HisarBlok · features
What comes in the box
What HisarBlok does as of version 0.13.1. It is all part of the same core; a module you do not want is switched off per site with one button. A module that is off does not run and its generated files leave the site; its data is kept.
Version 0.13.1 · AGPL-3.0-or-later · Source code coming soon
- Pages
- Blocks
- Blog
- Media
- Menus
- Announcements
- Redirects
- Forms
- Comments
- Forum
- Members
- Search
- Downloads
Publishing
Static output
The moment you save, the affected pages are written to disk as plain HTML, with .gz copies and, where PHP has Brotli, .br ones. A visitor's request runs no code.
Build queue
The page you save is written at once; lists, the sitemap, feeds and full rebuilds are queued and run in slices in the background. Progress shows in the top bar, and interrupted work resumes where it stopped.
One visitor door
Forms, comments, forum posts and member sign-in go through go.php and get.php only: a same-origin check, a token bound to the page, a time gate, a honeypot and rate limits.
Content
Pages from blocks
Hero, card grid, badges, gallery, Markdown, rich text, release notes, form, latest posts and download blocks; or Markdown or sanitized HTML in the built-in editor. Markdown supports footnotes.
Blog
Tags, a paged index, tag pages, reading time, related posts; RSS and Atom per language and a feed for every tag.
Media
An uploaded image is re-encoded, stripped of metadata and resized; 480/960/1440 px WebP and, where supported, AVIF copies are served through srcset.
Menus and announcements
The site menu from the admin, per language; short announcements on the home page.
Downloads
Products, releases and files; counted links and checksums.
Redirects
301 rules that keep old addresses alive: a redirect page that works on any server, plus exportable nginx/Apache rules.
Engagement
Form builder
Forms added to a page as a block; answers are kept in the admin and notification mails are queued. A refused form is drawn again with each error beside its field and everything typed kept.
Comments
Under pages and posts; approved first, then written into the static page.
Forum
Categories, topics, replies; pin, lock, hide and move. Reading runs no code, and nothing a stranger writes appears unapproved. In every site language, with its own feeds.
Members
Sign-up with a verified email, sign-in, password reset, profiles. One account for every language, mails in the member's language. Only members carry a cookie.
Search
Over a static index, in the reader's browser. Accented letters match their base letters.
Spam protection
No puzzles and no outside service: a time gate, a honeypot, a submission budget per address and per site, moderation.
Languages and search engines
Many sites, many languages
Several sites from one installation; languages, a default language and a language switcher per site. hreflang and language links only go to translations that exist.
Eight visitor languages
Everything a visitor reads is in Turkish, English, German, Spanish, French, Portuguese, Russian and Arabic. Arabic, Persian, Hebrew and Urdu pages are drawn right to left. The admin is in Turkish and English.
Addresses in any script
Titles in Arabic, Hebrew, Japanese and other scripts keep their letters in the address; Cyrillic and Greek are transliterated with a fixed table. Latin addresses do not change.
Structured data
JSON-LD on every page (Organization, WebSite, BlogPosting, DiscussionForumPosting for the forum), OpenGraph and Twitter cards, one h1, a time zone per site.
Sitemap and feeds
An XML sitemap, RSS and Atom per language, and Atom feeds per blog tag and forum category.
Broken link report
After every full rebuild each internal link is checked against the files on disk, with no network request. The dashboard lists broken addresses.
Themes
Three themes
default: the token-driven base theme. Studio: for software product sites; this site runs on it. Journal: for writing meant to be read, with a serif reading column and footnotes.
Themes extend themes
A theme builds on another with "extends" in its theme.json and ships only what it changes. Colours and sizes change through --hb-* variables.
Templates without a database
A template receives only the view model prepared for it and cannot write a query. Dark mode, print, reduced motion and a script-free mobile menu come ready.
Running it
Setup wizard
Locked by a one-time code on the server, checks with a real request that data/ is not reachable from the web, and disappears completely once installation is done. The same can be done from the command line.
Signed updates
A new version is unpacked only if its Ed25519 signature checks out; a backup comes first, the code is switched in one move, and a failed step is rolled back by itself. The admin never writes code.
Backup and restore
Single-file backups with a SHA-256 for every file; the newest 14 are kept. Restoring happens only on the server, after every checksum is verified and the current state is backed up.
SQLite or MySQL/MariaDB
Single-file SQLite by default; MySQL/MariaDB as an option (table prefix, TLS to a remote server). A tool to move in either direction, and the same backup format for both.
Command line
bin/hisarblok is one door to every tool: backup, restore, rebuild, update, import and export. doctor reports the installation's health; make:module and make:theme write skeletons.
Dashboard and roles
Real numbers per module, pending work, first steps and site health. Capability-based administrator and editor roles; an account can be limited to some sites, with a role per site.
Moving
Old addresses are redirected permanently to their new places, but never over a page that lives on the site.
In
WordPress (WXR), Joomla 3–5, Drupal 7 and 8+, Ghost, Blogger, Disqus comments, Medium, Substack, Hugo, Jekyll and any RSS/Atom feed. A dry run comes first, and runs can be repeated.
Forums
phpBB 3, MyBB 1.8, SMF 2, vBulletin 3/4/5, XenForo 1/2, Flarum, Invision Community 4, Discourse and NodeBB. Members sign in with their old passwords, upgraded to Argon2id on first sign-in.
Out
The whole site as plain JSON Lines files and the original images in one .zip, in an open, documented format. Passwords, sessions and mail settings are never in it.
Security and privacy
Accounts
Argon2id password hashes, TOTP two-factor sign-in with recovery codes, sign-in limits per address and per account name, an audit log. Security features never go behind a paid tier.
The admin
Designed to run at an address of its own, apart from the site: a nonce-based Content Security Policy, a CSRF token on every form, session binding, capability-based permissions.
Content and visitor input
An author's HTML is cleaned against an allow-list with PHP's HTML5 parser. Everything a visitor sends is escaped; javascript: and data: links are refused.
Cookieless statistics
Views, daily visitors, the most read pages and referring sites. No cookie, no IP address or browser string stored, no third party. Switched off per site.
Accessibility
The themes and the admin were reviewed against WCAG 2.2 AA: keyboard use, visible focus, enough contrast, landmarks, names for screen readers.
No tracking
No dependencies, no CDN, no web fonts from elsewhere. The site makes no outside connections on its own; even the update check is off by default.
Not there yet
A shop module (digital downloads, licence keys, cart, payment) is the next large item on the roadmap; it does not exist yet. The admin speaks Turkish and English; other admin languages are waiting for translators. The source code is not public yet: details.
How installation works is in the docs, and what changed from release to release in the changelog.