The Moodle Marketplace is here, and so are we
Moodle has launched the Moodle Marketplace, the new home for every plugin that used to live in the moodle.org plugins directory. It's a big step for the ecosystem: one place to find, buy, and install plugins, with proper support for commercial vendors for the first time.
We think that's worth celebrating. A healthier plugin economy means more plugins, more maintainers who can afford to keep maintaining, and more code running inside your Moodle sites. Which is exactly why we exist: a marketplace tells you what a plugin does. An independent security review tells you what its code actually does. MDL Shield tracks every plugin on the Marketplace, reviews the code line by line, and puts the result on a public grade badge, so "is it safe?" has an answer that doesn't depend on taking anyone's word for it.
Here's what the transition changes for you.
Free community reviews: unchanged
Non-commercial plugins listed on the Marketplace keep their free monthly reviews. Verify you're the maintainer, run reviews, publish them, embed the badge. Nothing about that flow changes.
Paid plugins: release reviews make way for Repository reviews
The Marketplace doesn't let us download paid plugins' released packages, so release reviews of paid plugins are no longer possible. We detect this automatically and tell you up front instead of failing halfway.
If you maintain a paid plugin, your path is a Repository review: connect your Git repository (public or private, read-only deploy key) and we review the code directly. In many ways it's the stronger option, since you can review before you release, not after.
New: paid plugins can publish Repository reviews
Until now, publisher publication was reserved for plugins outside the directory. That rule made no sense once paid Marketplace plugins lost their release-review path, so we've changed it: if the Marketplace won't give us your released package, you can become a verified publisher and take your Repository reviews public, grade badge included. The published page states plainly that the review covers your source repository rather than the Marketplace package, so buyers know exactly what was reviewed.
You choose the disclosure level per review, which matters when your plugin is closed source:
- Full report: the complete review, findings and all.
- Grade summary: just the grade and a plain verdict. No findings, no code snippets, and for private repositories no repository location, branch, or commit either. Your code and your repo stay yours; only the grade goes public.
The small print
- Your plugin page now shows whether the Marketplace lets us download your releases, with a one-click re-check if you think we've got it wrong.
- Every link, page, and email now says Moodle Marketplace, and plugin links point at your plugin's Marketplace page. The directory served the community well for a long time; its name is retired with honours.
If you run into anything the migration broke that we haven't caught, tell us and we'll chase it.