The official Z-CMS marketplace

Extend every Z-CMS site with themes and plugins you can trust.

Z-CMS Marketplace is where developers publish, and site owners discover, the themes and plugins that power the Z-CMS ecosystem. Every package is signed by a verified publisher and read by a human before it can ship to a single site.

Why the marketplace exists

Trust is the product.

Signed by verified publishers

Every package carries an Ed25519 signature that proves it really came from the publisher it claims. A package whose signature does not match a registered key never enters the registry.

Reviewed before it ever ships

Uploads pass an automated security scan and then a human reviewer reads the code — even when the scan is clean. Nothing reaches a live site on trust alone.

One registry, every instance

Publish once and your theme or plugin is installable from any Z-CMS instance on earth. A signed revocation kill switch lets a bad version be pulled everywhere at once.

For developers

From code to catalogue in four steps.

  1. Register a publisher

    Sign in with Google or GitHub and register your public signing identity. No password is ever stored.

  2. Sign your package

    Build with the Z-CMS SDK and sign the artifact with your private key using `zcms pack`.

  3. Submit for review

    Upload the signed package. It is scanned automatically and queued for a human reviewer.

  4. Go live

    Once approved, your package is published to the registry and available to every Z-CMS site.

Ready to publish?

Sign in with Google or GitHub — it takes a minute, and there is no password to remember.

Open the developer portal