Timberdocs

Introduction

Why Timber?

Most websites are small. A homepage, an about page, a blog, a contact form, a few images. Yet the usual ways of building them ask for a lot: a database server, a plugin for every feature, a build pipeline, a monthly bill for the hosting that runs all of it.

Timber starts from the opposite end: what is the least machinery that gives a small site a proper CMS?

The itch#

  • You want a real admin — not "edit the HTML and re-upload" — but WordPress feels like a lot for a five-page site.
  • Static-site generators are fast, but your collaborator or client can't use Git, and "rebuild and deploy" is friction.
  • Hosted site builders are easy until you want to own your content, change the code, or stop paying per feature.
  • Every plugin you add is another thing to update, another attack surface, another page-weight tax.

What Timber does differently#

Simple#

One folder. JSON files instead of MySQL. Admins, editors and read-only users — and nothing else to configure. Back up by copying a directory. Move hosts by copying a directory.

Fast#

Pages render straight from PHP with no query layer, system fonts, no third-party requests by default, and a few kilobytes of JavaScript.

Fuller#

Forms, SEO, redirects, privacy, email, maintenance mode, a media library, a code editor, import/export — the things you'd normally install five plugins for.

Modern#

A live-preview Playground, side-by-side site versions, htmx and Alpine in the admin, Google Consent Mode v2, an RSS feed, JSON-LD — and designs that look current out of the box.

The principles#

  1. No build step. Edit a file, refresh, it's live. Nothing to compile, bundle or transpile.
  2. No required third-party service. Not a database, not a CDN, not a SaaS. Optional integrations are optional.
  3. Settings over code. If an owner might want to change it, it's a field in the admin.
  4. Boring where it counts. Plain PHP, plain JSON, plain HTML. You can read the whole thing in an afternoon.
  5. Secure by default. CSRF on every POST, hashed passwords, role checks on the server, login throttling, internals blocked at the web-server level, non-executable uploads.
  6. Easy to leave. Your content is JSON, your uploads are files, your theme is a folder. Export the whole site as a .zip any time.

Made by indies, for indies#

Timber grew out of a real production site that needed a CMS the team could run without an ops person. It was generalised into a product for people in the same position: small teams who ship things and would rather spend time on the site than on the stack beneath it.

Timber is open source. Built by indies, for indies. © 2026