Skip to content
HisarBlok
Menu
TR

HisarBlok · features

What comes in the box

What HisarBlok does as of version 0.13.1. It is all part of the same core; a module you do not want is switched off per site with one button. A module that is off does not run and its generated files leave the site; its data is kept.

Installation Changelog

Version 0.13.1 · AGPL-3.0-or-later · Source code coming soon

Publishing

Static output

The moment you save, the affected pages are written to disk as plain HTML, with .gz copies and, where PHP has Brotli, .br ones. A visitor's request runs no code.

Build queue

The page you save is written at once; lists, the sitemap, feeds and full rebuilds are queued and run in slices in the background. Progress shows in the top bar, and interrupted work resumes where it stopped.

One visitor door

Forms, comments, forum posts and member sign-in go through go.php and get.php only: a same-origin check, a token bound to the page, a time gate, a honeypot and rate limits.

Content

Pages from blocks

Hero, card grid, badges, gallery, Markdown, rich text, release notes, form, latest posts and download blocks; or Markdown or sanitized HTML in the built-in editor. Markdown supports footnotes.

Blog

Tags, a paged index, tag pages, reading time, related posts; RSS and Atom per language and a feed for every tag.

Media

An uploaded image is re-encoded, stripped of metadata and resized; 480/960/1440 px WebP and, where supported, AVIF copies are served through srcset.

Menus and announcements

The site menu from the admin, per language; short announcements on the home page.

Downloads

Products, releases and files; counted links and checksums.

Redirects

301 rules that keep old addresses alive: a redirect page that works on any server, plus exportable nginx/Apache rules.

Engagement

Form builder

Forms added to a page as a block; answers are kept in the admin and notification mails are queued. A refused form is drawn again with each error beside its field and everything typed kept.

Comments

Under pages and posts; approved first, then written into the static page.

Forum

Categories, topics, replies; pin, lock, hide and move. Reading runs no code, and nothing a stranger writes appears unapproved. In every site language, with its own feeds.

Members

Sign-up with a verified email, sign-in, password reset, profiles. One account for every language, mails in the member's language. Only members carry a cookie.

Search

Over a static index, in the reader's browser. Accented letters match their base letters.

Spam protection

No puzzles and no outside service: a time gate, a honeypot, a submission budget per address and per site, moderation.

Languages and search engines

Many sites, many languages

Several sites from one installation; languages, a default language and a language switcher per site. hreflang and language links only go to translations that exist.

Eight visitor languages

Everything a visitor reads is in Turkish, English, German, Spanish, French, Portuguese, Russian and Arabic. Arabic, Persian, Hebrew and Urdu pages are drawn right to left. The admin is in Turkish and English.

Addresses in any script

Titles in Arabic, Hebrew, Japanese and other scripts keep their letters in the address; Cyrillic and Greek are transliterated with a fixed table. Latin addresses do not change.

Structured data

JSON-LD on every page (Organization, WebSite, BlogPosting, DiscussionForumPosting for the forum), OpenGraph and Twitter cards, one h1, a time zone per site.

Sitemap and feeds

An XML sitemap, RSS and Atom per language, and Atom feeds per blog tag and forum category.

Broken link report

After every full rebuild each internal link is checked against the files on disk, with no network request. The dashboard lists broken addresses.

Themes

Three themes

default: the token-driven base theme. Studio: for software product sites; this site runs on it. Journal: for writing meant to be read, with a serif reading column and footnotes.

Themes extend themes

A theme builds on another with "extends" in its theme.json and ships only what it changes. Colours and sizes change through --hb-* variables.

Templates without a database

A template receives only the view model prepared for it and cannot write a query. Dark mode, print, reduced motion and a script-free mobile menu come ready.

Running it

Setup wizard

Locked by a one-time code on the server, checks with a real request that data/ is not reachable from the web, and disappears completely once installation is done. The same can be done from the command line.

Signed updates

A new version is unpacked only if its Ed25519 signature checks out; a backup comes first, the code is switched in one move, and a failed step is rolled back by itself. The admin never writes code.

Backup and restore

Single-file backups with a SHA-256 for every file; the newest 14 are kept. Restoring happens only on the server, after every checksum is verified and the current state is backed up.

SQLite or MySQL/MariaDB

Single-file SQLite by default; MySQL/MariaDB as an option (table prefix, TLS to a remote server). A tool to move in either direction, and the same backup format for both.

Command line

bin/hisarblok is one door to every tool: backup, restore, rebuild, update, import and export. doctor reports the installation's health; make:module and make:theme write skeletons.

Dashboard and roles

Real numbers per module, pending work, first steps and site health. Capability-based administrator and editor roles; an account can be limited to some sites, with a role per site.

Moving

Old addresses are redirected permanently to their new places, but never over a page that lives on the site.

In

WordPress (WXR), Joomla 3–5, Drupal 7 and 8+, Ghost, Blogger, Disqus comments, Medium, Substack, Hugo, Jekyll and any RSS/Atom feed. A dry run comes first, and runs can be repeated.

Forums

phpBB 3, MyBB 1.8, SMF 2, vBulletin 3/4/5, XenForo 1/2, Flarum, Invision Community 4, Discourse and NodeBB. Members sign in with their old passwords, upgraded to Argon2id on first sign-in.

Out

The whole site as plain JSON Lines files and the original images in one .zip, in an open, documented format. Passwords, sessions and mail settings are never in it.

Security and privacy

Accounts

Argon2id password hashes, TOTP two-factor sign-in with recovery codes, sign-in limits per address and per account name, an audit log. Security features never go behind a paid tier.

The admin

Designed to run at an address of its own, apart from the site: a nonce-based Content Security Policy, a CSRF token on every form, session binding, capability-based permissions.

Content and visitor input

An author's HTML is cleaned against an allow-list with PHP's HTML5 parser. Everything a visitor sends is escaped; javascript: and data: links are refused.

Cookieless statistics

Views, daily visitors, the most read pages and referring sites. No cookie, no IP address or browser string stored, no third party. Switched off per site.

Accessibility

The themes and the admin were reviewed against WCAG 2.2 AA: keyboard use, visible focus, enough contrast, landmarks, names for screen readers.

No tracking

No dependencies, no CDN, no web fonts from elsewhere. The site makes no outside connections on its own; even the update check is off by default.

Not there yet

A shop module (digital downloads, licence keys, cart, payment) is the next large item on the roadmap; it does not exist yet. The admin speaks Turkish and English; other admin languages are waiting for translators. The source code is not public yet: details.

How installation works is in the docs, and what changed from release to release in the changelog.