
The Problem
Choosing a CMS means choosing the work that comes with it. A general-purpose platform offers a broad ecosystem; a headless stack offers architectural flexibility. Either can be the right choice, but not every independent publication needs that much setup.
VonCMS takes a narrower approach: a publishing workflow, bundled themes, and a PHP runtime in one deployable application. Start with those defaults, then customize when your project needs it.
A publication should be judged by its stories, not the complexity of its stack.
Ownership
A site owner should be able to move hosts, inspect the source, back up the database, replace files manually, and keep publishing without asking a platform for permission. That is why VonCMS uses standard PHP and MySQL for runtime hosting.
Files you can replace
The Deploy ZIP path keeps runtime deployment understandable for shared hosting and VPS users.
Data you can back up
Content and settings live in a database the site owner controls.
Source you can study
Developers can fork the repository, change themes, build plugins, edit APIs, and create releases.
Daily Workflow
A CMS is something you use every day. Writers need space to draft; reviewers need a clear queue; publishers need to decide when a story goes live. VonCMS separates those responsibilities without granting every writer publishing access.
For site owners
Install the Deploy ZIP, choose a theme, and work from the dashboard. Publish alone, or use Writer submissions and staff review when a team is involved.
For developers
Use the source repository when custom code is needed. Keep changes focused, run the relevant checks, and package deliberately.
Ordinary Runtime
The production runtime should not require Node.js, npm, Vite, or a separate frontend server. VonCMS uses those tools for source development, then ships built assets for runtime hosting.
Open Source
VonCMS is free software under GPL-3.0-only. You can study, modify, and redistribute it under the license terms. Distribution of modified copies carries obligations; hosting and optional services are separate costs.
Open source should mean more than a public download. The repository needs to be understandable enough for someone to inspect architecture, build a theme, change a plugin, review security-sensitive code, and reproduce release checks.
- Docs should point developers toward the right files.
- Release packages should avoid private workspace artifacts.
- Checks should be explicit enough to rerun later.
- Marketing copy should not claim more than the source proves.
SEO Ownership
Readers and search engines need usable public pages. VonCMS handles metadata, social cards, sitemaps, feeds, canonical URLs, robots output, llms.txt, and structured data in the runtime. These are foundations for discovery, not a promise of search rankings.
Security Posture
Security should be handled with evidence and scope, not slogans. VonCMS favors focused boundaries: role checks, CSRF coverage, safe importer behavior, routing rules, sensitive-file protections, and release checks that can be re-run.
Security is ongoing maintenance and verification, not a badge on a landing page.
Product Beliefs
Hostability matters
A CMS that cannot run on ordinary hosting excludes too many real publishing use cases.
Source should be useful
Public code should help developers modify and verify the product, not just satisfy a license checkbox.
Core should carry the basics
Publishing, SEO, themes, extensions, media, users, comments, and repair tools should not require a shopping list.
Claims need restraint
A professional product page should say what changed and what exists, without pretending every feature is revolutionary.