Release Candidate QA
Use this checklist before calling a package v1.0-ready.
Automated Checks
Run:
composer audit --no-interaction
php artisan test
npm audit
npm run build
python -m pip install -r requirements-docs.txt
python -m mkdocs build --strict
powershell -ExecutionPolicy Bypass -File .\scripts\build-buyer-package.ps1
Expected result:
- Composer audit has no known advisories.
- Laravel tests pass.
- npm audit has no vulnerabilities.
- frontend assets build.
- documentation site builds.
- buyer ZIP excludes
storage/app/installed.lock,storage/app/plugin-packages/,storage/app/theme-presets/,storage/app/public/branding/,storage/app/public/affiliate/,database/database.sqlite,dist/, and public diagnostic helpers.
Browser Smoke
Run the Playwright smoke script against the real deployment target before launch.
Fresh package before installer completion:
Installed site after setup is complete:
python scripts/smoke_test.py --base-url https://your-domain.example --mode installed --admin-email admin@example.com --admin-password "your-password"
Local php artisan serve run:
python scripts/smoke_test.py --base-url http://127.0.0.1:8001 --mode installed --admin-email admin@example.com --admin-password "your-password" --skip-canonical-redirect-check
Expected result:
/public/installcanonicalizes correctly- fresh mode reaches installer Step 1
- installed mode reaches public home, admin dashboard, extensions marketplace, locked premium SEO screen, and a working public profile lookup
- screenshots are written under
release-builds/smoke-artifacts/
Note:
- the
/public/installcanonical redirect is an Apache/shared-hosting rule, sophp artisan servecannot validate it locally
Fresh Install
Test a clean install without storage/app/installed.lock.
- Visit
/install. - Complete environment check.
- Enter database credentials.
- Run migrations.
- Create admin user.
- Finalize install.
- Confirm
/installredirects after install lock exists.
Admin Panel
Confirm:
- dashboard loads
- sidebar stays usable on desktop and mobile
- settings save successfully
- toasts are visible and auto-dismiss
- cache clear works
- account settings work
- logo and favicon upload/delete work
API Providers
Test at least one provider before release.
Recommended checks:
- TikWM key test
- RapidAPI key test
- TikAPI key test if available
- fallback enabled with at least two configured providers
- invalid key gives readable error
Public Flow
Confirm:
- homepage loads
- search works
- profile page renders
- posts load
- video route resolves
- download buttons do not expose API keys
- Turnstile behaves correctly when enabled
Extensions
Confirm:
- official theme ZIP uploads
- uploaded theme appears in Theme Presets
- theme can be applied
- active theme cannot be deleted
- inactive uploaded theme can be deleted
- SEO Engine Pro stays locked before plugin ZIP upload
- plugin ZIP upload unlocks SEO Engine Pro
- plugin can be disabled/enabled/deleted
Documentation
Confirm:
- README points to current docs
- configuration docs match the admin panel
- API provider docs mention RapidAPI, TikWM, TikAPI, Custom Gateway, and Apify Gateway
- install docs mention Hostinger/cPanel assumptions
- changelog has the latest release notes