Signed by verified publishers
Every package carries an Ed25519 signature that proves it really came from the publisher it claims. A package whose signature does not match a registered key never enters the registry.
Z-CMS Marketplace is where developers publish, and site owners discover, the themes and plugins that power the Z-CMS ecosystem. Every package is signed by a verified publisher and read by a human before it can ship to a single site.
Every package carries an Ed25519 signature that proves it really came from the publisher it claims. A package whose signature does not match a registered key never enters the registry.
Uploads pass an automated security scan and then a human reviewer reads the code — even when the scan is clean. Nothing reaches a live site on trust alone.
Publish once and your theme or plugin is installable from any Z-CMS instance on earth. A signed revocation kill switch lets a bad version be pulled everywhere at once.
Sign in with Google or GitHub and register your public signing identity. No password is ever stored.
Build with the Z-CMS SDK and sign the artifact with your private key using `zcms pack`.
Upload the signed package. It is scanned automatically and queued for a human reviewer.
Once approved, your package is published to the registry and available to every Z-CMS site.
Sign in with Google or GitHub — it takes a minute, and there is no password to remember.
Open the developer portal