Example add-on workflow: upload example-import-addon.zip in Admin → Add-ons. After enabling it, its JSON file appears under Admin → Templates. Safe add-ons may supply declarative JSON/TXT templates, CSS/JS/SVG/image presentation assets, and reversible SQL migrations. Executable PHP, shell files, unsafe paths, privilege SQL and undeclared files are blocked. Increase the semantic version for every update; keep the earlier ZIP/backup until the new version is verified.
