Screenshots
About MiniShop3
MiniShop3 is a modern, full-featured e-commerce component for MODX 3 — the successor to MiniShop2 (MODX 2). It provides product catalog with options and galleries, cart, checkout and orders, customer accounts with email/SMS verification, deliveries and payments, model fields and grids — all through a Vue 3 + PrimeVue admin UI and a clean REST API for storefront and integrations.
Information
Released
October 9, 2026
Supported Database
MySQL
License
GPLv2
Instructions
New in 1.14.1-beta2
[1.14.1-beta2]
Changed
- Package files are shipped as their own vehicles and no longer written to a
.preserved.zipon every install. Upgrades get faster — 3.1 s to 2.2 s on a warm cache, more on slow disks — at the cost of the Restore uninstall mode for MiniShop3 files: with no archive there is nothing to roll back, so that mode now restores category objects while removing the files. Preserve (the default) and Remove behave exactly as before, and the rollback was already partial because Phinx migrations never roll back (#783).
[1.14.1-beta1]
Fixed
- Upgrading over an installed MiniShop3 no longer dies with
Class "ComposerAutoloaderInit…" not found.bootstrap.phploadsvendor/autoload.phpon every MODX request, so the previous version'scomposer/autoload_real.phpis already in memory when the transport unpacks a newvendor/over it; the migrations resolver then re-readsautoload.php, skips itsrequire_onceon the unchangedautoload_real.phppath and calls a class nobody declared.ms3PhinxEnsureAutoloaderInit()now reads the expected class name out of the newautoload.phpand requirescomposer/autoload_real.phpdirectly when it is missing (#779). - The generated autoloader class name is pinned through
config.autoloader-suffix, so it no longer moves with the package set and cannot desynchronise across releases (#779). - The transport build refuses to package a
vendor/that still holdsrequire-devpackages. 1.14.0-beta1 shipped PHPUnit, PHPStan and the testbench — 45 MB instead of roughly seven (#779).
[1.14.0-beta1]
Added
- Opt-in inventory: stock is reserved on the New status, committed on Paid and released on Canceled, with an atomic ledger in
ms3_inventory_reservationsand sixmsOnInventory*events. Off by default (ms3_inventory_enabled); an external warehouse replaces thems3_inventoryservice (#589, #603, #763). - Payment attempt lifecycle:
ms3_payment_attempts+ms3_payment_attempt_events, a publicPOST /api/v1/payment/webhook/{payment_method_id}endpoint and idempotent webhook replay guarded by a uniqueprovider_event_id. Gateways plug in throughPaymentWebhookHandlerInterface(#590, #604, #626). - Shipment lifecycle:
ms3_shipments+ms3_shipment_events, delivery webhook, tracking numbers and order-status sync, plusGET|PUT /orders/{id}/shipmentin the Manager API and{$shipments}inmsGetOrder. Off by default (ms3_shipment_enabled) (#591, #605, #606, #607). - Order status lifecycle gate: validated transitions with optional
ms3_order_status_transitionsallow-list, in-transaction domain ports and an idempotentensure(). A plugin error after commit no longer reverts the status (#592, #596). - Domain events and an outbound webhook contract:
order.status_changedwith an id/amount-only payload, HMAC-SHA256 signature over{timestamp}.{rawBody}(X-MS3-Signature,X-MS3-Timestamp, 300 s skew), aNullWebhookDispatcherby default and in-process listeners viaDomainEventBridge::addListener()(#593, #764, #772, #774). - Resource-group ACL across the storefront: the public catalog, Fenom snippets and cart honour MODX resource groups; a signed-in customer whose customer group is linked to a MODX user group sees the member catalog (
ms3_web_catalog_respect_resource_groups). NewmsCustomerGroupmodel and Manager CRUD (#659, #666, #677, #681, #757). - Public Category API (
list/get/tree), extendedproduct/listfilters,product/filtersfacets, publicdelivery/listandpayment/list, product gallery inproduct/{id}/images, catalog resolve byalias|uri(#578, #580, #586, #597, #598, #644). - SEO block for the public catalog:
title,description,canonical,robotsand Open Graph fields, TV overlay throughms3_public_seo_tv_map,robotsderived fromsearchable, and themsOnGetPublicSeoevent (#599, #715). - Customer auth contract for SSR front ends:
me,refreshand Bearer binding, plus order-draft prefill from the customer profile after login (#588, #639). - Text watermarks for Media Source thumbnails alongside the existing image overlay, with the font path jailed to the site root (#731, #769).
- Per-category
menuindex: products keep their own order inside additional categories, both in the manager grid and inmsProducts(#625, #627). - Live MODX test suite on
modxkit/testbenchacross MODX 3.1.2-pl, 3.2.3-pl and 3.2.4-pl, with the schema built from Phinx migrations and processor ACL assertions (#687, #698, #699, #712).
Changed
- Vue manager follows the MODX 3 look: the theme comes from VueTools
getActiveTheme()(Aura stays the default,vuetools.theme=modxswitches), control heights in toolbars match MODX, and button sizes are unified across screens (#621, #702, #738, #760, #761, #765, #768). msProductsvalidates stringsortbyagainst an allow-list before it reaches pdoTools: resource and product columns are qualified, declared TVs, vendor fields andsortbyOptionskeys pass through,RAND(),FIELD(),IFNULL(),COALESCE()andCAST()are allowed with checked arguments, and anything else is dropped and logged (#741, #742, #757).- Failed payments no longer cancel the order by default —
ms3_payment_on_failed_statusnow defaults to0, so a customer can retry without a 409. With inventory enabled the reservation stays with the order until it is canceled (#754, #756). - Notifications are sent even when a plugin on
msOnChangeOrderStatusreturns an error: the status is already committed, so the customer is no longer left uninformed (#754, #756). - Package upgrades clean up obsolete files from
coreandassets, skipping anything still listed inms3_frontend_assets, and migrations always run on MiniShop3's own Phinx instead of another extra's copy (#690, #709, #726, #728). - CORS preflight is answered before the middleware stack, without touching the MODX session or poisoning the cache (#637, #708, #725, #727).
Fixed
- Customer lockout: a temporary lockout no longer blocks password reset, permanent blocks revoke tokens, and the failure counter resets once the lockout expires (#734, #747, #748).
PdoPaymentAttemptStoreno longer swallows write errors on the MODX connection (ERRMODE_SILENT): duplicate keys are reported honestly and failed statements raise instead of passing silently (#752, #753).- Repeated delivery webhooks heal an order status that drifted from the shipment, and a duplicate claim no longer re-emits
msOn*events (#754, #756). - Option suggestions in the manager return distinct values again (#745, #746).
- Manager connector never emits invalid UTF-8 or an empty JSON body on broken input (#662, #676, #691, #618).
- Gallery and product sorting honour
msproductfile_save/msproduct_savepermissions, and order field ACL followsminiShopManagerPolicy(#614, #661, #675). - Facet and page caches are invalidated when resource-group ACL, group membership or a customer-group link changes (#735).
- Cart accepts JSON strings for
optionsincart/addandcart/change-option(#633, #638). - A poisoned English lexicon cache under a non-English key is healed once after install or upgrade, restoring translated product tabs (#758, #759, #767, #771).
Notes
- Documentation for inventory, shipment and payment attempts is not in
docs.modx.proyet — it follows in a separate update.