Why Furnivo
What makes it better
than the alternatives
- 01
Shopify-style admin with roles
Shopify-style admin with roles
- 02
Translatable content in English and Arabic
Translatable content in English and Arabic
- 03
Inventory service with full audit trail
Inventory service with full audit trail
- 04
Theme system with visual customiser
Theme system with visual customiser
- 05
Rich-text sanitiser and structured data
Rich-text sanitiser and structured data
Storefront
- Home page with toggleable sections (hero slider
- brand logos
- collections
- product rows
- testimonials
- scene images)
- Collection and brand listing pages with filters (category
- price
- brand
- colour
- material) and sorting
- Product pages with options
- variants
- gallery
- reviews with photos
- stock alerts
- per-product delivery/returns text
- Bag drawer
- wishlist
- recently viewed
- guest checkout or customer accounts with address book
- Multi-currency display (CurrencyService)
- VAT-inclusive prices
- discount codes and Buy X get Y promotions
- Customer account: orders
- invoices
- returns/exchanges
- reorder
- address management
- Static landing page at /landing/ (LandingController serves resources/landing/)
Admin Dashboard & Analytics
- Sales dashboard with revenue
- orders
- conversion rate
- top products
- SalesReport service: daily/weekly/monthly charts
- year-over-year comparison
- Funnel analytics: product views → add to bag → checkout → paid
- Customer insights: new vs returning
- lifetime value
- top customers
- Activity log (Auditable trait): who changed what and when
Product Catalog
- Products with variants (ProductVariant)
- options (ProductOption
- ProductOptionValue)
- SKU
- barcode
- cost
- compare-at price
- SaveProduct action coordinates product
- options
- variants
- images and stock in one transaction
- Bulk actions (ProductBulkActions): activate
- deactivate
- delete
- change status
- assign category
- CSV import/export (ProductCsv
- ProductCsvImporter
- ProductCsvExporter
- ProductCsvValidator uses ProductRequest rules)
- Media library (MediaService
- ImageProcessor): upload → WebP in 3 sizes (original
- medium 800px
- thumb 200px) with PHP GD
- Categories with parent/child tree (Category::flatTree)
- brands with logo and origin
- Product search (ProductSearch) with facets (ProductFacets)
- recently viewed (RecentlyViewed service)
Inventory Management
- Stock tracking per variant (ProductVariant.track_inventory
- stock_quantity)
- InventoryService: adjust
- set
- reserve
- release methods; only place stock changes
- InventoryMovement log: quantity
- reason (InventoryReason enum: restock
- damage
- sale
- return
- adjustment)
- admin
- note
- timestamp
- Low stock threshold (Settings → Inventory)
- stock alerts sent to customers (SendStockAlerts command)
- Inventory screen: filter by low/out of stock
- adjust with reason and note
- view movement history
Orders & Fulfilment
- Order model: status (OrderStatus enum: pending
- processing
- shipped
- delivered
- cancelled)
- payment_status (PaymentStatus enum)
- fulfilment_status (FulfillmentStatus enum)
- PlaceOrder action: validate
- calculate totals (TotalsCalculator)
- reserve stock
- create order
- send confirmation email
- OrderService: updateStatus
- addNote
- sendEmail; FulfillmentService: ship
- deliver
- partial fulfilment
- RefundService: full or partial refunds
- stock release
- Stripe refund API call
- Draft orders created by staff (Admin/Sales/DraftOrderController)
- invoices (PDF view)
- timeline
- Returns/exchanges (ReturnService
- Return model): customer requests
- admin approves/rejects
- refund or exchange
- Abandoned cart reminders (SendCartReminders command
- CartReminder mail): sent after 24 hours if unpaid
- Unpaid orders auto-cancelled after UNPAID_ORDER_MINUTES (ReleaseUnpaidOrders command)
Payments & Shipping
- PaymentManager with gateways: StripeGateway (hosted checkout)
- CashOnDeliveryGateway
- ManualGateway
- StripeClient wraps Stripe API; StripeWebhookHandler processes payment_intent.succeeded
- payment_intent.payment_failed
- ShippingService with carriers: FlatRateCarrier
- AramexCarrier (live rates via SOAP API)
- ShippingDestination: Country → State/Region → City addresses; UAE emirates built in (STORE_EMIRATES)
- Tax settings: VAT rate
- inclusive/exclusive
- tax number displayed on invoices
Customers & Marketing
- User model: name
- phone
- locale
- is_active; addresses (Address model) with label
- Customer screen: orders
- lifetime value
- last order
- deactivate account
- Reviews (Review model): rating
- comment
- photos (Media)
- moderation (is_approved)
- Subscribers (Subscriber model): email
- subscribed_at; newsletter signup form
- Enquiries (Enquiry model): custom order requests
- contact messages
- Discount codes (Discount model): percentage or fixed
- minimum order
- usage limit
- date range
- Promotions (Promotion model): Buy X get Y
- free shipping
- category/product conditions
Content & SEO
- Pages (Page model): slug
- title
- content (rich text)
- template (about
- careers
- faq
- legal)
- is_active
- Menus (Menu model): header
- footer; MenuRepository builds nested structure
- Banners (Banner model): image
- link
- position
- is_active; shown on home/collection pages
- Rich text editor (Trix) with HasRichText trait: cleans HTML on save (RichText::clean allow-list)
- renders with RichText::render
- SEO: schema.org Product and BreadcrumbList (StructuredData service)
- sitemap.xml (SeoController)
- robots.txt
- canonical URLs
- Translatable fields (spatie/laravel-translatable): name
- description
- seo_title
- seo_description in JSON columns
Settings & Configuration
- SettingsService: rows in settings table
- cached
- read with setting('group.key')
- General: store name
- logo
- contact details
- social links
- timezone
- order number prefix
- Currencies: base currency (STORE_CURRENCY)
- display currencies (Currency model)
- CurrencyService converts prices
- Checkout: guest checkout
- account required
- terms & conditions page
- Notifications: order confirmation
- status updates
- low stock alerts
- cart reminders (OrderNotifier
- OrderEmails)
- Mail server: SMTP credentials
- from address
- test email (MailServerController)
- Credentials: Stripe keys
- Aramex account
- reCAPTCHA (stored encrypted in settings
- Credentials service decrypts)
- Tracking: Google Analytics
- Facebook Pixel
- custom head/body scripts (CustomCode service)
Theme Customisation
- ThemeSettings service: THEME_SECTIONS maps section keys to Blade files in storefront/home/sections/<key>.blade.php
- Online Store → Customize: colours (primary
- accent
- background)
- fonts (heading
- body from Google Fonts)
- announcement bar text/link
- Homepage sections: toggle on/off
- reorder (stored in settings.theme.sections_order
- settings.theme.sections_disabled)
- Custom CSS/JS: settings.theme.custom_css
- settings.theme.custom_js injected into <head>
- Draft preview: settings.theme.draft stores unpublished changes
- /admin/online-store/preview shows draft
- Publish button copies draft to live
| Language | Version | Framework | Used for | Share of code |
|---|---|---|---|---|
| PHP | — | — | Web, API | 93.7% |
| JavaScript | — | — | Front-end | 2.4% |
| SQL | — | — | Database | 2.2% |
| CSS | — | — | Styling | 1.3% |
| Shell | — | — | Scripts | 0.2% |
| Python | — | — | Web, API | 0.1% |
| HTML | — | — | Front-end | 0% |
- Primary language
- PHP 8.2
- Framework
- Laravel 12.69
- Database
- MySQL 8.0
- Authentication
- Laravel session guards (web for customers, admin for staff) with bcrypt password hashing; password reset via email tokens
- Licence
- Single-site
- Screens
- 45
- Database tables
- 42
- Supported languages
- English, Arabic (RTL with IBM Plex Sans Arabic font, dir=rtl, text-align: right)
- Browser support
- Modern browsers (Chrome, Firefox, Safari, Edge); CSS uses clamp(), CSS Grid, Flexbox
| Minimum | Recommended | |
|---|---|---|
| CPU | 2 vCPU | 4 vCPU |
| RAM | 4 GB RAM | 8 GB RAM |
| OS | Ubuntu 22.04+ / Debian 11+, PHP 8.2–8.4, Composer 2.x, Node.js 20.19+, npm 10+, MySQL 8.0+ | Ubuntu 22.04+ / Debian 11+, PHP 8.2–8.4, Composer 2.x, Node.js 20.19+, npm 10+, MySQL 8.0+ |
| Est. monthly hosting | $25 | $25 |
```bash cp .env.example .env # Edit .env: set DB_PASSWORD, ADMIN_EMAIL, ADMIN_PASSWORD docker compose up -d --build # → http://localhost:8080 and /admin ```
```bash
# Install dependencies
sudo apt update && sudo apt install -y php8.2 php8.2-{cli,fpm,mysql,mbstring,xml,curl,zip,gd,intl,bcmath} mysql-server nginx composer nodejs npm git
# Clone and setup
git clone <repo> /var/www/furnivo
cd /var/www/furnivo/laravel-project
cp .env.example .env
# Edit .env: APP_URL, DB_*, ADMIN_EMAIL, ADMIN_PASSWORD
composer install --no-dev --optimize-autoloader
php artisan key:generate
php artisan migrate --force
php artisan db:seed
php artisan storage:link
npm install && npm run build
sudo chown -R www-data:www-data storage bootstrap/cache
sudo chmod -R 775 storage bootstrap/cache
# Nginx config (see deploy/nginx.conf), then:
sudo systemctl restart nginx php8.2-fpm
# Queue worker and scheduler (see deploy/vibe-queue.service, deploy/crontab)
sudo systemctl enable vibe-queue && sudo systemctl start vibe-queue
crontab -e # add: * * * * * cd /var/www/furnivo/laravel-project && php artisan schedule:run >> /dev/null 2>&1
``````bash # Upload laravel-project/ to public_html/furnivo/ # Point domain document root to public_html/furnivo/public/ # SSH or cPanel Terminal: cd public_html/furnivo cp .env.example .env # Edit .env via File Manager or nano php artisan key:generate php artisan migrate --force php artisan db:seed php artisan storage:link # Upload node_modules or run: npm install && npm run build # Set storage/ and bootstrap/cache/ to 775 # Setup cron: * * * * * cd /home/user/public_html/furnivo && php artisan schedule:run ```
```bash # Same as VPS, plus: # - RDS/managed MySQL for database # - S3/Spaces for media (set FILESYSTEM_DISK=s3, AWS_* in .env) # - Load balancer + multiple app servers (set CACHE_STORE=redis, QUEUE_CONNECTION=redis) # - Redis for cache and queue (install php-redis, set REDIS_HOST) ```
```bash # Install PHP 8.2, Composer, Node.js 20, MySQL 8 on your machine, then: cd laravel-project cp .env.example .env php artisan key:generate # Create database 'furnivo' in MySQL, set DB_* in .env php artisan migrate php artisan db:seed php artisan storage:link npm install composer run dev # starts server, queue, logs, vite in parallel # → http://127.0.0.1:8000 and /admin ```
Quality report
Manually reviewedHow to read the quality report
What this is. Every project on Vibe96 goes through an automated audit of its source code before a reviewer in Dubai checks it by hand. The score is out of 100; 75 is the minimum to be listed, and any single failing check blocks a listing regardless of the score.
- Security
- No real credentials in the code, every data-changing route protected, admin areas role-gated, no SQL built from user input.
- Code structure
- A developer can navigate and extend it: clear module boundaries, no giant files, little copy-paste.
- Docs & completeness
- The setup guide, example config, schema and required files the builder committed to are actually in the archive.
- Dependency health
- Packages pinned, no known critical vulnerabilities, no abandoned libraries in production paths.
- Build & deploy
- A clean machine can restore, build and start it by following the shipped instructions.
Warnings are problems that didn't block the listing; they stay visible here until a later version clears them. The audit reads the code — it does not run it — so always try the live demo before you buy. Lines of code are counted from the same audited archive.
What to know before you buy
3 non-blocking findings shown publicly: good separation of concerns with some duplication and oversized files; strong authentication & role checks; minor ownership gaps on read endpoints; database access is mostly safe; a few missing indexes and one unscoped delete found. The seller has been notified; fixes ship in the next version.
Versions & updates
No updates yet. New versions appear here with a changelog.
Buyers receive updates free for 1 year.
What you get
- </>Full source codeThe complete audited source, delivered as a download from your account. No obfuscation.
- ▤DocumentationSetup guide, architecture notes, CLAUDE.md and AGENTS.md.
- ↻One year of updatesEvery new version the builder publishes, free for 12 months.
- ♧30 days of supportInstallation and defect support through Vibe96 tickets.