Upload
Choose the complete ZIP. plugin.json must be at its root.
Rules
Clear expectations for safe packages, trusted publishers, and family-account privacy.
Publishing standard
Start with one standalone ZIP. Racinage detects the catalog details, keeps source quarantined, and publishes only after automated and human review.
Five predictable steps. Your source is never activated during upload.
Choose the complete ZIP. plugin.json must be at its root.
Paths, size, manifest, entrypoint, and media are inspected without executing code.
Review the detected name, description, features, permissions, and catalog images.
Explain pricing, plan limits, provider costs, support, refunds, and compatibility.
Racinage reviews security, privacy, tenant isolation, UX, and claims before publishing.
The manifest is the contract between the author, Racinage, and the user.
{
"slug": "meal-planner",
"entrypoint": "runtime.php",
"assets": { "logo": "assets/logo.webp" },
"feedback": {
"duration": 10000,
"position": "center-top",
"show_close_button": true
},
"capabilities": {
"pages": ["/dash/plugin/meal-planner"],
"functions": ["Read selected people"]
}
}Use a verb, a specific target, and the condition that allows it.
Four groups make the standard easier to scan and harder to misunderstand.
Use this before submitting a new plugin or update.
Request developer permission first. If you plan to sell paid plugins, complete the publisher payout profile before review.
Request developer permission