AtmaJyoti CMS technical specifications
One file. Zero dependencies. Full control.
AtmaJyoti CMS is an entire content, booking, analytics and security system inside a single server.js — no npm packages, no database, no build step. It runs on Node.js over Windows / IIS / Plesk and is readable end to end.
Architecture with no attack surface
Every line is yours. Nothing comes from third parties.
Zero npm dependencies
No third-party library means no supply-chain gap — the problem that has hit thousands of Node projects. Whatever runs, you can see it.
npm ls → (empty)One readable file
The entire system lives in one server.js. You need no tools, bundlers or framework knowledge to review or change it.
Flat-file JSON storage
Data in plain JSON files. Backup = folder copy. No SQL injection surface, no database service to maintain.
data/*.json + in-memory index600+ tests, two-stage review
The test suite runs on the built-in node:test — no Jest, no Mocha. Every security change also passes an independent second review before it ships.
Enterprise-grade security stack
Tested in production against constant, real-world attacks.
"It's no longer just a flat-file CMS. The security & operations layer — a firewall with progressive bans, shared multi-site defence, crawler verification, integrity monitoring — is the kind of capability you usually find in managed enterprise platforms."
Built for real deployment
Windows / IIS / Plesk — production, not theory.
Windows / IIS / Plesk
Runs native via iisnode with a ready, tested web.config — request filtering, HTTPS detection, separate log directories.
web.config · hardenedNew version, no recycle
Upload the new file and it loads by itself within seconds; the integrity check recognizes the upgrade and refreshes its fingerprint.
self-reload · integrity_upgradePerformance without a database
In-memory index and caches for pages, settings and analytics, incremental log reading, minified public code — fast even on a modest server.
in-memory index · incremental logsResilient in operation
Schedulers with retry/backoff, exception handlers, health checks and log rotation — one error won't take the site down, the disk won't fill up.
graceful degradationRecycle bin & history
Pages with full version history, posts, events, to-dos, subscribers, FAQ, polls, forms, PDFs, media — soft-delete with restore.
restore · version historyBackup = copy
With no database, a backup is one file or a folder copy. Move to a new server without migrations, without dumps.
copy data/ → doneDiagnostics & resources
SMTP, scheduler, RAM, disk, worker PID, heartbeat — and a trace for every alert email (sent / failed / skipped).
diagnostics · heartbeatMany sites, one server
Each site in its own folder and application pool; a shared folder only for what benefits all of them (bans, geolocation cache), with least privilege.
least privilege · shared defence