XTen.Stack is a free, security-first PHP application platform — RBAC, reversible audit logging, soft deletes, and a module system for adding features without forking the base app. Self-host it yourself, or have XTen.Deploy build on it for you.
A server-rendered AdminLTE backend — no client-rendered SPA to fight, responsive on any screen. (Screens below are still the template's placeholder images — swap in real XTen.Stack screenshots here.)
The parts every serious application needs and almost always builds last — already built in, already tested.
Session-based login, role-gated controllers, and an API-key path for machine callers — seeded with sensible roles out of the box, not left for you to design from scratch.
Opt-in per model, captures before/after values on every create/update/delete — and unlike a plain activity feed, a reversible entry can actually be reversed, non-destructively, with the original left untouched.
Optional features ship as Composer packages with a manifest, discovered automatically and toggled per-instance from the admin Configuration page. Core application modules stay separate and can't be accidentally disabled.
XTen.Stack itself is $0, forever. These are the paid support plans for self-hosters — see below for XTen.Deploy's done-for-you and per-module pricing.
The full XTen.Stack platform, self-hosted, MIT licensed. No feature gating.
For self-hosters who want a real person answering when something breaks.
For self-hosters running something that can't wait two days for a reply.
Self-hosting XTen.Stack, or anything else: has anyone ever actually restored your backup? A person checks your system against 46 published points, restores your most recent backup on a throwaway instance, and writes down what happened. A one-page summary and a prioritised 90-day plan, written so your own developer can act on it. No obligation afterwards.
Want XTen.Deploy to build it for you instead? Deploy Complete starts from $6,500 fixed; individual Deploy Modules run $850–$2,500 each from a costed spec.
XTen.Stack is early — we'd rather show you our own use than fake a customer list. Here's what the platform actually gives you, proven on ourselves first.
Every build starts roughly 80% finished — auth, RBAC, audit logging with reversal, soft deletes, and a module system are already there. That's weeks of work you don't start from zero on, whether you self-host it yourself or have XTen.Deploy build on it for you. It's already running across four real environments of our own — local dev, an internal dev droplet, a test/staging instance, and production — not just a demo checkout.
The code is yours outright — MIT licensed, no subscription required to keep using it, no vendor to get locked into.
Security defaults are on from the start: CSRF protection, RBAC, audit trails, soft deletes — not bolted on later or reserved for a higher tier.
We stood up a brand-new internal tool the same day we needed one — no droplet, no new database to provision, just php -S pointed at a Postgres database we already had running. A real gap in the base list-view surfaced along the way and was fixed that same afternoon, in the shared codebase every instance runs on.
A safety ladder, not a one-size-fits-all contract: start DIY-free, buy one module, or hand the whole thing over — and move between them as your needs change.
No proprietary runtime, no exotic dependencies — a stack any competent PHP developer can pick up, plus a Composer-package module system for adding features without forking core.
XTen.Register is a free, open directory of Australian businesses and practitioners — every listing ABN-verified against the ATO's own register. It's built on the same data pipeline behind XTen.Stack. Claim your free listing →
Clone it, self-host it, and it's yours — no signup, no credit card, no catch.