always one step ahead
🔍

AtmaJyoti CMS technical specifications

// single-file · zero-dependency · self-hosted

One file. Zero dependencies. Full control.

AtmaJyoti CMS is an entire content, booking, analytics and security system inside a single server.js — no npm packages, no database, no build step. It runs on Node.js over Windows / IIS / Plesk and is readable end to end.

1
server.js file
0
npm dependencies
600+
automated tests
JSON
flat-file storage
01

Architecture with no attack surface

Every line is yours. Nothing comes from third parties.

every request passes through successive filters before it reaches the content
→real client IPtrusted-proxy model · spoofed headers ignored
→connection-rate limitersliding window per IP · 429 on flood
→ban list · local + sharedprogressive duration · shared by all sites on the server
→geo-block · datacenter · bot verificationby country · official Google/Bing/Apple networks
→scanner trap · 404 burstsattack signatures → instant logging & ban
→CSRF · session · 2FA · rolesconstant-time · HttpOnly · SameSite · central authorization gate
→router → server.jsflat-file JSON · in-memory index & cache
→content + admin UIpages · blog · appointments · newsletter · analytics
zero supply-chain risk

Zero npm dependencies

No third-party library means no supply-chain gap — the problem that has hit thousands of Node projects. Whatever runs, you can see it.

npm ls → (empty)
auditable

One readable file

The entire system lives in one server.js. You need no tools, bundlers or framework knowledge to review or change it.

1 file · fully auditable
no database

Flat-file JSON storage

Data in plain JSON files. Backup = folder copy. No SQL injection surface, no database service to maintain.

data/*.json + in-memory index
tested & reviewed

600+ tests, two-stage review

The test suite runs on the built-in node:test — no Jest, no Mocha. Every security change also passes an independent second review before it ships.

node test.js → 0 fail
02

Enterprise-grade security stack

Tested in production against constant, real-world attacks.

Firewall & automatic defence
[✓]
Auto-ban (fail2ban-style)Offense accumulation → automatic ban + email alert, with a detailed reason.
[✓]
Progressive ban durationRepeat offenders are blocked for longer, up to permanently — with a full history per IP.
[✓]
Scanner trap & secret probesAnyone hunting for passwords, keys or known holes is blocked on the first request.
[✓]
Datacenter-awareZero tolerance for suspicious activity from cloud / hosting networks.
[✓]
Shared ban list (multi-site)A ban on one site applies to every site on the server within seconds — with least-privilege file permissions.
[✓]
Crawler verificationGooglebot / Bingbot / Applebot are verified (DNS + official networks) — the fake ones are not.
[✓]
Geo-IP country blockingBlock by country, with a separate list for the admin and an optional fail-closed mode.
[✓]
Connection-rate limitingSliding window per IP; instant 429 on flood/DoS.
Identity & access
[✓]
2FA (TOTP)QR code, recovery codes and trusted devices.
[✓]
scrypt password hashingMemory-hard hashing, constant-time verify, password-strength policy.
[✓]
Session hardeningMaximum lifetime, device binding, forced logout — a stolen cookie doesn't live forever.
[✓]
Roles & central authorizationEvery admin endpoint is checked centrally — not just buttons hidden in the UI.
[✓]
Brute-force lockout + honeypotLockout after failures, with a bot trap on forms.
[✓]
Login alerts (success & fail)Email with user, time, IP, country — instant intrusion detection.
Application & data
[✓]
CSRF on every admin POSTPer-session token with constant-time comparison — uploads included.
[✓]
XSS defence in depthEscaping everywhere, HTML sanitizing for non-admins, CSP and an SVG sandbox.
[✓]
File integrity monitoringSHA-256 fingerprint of the code + web-shell scanning, with evidence copies.
[✓]
Path-traversal & zip-slip guardsChecks on pages, uploads, static, backup restore.
[✓]
Upload triple-validationExtension whitelist + magic bytes + size limit.
[✓]
Security headers & security.txtCSP, COOP, CORP, X-Frame-Options, nosniff — plus an RFC 9116 security.txt.
[✓]
Audit trailActivity log with settings diffs, security events by country, weekly security report.
[✓]
Privacy by designServer-side analytics with no JavaScript on the visitor; GDPR consent, export & automatic deletion.

"It's no longer just a flat-file CMS. The security & operations layer — a firewall with progressive bans, shared multi-site defence, crawler verification, integrity monitoring — is the kind of capability you usually find in managed enterprise platforms."

// technical architecture review
03

Built for real deployment

Windows / IIS / Plesk — production, not theory.

iisnode-ready

Windows / IIS / Plesk

Runs native via iisnode with a ready, tested web.config — request filtering, HTTPS detection, separate log directories.

web.config · hardened
zero-downtime updates

New version, no recycle

Upload the new file and it loads by itself within seconds; the integrity check recognizes the upgrade and refreshes its fingerprint.

self-reload · integrity_upgrade
fast

Performance without a database

In-memory index and caches for pages, settings and analytics, incremental log reading, minified public code — fast even on a modest server.

in-memory index · incremental logs
resilient

Resilient in operation

Schedulers with retry/backoff, exception handlers, health checks and log rotation — one error won't take the site down, the disk won't fill up.

graceful degradation
recoverable

Recycle bin & history

Pages with full version history, posts, events, to-dos, subscribers, FAQ, polls, forms, PDFs, media — soft-delete with restore.

restore · version history
self-contained

Backup = copy

With no database, a backup is one file or a folder copy. Move to a new server without migrations, without dumps.

copy data/ → done
observable

Diagnostics & resources

SMTP, scheduler, RAM, disk, worker PID, heartbeat — and a trace for every alert email (sent / failed / skipped).

diagnostics · heartbeat
multi-site

Many sites, one server

Each site in its own folder and application pool; a shared folder only for what benefits all of them (bans, geolocation cache), with least privilege.

least privilege · shared defence