What is Lumora?
Lumora is a visual website builder ready to launch as your own SaaS. Your users build Bootstrap 5 pages by dragging in sections, edit them live (in code too) and publish them in one click to their own subdomain or domain. It ships with accounts, teams, Stripe paid plans, an admin panel and Docker deployment.
It is not a UI kit: every screen in the screenshots is backed by the API, a Postgres database with versioned migrations and automated tests. The video and the animated gallery images show it in action.

01. Visual builder
- Drag and drop from the components panel (mouse and touch): more than 60 Bootstrap 5 components and sections.
- Inline text editing with a double click.
- Properties panel: text, classes, typography, spacing, colors, borders, shadows and attributes.
- Undo/redo (up to 100 steps), duplicate, move, layers tree and breadcrumb.
- "My blocks": save a section and reuse it in any of the team's projects.


02. One-click page styles
The Page style panel restyles the whole page at once: 8 ready-made styles, a brand palette with a readability check (AA/AAA), Google Fonts and corner rounding, with a live preview. It is saved inside the project and exported with it.


03. Real-time code editor
A bottom panel with CodeMirror 6 for HTML, CSS and JS, with two-way sync: what you type is applied to the canvas, and what you do on the canvas shows up in the code instantly. Custom CSS is applied live and travels with the export.


04. Templates
8 starter templates: SaaS, agency, café, photography, blog, yoga studio, event and shop. They are generated from a script, so you can add your own.
05. Responsive design and dark mode
Check every page on desktop, tablet and mobile without leaving the editor. The whole interface (editor, panels, dialogs and legal pages) has light and dark modes, or follows the system setting.



06. Publishing and sites
- Publish to
https://<name>.yoursites.com in one click, with version history (5, 20 or 50 depending on the plan) and restore. - Per-site SEO (description, social image, favicon, language, noindex),
robots.txt and sitemap.xml. - Private 7-day preview links to show a draft to a client.
- Custom domains with DNS verification and automatic HTTPS via Caddy.
- Forms on published sites receive submissions (anti-spam, per-plan quota, email notification and CSV export).
- Visit statistics without cookies or personal data.


07. Teams and collaboration
- Teams with roles (owner, admin, editor, viewer) and email invitations.
- Comments on elements, with replies and resolving.
- Autosave with concurrency control across tabs and members, an anti-loss local draft and a 30-day trash.
- Team activity log.


08. Accounts and sign-in security
Sign-up with email verification, password recovery, two-step verification (TOTP + recovery codes), optional sign-in with Google or GitHub, and account data export and deletion (GDPR). New accounts get a getting-started guide that advances on its own.


09. Plans and Stripe billing
Free, Pro and Team plans per workspace, with limits enforced on the server. Integrates Stripe Checkout, the Customer Portal and signed, idempotent webhooks. In development, payment is simulated without leaving the app. The plan and price catalog lives in a single file (shared/src/plans.ts); without billing (BILLING_DRIVER=none) it works as an internal tool.
10. Administration
A platform panel for the first registered user: figures, user and workspace search, account and site suspension, report handling and a global activity log.

11. Export
Single-file HTML, ZIP (index.html + CSS + JS), ZIP with local Bootstrap for offline use, and a re-importable .json project.

12. Security and operations
- HttpOnly session cookies, scrypt passwords, rate limiting, zod validation and an origin check against CSRF.
- A production CSP that blocks inline and third-party scripts; the canvas sanitizes HTML, and published sites are served on their own domain, separate from the app's.
- Uploaded images are re-encoded with sharp (no EXIF or GPS metadata).
- Docker + Compose (app, Postgres 16, MinIO, Caddy, backups),
/healthz, /readyz, Prometheus metrics, JSON logs and optional Sentry.
13. Quality
More than 250 unit tests (Vitest, also against a real Postgres), 22 end-to-end and accessibility suites (Playwright + axe), strict typecheck and lint. Verified with a clean install from the ZIP (npm ci, build, typecheck, tests and lint).
Requirements
- Node.js 20 or later and npm 10.
- Development: no Postgres install needed (it uses embedded Postgres via PGlite).
- Production: Postgres 16 (managed or the one in
compose.yml), one domain for the app and another with wildcard DNS for published sites. - Optional, with your own keys: Stripe, SMTP or Resend for email, S3/R2 storage, Google/GitHub OAuth and Sentry.
Good to know
- The interface, code and emails are in English.
- The terms and privacy pages are drafts: have a professional review them before opening the service.
- Template images load from the Unsplash CDN (Unsplash License) and are not included in the package.
- No keys or credentials are included: set them in
.env based on .env.example. - Third-party component licenses (MIT, Apache-2.0 and similar) are listed in
THIRD-PARTY-NOTICES.md. - The screenshots, animations and video were made with the real app and made-up demo data.