HomeWebBlocks UIWebBlocks CMSCommerce GuidePluginsArticles

Technical reference

WebBlocks Commerce documentation

Simple product sales, cart and hosted checkout foundations for WebBlocks CMS sites.

Values below come from the current package manifest and Composer metadata.

Package identity

  • Handle: webblocks-commerce
  • Version: 0.15.1
  • Type: CMS plugin
  • License: MIT

Runtime requirements

  • Current version: 0.15.1
  • Host product: WebBlocks CMS
  • CMS compatibility: ^1.78.22
  • PHP: >=8.3
  • License: MIT
  • Catalog status: Public catalog plugin

Installation is disabled-by-default and setup remains an explicit operator action.

  1. Open System → Plugins in a compatible WebBlocks CMS installation.
  2. Install the catalog release or upload its validated ZIP artifact.
  3. Review the manifest, compatibility and permissions before enabling it.
  4. Enable the plugin, then run explicit plugin setup or migrations when health reports that setup is required.
  5. Confirm plugin health and complete product-specific settings before exposing its public workflow.

Updates: review release notes and compatibility first. Package replacement must not silently enable the plugin or run migrations.

Inspectable behavior contributed to the host product.

Registered surfaces

  • Admin, internal API, public storefront and webhook routes
  • Commerce Buy Button block
  • Stale-order expiry command
  • Storefront CSS and cart indicator

Permissions

  • webblocks-commerce.view
  • webblocks-commerce.manage
  • webblocks-commerce.manage-products
  • webblocks-commerce.manage-orders
  • webblocks-commerce.manage-settings

The public contract describes ownership without exposing secrets or private implementation details.

Data ownership

Owns product, translation, cart, order, order-item and payment-attempt records. Money is stored as integer minor units and order state changes through a guarded state machine.

Security model

Gateway credentials are write-only. Webhooks are notifications, not proof of payment; the plugin re-reads provider state before changing an order.

Disable and uninstall

Disabling makes plugin-owned routes, menus, blocks and behavior inert. Run migrations explicitly after compatible updates. Before uninstalling, export or back up plugin-owned data; package removal and data removal are separate lifecycle decisions.

Health and troubleshooting

Start with the plugin detail screen and health result. Confirm compatibility, required migrations, host services, scheduled commands and external-provider configuration before inspecting application logs.

What exists in the local package today, and what should be expanded next.

Current source set: README, changelog, operator guide and SumUp quickstarts (EN/TR/DE).

Best-documented plugin and the reference standard for the rest of the catalog.