before it writes, and a full export of the site in an open format.

Languages

Several sites and languages from one installation, hreflang, a language switcher; visitor wording in eight languages, right-to-left included.

Search

On-site search over a static index, run in the reader's browser. Nothing typed leaves the reader's computer.

Two-factor sign-in

Argon2id passwords, TOTP and recovery codes, a login rate limit and an audit log that answers who did what.

Forum and members

Categories, topics, moderation; members with a verified email. Members move over from eight forum packages with their old passwords.

Cookieless statistics

Views, daily visitors, the most read pages and referring sites; counted on the site's own server, with no cookie and no IP address.

A look at the admin

Screenshots from a trial install with sample content (Turkish admin).

The overview screen of the HisarBlok admin: content counts, first steps and site health
Overview: counts, pending work and site health on one screen.
The home page of a sample coffee roaster site built with HisarBlok
A sample site built from the same admin: plain HTML for visitors.

Who it is for

Organisations and small businesses

People who want a fast site that is easy to keep, without chasing plugin updates. Security, backups and search engine settings come with the installation.

Software products and communities

Release notes and download pages, docs, a blog, a forum and members in one admin. This site and ciciftp.com are both built with HisarBlok.

Server administrators and agencies

Several sites from one installation; accounts limited to some sites with a role per site; a command-line tool and signed updates.

Moving from another system

Importers for WordPress, Joomla, Drupal, Ghost, Blogger, Medium, Substack, Hugo, Jekyll and forum packages; old addresses kept alive with 301s.

No dependencies

HisarBlok needs PHP 8.4 or newer and a web server: nginx or Apache. The default database is a single SQLite file; MySQL/MariaDB is there if you want it. There is no Composer or npm step, neither to install nor to run, and no CDN, no web fonts from elsewhere and no tracking script. The only third-party part is the admin's editor, ProseMirror; it ships pre-built and is served from your own server.

This site is built with HisarBlok

The pages you are reading were written as blocks in HisarBlok's admin and saved to the server as plain HTML. Opening this page ran no PHP on the server; only sending the contact form goes through a single, narrow entry point.

All features · Installation · Changelog · Write to us