Timberdocs

Help

FAQ

The basics#

Is Timber free? Yes. It's open source — see Open source & contributing.

Do I need a database? No. Content lives in JSON files in data/.

What do I need to host it? Any PHP 8.1+ web server. See Requirements.

Can I run it on localhost? Yes: php -S localhost:8430 router.php.

Can I use it on shared hosting? Yes — that's a main use case. Upload the files, open the site.

How big is it? About 1.7 MB and around 160 files.

Compared with WordPress#

Is it a WordPress replacement? For blogs, portfolios, studio, product and small-business sites edited by one or two people — yes. For multi-user, e-commerce or plugin-dependent sites — no. See Timber vs WordPress.

Can I use WordPress plugins or themes? No. Timber has its own themes (Building themes) and builds in most of what plugins are used for (Built-in vs plugins).

Can I move my WordPress site over? Yes, with the migrator wizard.

Using it#

Can several people edit? Yes. Add administrators, editors (posts only) and read-only users, each with their own email and password. See Users & roles. (Timber has no member or subscriber accounts for your visitors.)

Can I change the design? Yes: Design → Branding for logo and colours, the Playground to edit and switch designs, or edit theme code directly.

Can I use my own fonts? Yes. Add @font-face rules to your theme CSS (or Global CSS) and upload font files to assets/. Starter themes use system fonts so nothing is downloaded by default.

Does it do multilingual sites? Not yet.

Does it support e-commerce? No — embed a hosted checkout (Stripe Payment Links, Gumroad, Shopify buy buttons) in a page or Block.

Does it have comments? No. Embed a third-party widget in a Block if you need them.

Is there a REST API? Not as a product feature. Timber is server-rendered HTML.

Speed and scale#

Is flat-file fast enough? For sites up to a few thousand records, yes — pages are a few small file reads. See Data & storage.

Do I need a cache plugin? No. You can put a CDN or Varnish in front for public pages; admin pages are never cached.

Safety#

Is sign-in safe? Passwords are hashed, sign-in is throttled, every admin action is CSRF-protected and permission-checked by role, and it's meant to be used over HTTPS. See Security model.

I forgot my password. Run php _dev/reset-password.php "new password" on the server, or ask another administrator to reset it. See Users & roles.

Where is my data? Only on your server, in data/ and uploads/.

Open source#

Can I use it for client sites? Check the license file in your download for the exact terms.

Can I contribute? Please do — see Open source & contributing.

Timber is open source. Built by indies, for indies. © 2026