Explainer

    What Is Mage-OS? How It Works and How It Compares with Magento Open Source

    Distribution, Mirror, Releases, Security Fixes and Switching

    By Simon Bumford, Founder of EveryHost••10 min read

    The short answer

    Mage-OS is a free, community-run distribution of Magento Open Source, maintained by the non-profit Mage-OS Association and independent of Adobe. It takes Adobe's Magento Open Source code, adds its own changes, and publishes the result as its own Composer packages that install without an Adobe account. The current release, Mage-OS 3.5.0, is based on Magento Open Source 2.4.9. A Mage-OS store looks and runs like a Magento store, but its packages, version numbers, extra features and update schedule are its own.

    Checked against Mage-OS's own pages, code and package data on 6 October 2026.

    What Mage-OS is, and who runs it

    Mage-OS describes its main repository as an independent non-profit distribution of Magento Open Source, and says it is not associated with Adobe. It is run by the Mage-OS Association, which its imprint gives as a non-profit association under Polish law; its About page says it was founded in 2022 by people from the Magento community to further the interests of that community. It says it is funded mainly by individual and company memberships, with donations through Open Collective.

    The code is released under the same open source licences as Magento Open Source, OSL-3.0 and AFL-3.0. Mage-OS is free to use, and you do not need an Adobe account to download it.

    How Mage-OS works

    Technically, Mage-OS is a fork that keeps following Adobe. Its code repository regularly merges Adobe's Magento Open Source changes, and each Mage-OS release states which Adobe version it is built on.

    1. Step 1Adobe publishes Magento Open SourceAdobe releases new Magento Open Source versions and security fixes.
    2. Step 2Mage-OS merges the upstream codeMage-OS brings Adobe's changes into its own copy of the code and adds its own changes on top.
    3. Step 3Packages are published as mage-os/*Each package is renamed, for example magento/framework becomes mage-os/framework, and tells Composer it replaces the Magento original.
    4. Step 4Stores install them with ComposerFrom repo.mage-os.org, with no Adobe account or access keys.

    The renaming is the clever part. Every Mage-OS package declares that it replaces its Magento equivalent, so when an extension asks Composer for a Magento module, Composer accepts the Mage-OS one instead. That is why many existing extensions can install on Mage-OS unchanged, and why Mage-OS can be installed with one command from repo.mage-os.org, as its installation guide shows:

    composer create-project --repository-url=https://repo.mage-os.org/ mage-os/project-community-edition

    Mage-OS version numbers are separate from Adobe's. Mage-OS 3.0.0 to 3.5.0 are all based on Magento Open Source 2.4.9, and the older 2.x line was based on 2.4.8.

    Mage-OSReleasedBased on Magento Open SourceNotes
    3.5.08 Sep 20262.4.9Emergency release with Adobe's StyleSmuggler hotfix (APSB26-146) and September patch (APSB26-138)
    3.4.011 Aug 20262.4.9Adobe's August isolated patch (APSB26-92)
    3.3.05 Aug 20262.4.9Fix for a vulnerability in a Mage-OS-only Page Builder import and export module
    3.2.014 Jul 20262.4.9Adobe's July isolated patch
    3.1.018 Jun 20262.4.9Stability fixes
    3.0.018 May 20262.4.9First release on 2.4.9; PHP 8.2 dropped
    2.3.013 May 20262.4.8-p5Last planned release on the 2.x line

    Sources: Mage-OS releases page, Mage-OS release notes on GitHub and the package data on repo.mage-os.org, checked 6 October 2026. Release dates are Mage-OS's announcement dates.

    What Mage-OS 3.x adds and removes

    Comparing the packages that make up Mage-OS 3.5.0 with the last 2.x release, and with Magento Open Source 2.4.9, shows what Mage-OS does differently. Among the changes in the 3.x line:

    • Added: a returns (RMA) module, an admin activity log, an interactive installer, the n98-magerun2 command-line tool, an extended Varnish configuration module and a custom admin logo module.
    • Removed: Adobe's analytics modules and the Marketplace module. Mage-OS 3.x also no longer requires PHP's ftp extension.
    • Carried from earlier releases: Mage-OS add-ons such as automatic translation, Page Builder template import and export, and a meta robots tag module.
    • Security hardening of its own: the 3.5.0 notes describe extra protection around the StyleSmuggler attack that Mage-OS says is not part of Adobe's patch.

    The full lists are in the Mage-OS 3.0.0 announcement and the release notes.

    Mage-OS vs Magento Open Source, Adobe Commerce and OpenMage

    Five names get mixed up in conversations about Mage-OS. The important split is between the Mage-OS Distribution, which is Mage-OS's own version of the code, and the Mage-OS Mirror, which serves Adobe's unchanged Magento Open Source packages without needing Adobe access keys.

    NameWhat it isWho runs itWhere the code comes fromVersion line
    Mage-OS DistributionA distribution of Magento Open Source with Mage-OS's own changesMage-OS Association (non-profit)mage-os/* packages from repo.mage-os.org, no Adobe accountMage-OS 3.x is based on Magento Open Source 2.4.9
    Mage-OS MirrorAn unchanged copy of Adobe's Magento Open Source packagesMage-OS Associationmagento/* packages from mirror.mage-os.org, no Adobe account; Marketplace not includedMagento Open Source releases since 2.3.7-p3
    Magento Open SourceAdobe's free, open source edition of Magento 2Adobemagento/* packages from repo.magento.com, with Adobe access keys2.4.x, currently 2.4.9
    Adobe CommerceAdobe's licensed edition, with features not in Open SourceAdobeAdobe's repository, under a paid Adobe licence2.4.x
    OpenMageA community long-term-support fork of Magento 1The OpenMage communityGitHub and Composer (openmage/magento-lts)Magento 1, a separate codebase

    Sources: Mage-OS releases, Mage-OS FAQ, mirror.mage-os.org and the OpenMage README, checked 6 October 2026. Adobe Commerce Cloud is Adobe's own hosted service and is not covered here.

    How Mage-OS handles security fixes

    Adobe sometimes ships security fixes as isolated patches rather than new versions. Mage-OS ports those fixes into a new Mage-OS release, so a Mage-OS store gets them with a normal Composer update. Its releases page says updates typically follow Adobe's within days, and that only the latest release branch receives fixes. In the three recent cases we checked:

    • Adobe's APSB26-92 (11 August 2026) was in Mage-OS 3.4.0 the same day.
    • Adobe's APSB26-146, the StyleSmuggler hotfix (7 September 2026), was in Mage-OS 3.5.0 the next day.
    • Adobe's APSB26-138 (8 September 2026) was in Mage-OS 3.5.0 the same day.

    The practical point is the support policy. Mage-OS 2.3.0 was announced as the last planned 2.x release, so a store left on the 2.x line does not receive the fixes that went into 3.x. Running Mage-OS means keeping up with its releases. Our articles on StyleSmuggler and APSB26-138 cover those two bulletins.

    Extensions, themes and compatibility

    Mage-OS describes itself as highly compatible with existing Magento 2 extensions, and the package renaming makes that true for many of them. It is still worth treating every store as its own case:

    • Extensions that depend on modules Mage-OS 3.x removed, such as Adobe's analytics or Marketplace modules, will not install as they are.
    • Extensions bought from the Adobe Marketplace still come from Adobe's repository, so Composer needs that repository and your Marketplace keys alongside Mage-OS's.
    • Mage-OS 3.5.0 tightened how CMS content directives behave. Custom code or content that relied on the old behaviour needs testing.
    • Most vendors state compatibility against Magento versions. Map your Mage-OS release to its Magento base (2.4.9 for 3.x) and ask vendors directly where their statement is unclear.

    The reliable answer comes from testing your own store, with its own extensions, theme and integrations, on a staging copy.

    Switching a Magento store to Mage-OS

    Converting a Magento Open Source store to Mage-OS is a change to the store's code, so it is a job for a developer. Mage-OS's migration script automates the Composer changes. On our check, the script required Magento Open Source 2.4.9 and developer mode, and warned against running it on production. Mage-OS's migration guide mentions earlier Magento versions in places; follow the script's own check.

    1. If the store is older than 2.4.9, upgrade it first. Our guide to the Magento 2.4.7 to 2.4.9 upgrade covers the order.
    2. Take full backups of the database, files, composer.json and composer.lock.
    3. On a staging copy in developer mode, run the script, or make the same changes by hand: add the Mage-OS repository, replace the Magento product package with the Mage-OS one, and update dependencies.
    4. Run the database upgrade, compile, deploy static content, reindex and flush the cache.
    5. Test every extension, the theme, checkout, payments and integrations.
    6. Release the tested code to production the way you release any update.
    bash <(curl -s https://raw.githubusercontent.com/mage-os-lab/migrate-m2-to-mageos/refs/heads/main/migrate-to-mage-os.sh)

    Shown as published by Mage-OS Lab. Read any script before you run it, and run this one on staging only.

    Mage-OS documents a way back to Magento Open Source with Composer, losing Mage-OS's own additions, and switching back means getting Adobe's packages again. Changing hosting provider is a separate job from changing the code: our Mage-OS hosting requirements guide explains the difference.

    Is Mage-OS right for your store?

    Reasons merchants and agencies choose it:

    • Installing and updating needs no Adobe account or access keys.
    • Adobe's security fixes arrive as ordinary releases rather than separate patches.
    • Extra features such as returns and an admin activity log, and a project governed by its community.

    Things to weigh up:

    • Only the latest Mage-OS branch gets fixes, so you need a routine for regular updates.
    • Extension vendors test against Magento versions; Mage-OS compatibility is often something you confirm yourself.
    • There is no Adobe support for Mage-OS. Support comes from the community, your developer or agency, and your host.
    • Your developer or agency should be comfortable working with it before you commit.

    For an existing Magento store, there is no need to rush. Mage-OS and Magento Open Source 2.4.9 share their code base, so the server you need is the same either way.

    Hosting Mage-OS

    Because Mage-OS 3.x is built on Magento Open Source 2.4.9, it needs the same server stack: PHP, MySQL or MariaDB, OpenSearch, Valkey or Redis, Varnish and nginx at the right versions, with cron and Composer access. Our Mage-OS hosting requirements guide sets out the versions, where Mage-OS's and Adobe's figures differ, and how to size a server.

    EveryHost hosts Mage-OS on our current Managed VPS, dedicated server and High Availability plans, built to order on our nginx stack in a UK data centre with staging included. Moving an existing Mage-OS store to us is covered by our free managed migration. If you are considering Mage-OS, we are happy to look at your store with you and your developer.

    Frequently Asked Questions

    Mage-OS is built from Magento Open Source code, so a Mage-OS store works the way a Magento store does: the same admin, the same module structure and the same command-line tools. It is not identical. Mage-OS publishes the code under its own package names, adds some features of its own, removes a few Adobe modules and releases on its own schedule. Mage-OS 3.5.0 is based on Magento Open Source 2.4.9.

    Yes. Mage-OS is open source under the same OSL-3.0 and AFL-3.0 licences as Magento Open Source, and installing it from the Mage-OS repository needs no Adobe account or access keys. You still pay for hosting, and for any paid extensions, themes or developer time your store needs.

    Mage-OS is run by the Mage-OS Association, a non-profit association registered in Poland and funded mainly by member companies and individuals from the Magento community. It states that it is not affiliated with Adobe.

    Many will, because each Mage-OS package tells Composer it replaces the matching Magento package, so an extension that asks for a Magento module gets the Mage-OS one. That is not a guarantee. Extensions that depend on modules Mage-OS 3.x removed, such as Adobe's analytics and Marketplace modules, will not install as they are, and Adobe Marketplace extensions still need Adobe's repository and your Marketplace keys. Check each extension with its vendor and test the whole store on a staging copy.

    Yes, with a developer. Mage-OS's migration script swaps the Composer packages on a Magento Open Source 2.4.9 store in developer mode, and its authors warn against running it on production, so do it on a staging copy. Mage-OS also documents a route back to Magento Open Source, at the cost of Mage-OS's own additions. Take full backups first either way.

    They are different generations. Mage-OS is a distribution of Magento 2 (Magento Open Source). OpenMage is a separate community project that maintains a long-term-support fork of Magento 1. Mage-OS itself points Magento 1 users towards OpenMage.

    Mage-OS says its updates typically follow Adobe's within days, and in the cases we checked it was the same day or the next: Mage-OS 3.4.0 shipped on the same day as Adobe's August 2026 bulletin, and 3.5.0 a day after the StyleSmuggler bulletin. Mage-OS fixes only its latest release branch, so staying on an older Mage-OS line means going without fixes.

    No. Mage-OS is independent of Adobe, and Adobe's support and system requirements cover its own products. Mage-OS support comes from its community, your developer or agency, and your host.

    Sources and further reading

    All checked on 6 October 2026.

    Thinking about Mage-OS?

    Talk to our UK Magento engineers about the server your store would need, whether it runs Magento Open Source or Mage-OS.