Pandao CMS
Documentation · Version 8.2.0

Your website, your way.

Pandao CMS runs professional websites: pages built block by block, a blog, widgets, forms, media and menus, in as many languages as you need, with an administration that stays simple and a security built in. Extensions add what your business needs.

  • Pandao CMS 8.2.0
  • PHP 8.2 – 8.5
  • MySQL 5.7+ · MariaDB 10.3+
  • Responsive · Multilingual · RTL
www.your-site.com
Home page of a site made with Pandao CMS: slideshow and features
The same home page on a phone
Welcome

Thank you for choosing Pandao CMS

This guide takes you from the upload of the files to a site of your own, then through every screen of the administration. It is written for site owners as much as for web developers: no coding is needed to run a site, and the last chapters are there for those who want to go further.

Pandao CMS manages the website itself: pages, articles, menus, widgets, media, forms, languages, users and e-mails, with a responsive theme. Its extensions add whole features without touching its code, as Panda Multi Resorts adds a hotel booking engine.

If a question is not answered here, the troubleshooting section and the Diagnostic screen of your administration solve most issues in minutes. For anything else, our support is happy to help: include the report of the Diagnostic screen, it tells us everything about your server without any password.

Highlights

Everything a website needs

What a professional website needs, in one administration, without plugins to hunt for.

Simple to manage

Pages, articles, widgets and slides edited in the same clear forms, with a tab per language and a draft kept as you type.

A page builder

Compose a page with containers, columns, texts, images, videos, buttons and cards, by drag and drop, then edit each block in place.

Widgets everywhere

Slideshow, banners, parallax and video backgrounds, article grids, testimonials, contact details: placed on every page or on the ones you choose.

In every language

Each page, article, widget, menu and e-mail in each language of the site, right-to-left ones included, with a language selector.

Forms without code

Build a form field by field, place it in any page with a shortcode, receive the answers by e-mail and keep them in the administration.

A media library

Folders, images resized for every screen with a lighter WebP copy, and the point of each image kept in view when it is cropped.

Found by search engines

Clean addresses, titles and descriptions, canonical and hreflang tags, a sitemap, and old addresses redirected when they change.

Secure by design

Protected forms, strict security headers, modern password hashing, limited login attempts, a cookie banner with “Reject all”.

Extensions

Modules, pages, widgets, settings and scheduled tasks added by extensions, which install and update in one click.

Your brand

Your logo and your two colours set in the settings, and a child theme for deeper changes that updates never overwrite.

Made for phones

Every page of the website and of the administration works on a phone and a tablet.

A Diagnostic screen

PHP, database, server and scheduled tasks checked for you, with a report to join to a request for support.

For customers of version 7

New in version 8

Version 8 is a new generation of Pandao CMS for PHP 8.2 to 8.5: hardened, extensible, and easier to use every day. See Upgrading from version 7 before you move a site.

AreaVersion 7Version 8
PlatformPHP 7 and 8PHP 8.2 to 8.5, MySQL 8 and MariaDB, libraries installed, no Composer needed
Security—Rewritten routers, prepared queries, protection against forged requests, security headers, limited login attempts, errors logged but never shown
Extensions—An Extensions page: modules, pages, widgets, settings, roles and scheduled tasks added by extensions, with their database updates
ContentPages and articlesPage builder, form builder, popups, media library with folders and focal points, trash, drafts kept as you type, editing locks
WebsiteFont Awesome, sample content in lorem ipsumWidgets in any position, right-to-left languages, cookie banner with “Reject all”, privacy policy page, open-licence icons and photos, real sample texts
Administration—Menu in sections, Diagnostic screen, lists with filters by owner, seven languages of the administration
Moving a site—Import of a version 7 site in a few clicks: content, accounts, media and settings, with their addresses
See it live

Live demo

The online demo runs this very version with the sample texts of the package. Its photos are shown for preview only and are not included: the package comes with its own sample photos, under the CC0 licence.

Websitecms.pandao.eu
Administrationcms.pandao.eu/admin
Loginadmin / admin123

The administration of the demo is read-only, and what visitors create (comments, messages) is visible to other visitors and deleted every night. Do not type real personal details.

Getting started

Requirements

Pandao CMS runs on most shared hosts, VPS and managed servers. Once it is installed, the Diagnostic screen checks every point below on your own server.

ComponentNeededAdvised
PHP8.2 to 8.58.3 or 8.4
PHP extensionscurl, dom, fileinfo, gd, mbstring, openssl, pdo, pdo_mysqlintl, so that dates are written in the language of each page
DatabaseMySQL 5.7 or MariaDB 10.3, with the utf8mb4 character setMySQL 8 or MariaDB 10.6 and later
Web serverApache 2.4 with mod_rewrite and .htaccess files allowed, or IIS with URL Rewrite (web.config included)nginx in front of Apache, as on Plesk and many cPanel hosts, works as it is
Secure connection—HTTPS on the whole site (a free certificate from your host)
PHP memory128 MB256 MB
Getting started

Package contents

The main file downloaded from CodeCanyon holds this documentation and the website, ready to upload. The PHP libraries are already installed: you do not need Composer.

pandao-cms-8.2.0/
├── documentation/            this documentation: open index.html
└── upload/                   the website: upload the contents of this folder
    ├── admin/                the administration (www.your-site.com/admin)
    ├── bin/                  command line: scheduled tasks and extensions
    ├── config/               the configuration, written by the installation wizard
    ├── extensions/           the extensions you add
    ├── public/               public files: media, brand images
    ├── setup/                the installation wizard
    ├── templates/default/    the theme of the website
    ├── vendor/               PHP libraries
    └── common/, core/, …     Pandao CMS
Getting started

Installation

Allow about five minutes.

  1. Create a database

    In your hosting panel (MySQL Databases in cPanel, Databases in Plesk), create an empty database with the utf8mb4 character set, and a user who has every privilege on it. Keep its name, its user, its password and its host (often localhost) at hand.

  2. Upload the files

    Upload the contents of the upload/ folder to the web root of your domain (often public_html/ or httpdocs/), or to a sub-folder such as public_html/site/. The quickest way is to upload the zip with the file manager of your host, extract it there, then move the contents of upload/ into place. With an FTP client, make sure the hidden .htaccess files are sent too.

  3. Run the installation wizard

    Open the address of your site: the wizard starts by itself. Give the title of the site, its public address (https://www.your-site.com, without a slash at the end), the e-mail address that receives the notifications, the login and password of the administrator (12 characters at least), then the details of the database. Click Install.

    www.your-site.com
    The installation wizard with its General and Database fields

    The wizard writes config/config.php and public/robots.txt: PHP must be allowed to write in config/ and public/ while it runs, which is the case on most hosts.

  4. Log in

    Click Log in and sign in with the administrator account: the dashboard opens, and your site is ready to be made your own.

The site works in a sub-folder and on a sub-domain: its base path is found by itself. The administration is at https://www.your-site.com/admin/.

Once the site is installed, the wizard locks itself. You can still delete the setup/ folder and remove the write permission on config/config.php, two good habits on a live server.

Getting started

Sample content

A new site does not open on an empty page: it shows what each block can do, in English and French, ready to be replaced by your own words.

The home page

A slideshow of two slides, a list of features, a featured article, an advertising banner, cards of articles, a full-width banner, a video background and a parallax section, then the footer: contact details, navigation and an “About us” text.

The pages

A Features page built with the page builder, with four articles; a Contact page with its form and its map; Legal notices and a Privacy policy to complete; a blog, a search page and a “Not found” page.

The photos are under the CC0 licence and the video is in the public domain: you may keep them on your site. Every sample is edited or unpublished like any content. A site with one language only keeps the English texts.

Getting started

Launch checklist

The settings to review before you open your site, in the order that saves time.

  1. General settings

    Settings › General: title of the site, public site URL, time zone, date and time formats, the languages (Enable foreign languages) and the template.

    www.your-site.com/admin/module=settings
    The General tab of the settings
  2. Contact details and e-mails

    Settings › Contact: name, address, phones and e-mail of your company, shown in the header, the footer and the contact page. Settings › Email settings: the sender, and the SMTP server of your mailbox for a reliable delivery.

  3. Your brand

    Settings › Appearance: logo, footer logo, e-mail banner, favicon and brand colours. See Branding & theme.

  4. Your content

    Replace the sample texts and photos, page by page: the home page and its widgets, the Features page, the articles and the footer.

  5. Your legal pages

    The Legal notices and Privacy policy pages hold model texts: complete the passages between brackets.

  6. The anti-robot check

    Create reCAPTCHA keys on google.com/recaptcha and paste them in Settings › General (Captcha: public key and secret key): the contact form, the forms and the comments are then checked.

  7. Your users

    Change the password of the administrator if needed, and create an account for each person who edits the site, with the right role (Users & roles).

For customers of version 7

Upgrading from version 7

Version 8 is a new generation: its database has new tables and columns, its administration new screens, and its theme new widget positions. It is installed as a new site beside your version 7 site, then imports its content in a few clicks. The old site is only read: it keeps working until you switch.

  1. Back up

    The files and the database of your version 7 site.

  2. Install version 8

    Follow the installation in a folder beside the old site, on the same hosting (a temporary sub-domain is ideal), with a new, empty database: never reuse the one of the old site.

  3. Import your site

    In Settings › Database, click Import a Pandao CMS 7 site. The sites found beside the new one are offered: choose the old one, or type its folder, the one that holds its config folder. The screen lists what it holds; tick the confirmation, click Import, and keep the page open until the report, usually within a minute.

  4. Read the report

    It lists what is left to do: set your brand colours, look again at the pages whose layout you had changed in the theme of version 7, complete the privacy policy page that was added. Then browse the new site.

  5. Switch the domain

    Point your domain to the folder of the new site, and update the Public site URL in Settings › General.

The import takes the languages, pages, articles, menus, widgets, slides, media library, comments, messages, popups, texts, e-mails and accounts of the old site, the files of its media, its logos and its settings. Each page and article keeps its address, so that links and search rankings follow, and each account its password. What version 8 adds is kept, in your languages: its new texts and e-mails, the privacy policy page and the slideshow widget. The content of the new site is replaced; its administrator account stays.

The import also runs from the command line, handy for a large site: php bin/pandao import:v7 /path/to/old-site shows what it holds, and --run imports it. An import stopped on the way resumes where it stopped.

Keep the old site and its database offline for a few weeks. If you need help, our support answers.

Getting started

Updating

New versions are published on CodeCanyon, in your Downloads, with their notes in the changelog.

  1. Back up

    The files and the database of the site.

  2. Upload the new files

    Upload the contents of the upload/ folder of the new package over your site. Your configuration (config/config.php), your media and your brand images are not in the package: they are kept. Changes made to the theme belong in a child theme (see Customisation), so that an update never overwrites them.

  3. Apply the updates of the extensions

    When an extension receives new files, every screen of the administration shows a banner with its new version and an Update now button (also offered in Extensions). Click it when the upload is complete: its database is brought up to date in a few seconds. Until then, its pages tell your visitors that the site is being updated, with a code that search engines read as temporary.

Content

The administration

Everything is managed from https://www.your-site.com/admin/, on a computer, a tablet or a phone.

www.your-site.com/admin/
The dashboard of the administration

The menu on the left groups the modules in sections: Content (pages, articles, slideshow, widgets, popups, menus, media, tags), Communication (comments, messages, forms, e-mail templates) and Configuration (texts, social links, languages, locations, currencies, users). Each extension adds its own section. Settings, Extensions, Diagnostic and Trash sit beside them.

Every module has a list, with a search, filters, sorting by drag and drop when the order matters, and actions on several items at once (publish, unpublish, delete), and a form, with a tab per language for what is translated.

Content

Pages & page builder

The pages form the tree of your site: each has its place, its model, its address and its text.

www.your-site.com/admin/module=page&view=list
The list of the pages

The page builder

The text of a page is composed with the page builder: drag containers, rows of one to four columns, headings, texts, images, videos (YouTube, Vimeo or a file), buttons, cards and separators, then write in each block. Code shows the HTML of the page, to copy it or paste one.

www.your-site.com/admin/module=page&view=form
The page builder with the blocks of the Features page

A form built in Forms is placed in a page or a widget with its shortcode, such as [form id="quote"].

Content

Articles & blog

Articles are the news, posts and stories of the site. Each article belongs to a page, which lists it (a blog page, or any page), and has its own page too.

www.your-site.com/en/features
The Features page with its text and its articles
Content

Slideshow & widgets

The blocks of the pages are widgets you place, order, translate and hide in Content › Widgets, without touching any code.

www.your-site.com/admin/module=widget&view=list
The list of the widgets

Widgets of the theme

Slideshow, full-width banner, parallax background, video background, list with icons, featured article, featured articles, latest articles, article grid, image carousel, testimonials, Google reviews, contact information, list of pages, footer menu, and your own HTML content.

Where they go

Each widget has a position (top of the page, before or after the main content, left or right column, columns of the footer), its pages or all of them, its order and its languages. Extensions add their own widgets.

The slides are edited in Content › Slideshow: an image or a YouTube video, and a text with its title, in each language. On the home page, the title of the first slide is the main title of the page for search engines.

Content

Media library

All the images and files of the site, in folders, in Content › Media, and from the text editor.

www.your-site.com/admin/module=media&view=list
The media library with its folders
Content

Popups

A popup (Content › Popups) shows a message over the page, once per visit: an announcement, an offer, a closing notice. It has its text in each language, its background colour, its pages or all of them, and its publication dates.

Communication

Forms & messages

Build the forms you need, field by field, without code: a quote, a registration, a survey.

  1. Create the form

    In Communication › Forms: its title, its identifier (used in the shortcode), the addresses that receive the answers, whether the answers are kept in the administration, the subject of the e-mail, the label of the button and the message shown once it is sent.

  2. Add its fields

    Text, e-mail, phone, number, date, long text, list, check boxes or radio buttons, with their label, their placeholder and whether they are required, in each language.

  3. Place it

    Paste its shortcode, such as [form id="quote"], in a page or a widget.

The messages of the contact page and the answers kept are listed in Communication › Messages. Forms are protected against robots by reCAPTCHA when its keys are given, and limited per visitor.

Communication

Comments & ratings

Turn on the comments, and the ratings, in the form of a page or an article. A comment waits in Communication › Comments until you publish it. The published comments with a rating of a page are shown by the Testimonials widget of that page.

Communication

E-mails

Every e-mail of the site is a template of Communication › Emails content, in each language, with variables such as {name} or {site_url} replaced when it is sent: the confirmation of an account, the request of a new password and the password itself, a message of the contact page. Extensions add their own templates.

The e-mails carry the banner of Settings › Appearance, and are sent through the SMTP server of Settings › Email settings when you give one. Microsoft 365 with OAuth needs the league/oauth2-client library, installed with Composer. A sender address of your own domain, and the SPF and DKIM records of your domain set with your host, help delivery a lot.

Configuration

Languages & texts

Offer your site in as many languages as you need, right-to-left ones included.

  1. Turn on Enable foreign languages in Settings › General: the language selector appears in the header, and the addresses carry the language (/en/…, /fr/…).
  2. In Configuration › Languages, publish or add a language: its name, its code (de), its locale (de_DE), its flag and, for Arabic or Hebrew, right to left. Each content receives a copy to translate, in the main language.
  3. Translate the content in each form (a tab per language), then the interface: Configuration › Texts for the texts of the website, and Communication › Emails content for the e-mails.
www.your-site.com/fr
The home page in French, with the language selector open

In a right-to-left language, the whole website is mirrored: menus, carousels, forms and buttons. The administration is available in English, French, Spanish, Portuguese, Dutch, Russian and Turkish, chosen in Settings › General (Admin panel language).

Configuration

Users & roles

In Configuration › Users, each account has a role:

RoleWhat it does
AdministratorEverything, settings, extensions and users included.
ManagerThe content and the communication of the whole site.
EditorThe content of the site, according to the permissions of each module.
RegisteredA member of the website, with its account page when the site offers one: no access to the administration.

Extensions add their own roles, with the only permissions they need. Each user changes their name, e-mail and password in Settings › Profile.

Configuration

Branding & theme

Your logo and your colours, without editing a file: Settings › Appearance.

www.your-site.com/admin/module=settings#appearance
The Appearance tab: visual identity and brand colours

The website uses the default theme of Pandao CMS, chosen in Settings › General › Template. To change the theme itself, create a child theme (see Customisation).

Configuration

Social links, locations & more

Site

SEO

Site

Privacy & security

Privacy

  • A cookie banner (Settings › General) with Accept all, Reject all and Customise, as European regulators ask. Its texts are in each language (Configuration › Texts, COOKIES_*).
  • A privacy policy page with a model text to complete, which the banner links to, and that extensions complete with their own section.
  • Members delete their account themselves from their account page.

Security

  • Prepared SQL queries, protection of every form against forged requests, security headers, and routes limited to what exists.
  • Passwords hashed with the current algorithms; login attempts limited per address and per account.
  • Errors written in the log of the server, never shown to visitors.
  • Uploads checked by their content, and media kept in their folders.
  • Secret keys are never displayed again once saved.
Site

Maintenance mode

Turn on Maintenance mode in Settings › General while you prepare your site: visitors see a page with your message, and search engines are told to come back later (code 503), while you, logged in to the administration, browse the site as usual.

Site

Trash, drafts & locks

Site

Diagnostic

The Diagnostic screen, next to the settings, checks PHP, the database, the server and the scheduled tasks, and says what to ask your host.

www.your-site.com/admin/module=diagnostic
The Diagnostic screen

Copy the report copies a report without any password, to join to a request for support.

Scheduled tasks

Pandao CMS runs the scheduled tasks of its extensions: a site without extension has none. When an extension needs them, add a cron job that runs bin/pandao cron every minute: Diagnostic › Advanced configuration shows the exact line for your server, with the path of its PHP. It looks like this:

* * * * * /usr/bin/php /home/your-account/public_html/bin/pandao cron >/dev/null 2>&1

Without a cron job, the site runs the tasks itself after a visit, at most every ten minutes, on hosts that use PHP-FPM (most of them).

Developers

Customisation

Keep your changes out of the files of the package, so that every update stays a simple upload.

A child theme

A theme is a folder of templates/. A child theme only holds the files it changes: every file it does not have is taken from the default theme.

  1. Create templates/my-theme/ (lowercase letters, digits, hyphens).
  2. Add your styles in templates/my-theme/assets/css/custom.css, loaded after the styles of the theme.
  3. To change a template, copy it at the same path from the default theme: views/partials/header.php, views/partials/footer.php, views/page.php, widgets/featured_home.php…
  4. Choose it in Settings › General › Template.

A copied template no longer receives the improvements of the updates: prefer CSS when it is enough, copy only what you must, and compare your copies with the new versions after an update.

Texts and e-mails need no code: they are edited in the administration.

Developers

Extensions

An extension adds a whole feature to the site (a booking engine, a shop, a directory) without touching the files of Pandao CMS, so that each one is updated apart.

www.your-site.com/admin/module=extensions
The Extensions page
Developers

Build an extension

An extension is a folder of extensions/, whose name is its identifier (lowercase letters, digits and underscores).

extensions/my_extension/
├── extension.json            its manifest
├── src/Extension.php         Pandao\Extensions\MyExtension\Extension
├── admin/modules/            its modules of the administration
├── admin/langs/              its texts of the administration
├── templates/views/          its pages, which a theme can override
├── public/                   CSS, JS and images, served under /extensions/my_extension/
└── migrations/0001_create_tables.php
{
    "name": "my_extension",
    "title": "My extension",
    "description": "A short text shown in the administration.",
    "version": "1.0.0",
    "requires": { "pandao": "^8.1", "php": ">=8.2" },
    "admin": { "title": "My extension", "icon": "puzzle-piece", "menu": ["item"] }
}

The register() method of its Extension class declares what it adds: routes of pages and system routes, XHR actions, screens and actions of the administration with their permission, widgets, settings, roles, scheduled tasks, and hooks (actions and filters) such as front.head, front.footer, admin.dashboard or sitemap.entries. It only declares: it runs at each request, without touching the database.

A migration is a PHP file that returns static function (\PDO $db): void; the migrations run in the order of their numbers, once, at the activation and at each update, and their history is kept. "multilingual": true in the manifest opens a new site in its languages, when the extension ships with Pandao CMS in a package.

Developers

Command line

From the folder of the site, with the PHP of the site and its user:

php bin/pandao cron                                # runs the scheduled tasks that are due
php bin/pandao extension:list                      # lists the extensions and their state
php bin/pandao extension:enable my_extension       # enables an extension, as the Extensions page does
php bin/pandao extension:update my_extension       # applies the update of an extension
php bin/pandao extension:disable my_extension      # disables it, and keeps its data
php bin/pandao import:v7 /path/to/old-site         # what a version 7 site holds
php bin/pandao import:v7 /path/to/old-site --run   # imports it into this site

To display the PHP errors while you investigate a problem, add define('PMS_DEBUG', 1); to config/config.php, then remove it: a live site never shows its errors, it writes them in the PHP log of the server.

Help

Troubleshooting & FAQ

Start with the Diagnostic screen: it checks PHP, the database, the server and the scheduled tasks, and says what to ask your host.

The wizard does not open, or every page answers “Not found”

The .htaccess files were not uploaded (they are hidden: show the hidden files in your FTP client), or the server ignores them. Ask your host to turn on mod_rewrite and allow .htaccess files (AllowOverride All). On IIS, URL Rewrite reads the web.config file.

A blank page or an “error 500”

Check the version and the extensions of PHP (see Requirements), then the PHP error log of your hosting panel. define('PMS_DEBUG', 1); in config/config.php shows the error for a while.

E-mails do not arrive

Give the SMTP server of your mailbox in Settings › Email settings, with a sender address of your own domain, and look in the spam folder.

The map of the contact page is empty

Give a Google Maps key in Settings › General, and at least one place in Configuration › Locations.

An image looks cut

Set its focal point in the media library: the part of the image you choose stays in view.

A language is missing from the selector

Turn on Enable foreign languages, and publish the language in Configuration › Languages.

An extension is shown as Incompatible

It needs another version of Pandao CMS or of PHP: its line says which. Update Pandao CMS, or ask your host for the version of PHP it needs.

Help

Support

We answer through the Support tab of the page of Pandao CMS on CodeCanyon.

Item pagecodecanyon.net
Authoritems.pandao.eu
Live democms.pandao.eu
Help

Credits & licences

Pandao CMS is made by Pandao and sold under the licences of Envato Market. It includes the following resources, each under its own licence. The photos of the online demo, which the screenshots of this guide show, are for preview only and are not included.

ResourceLicence
Sample photos and videoCC0 (StockSnap) and public domain (NASA): docs/CREDITS.md
Phosphor IconsMIT
Rubik, Urbanist, Sora (fonts)SIL Open Font License 1.1
Bootstrap 5, jQuery, jQuery UIMIT
Owl Carousel, Magnific Popup, Animate.css, imagesLoaded, jQuery Appear, jQuery matchHeight, js-cookie, c-shareMIT
jQuery LazyMIT or GPL-2.0
Bootstrap Star RatingBSD-3-Clause
IsotopeGPL-3.0, or commercial licence of Metafizzy
MeanMenuGPL-3.0
CKEditor 5 (text editor of the administration)GPL-2.0 or later, or commercial licence of CKSource
UploadiFive (uploads of the administration)UploadiFive Standard License
PHPMailerLGPL-2.1
Help

Changelog

Version 8.2.0 New

The first version 8 of Pandao CMS sold on its own. A new generation for PHP 8.2 to 8.5 (see New in version 8):