What Mage-OS is, and who runs it
Mage-OS describes its main repository as an independent non-profit distribution of Magento Open Source, and says it is not associated with Adobe. It is run by the Mage-OS Association, which its imprint gives as a non-profit association under Polish law; its About page says it was founded in 2022 by people from the Magento community to further the interests of that community. It says it is funded mainly by individual and company memberships, with donations through Open Collective.
The code is released under the same open source licences as Magento Open Source, OSL-3.0 and AFL-3.0. Mage-OS is free to use, and you do not need an Adobe account to download it.
How Mage-OS works
Technically, Mage-OS is a fork that keeps following Adobe. Its code repository regularly merges Adobe's Magento Open Source changes, and each Mage-OS release states which Adobe version it is built on.
- Step 1Adobe publishes Magento Open SourceAdobe releases new Magento Open Source versions and security fixes.
- Step 2Mage-OS merges the upstream codeMage-OS brings Adobe's changes into its own copy of the code and adds its own changes on top.
- Step 3Packages are published as mage-os/*Each package is renamed, for example magento/framework becomes mage-os/framework, and tells Composer it replaces the Magento original.
- Step 4Stores install them with ComposerFrom repo.mage-os.org, with no Adobe account or access keys.
The renaming is the clever part. Every Mage-OS package declares that it replaces its Magento equivalent, so when an extension asks Composer for a Magento module, Composer accepts the Mage-OS one instead. That is why many existing extensions can install on Mage-OS unchanged, and why Mage-OS can be installed with one command from repo.mage-os.org, as its installation guide shows:
composer create-project --repository-url=https://repo.mage-os.org/ mage-os/project-community-editionMage-OS version numbers are separate from Adobe's. Mage-OS 3.0.0 to 3.5.0 are all based on Magento Open Source 2.4.9, and the older 2.x line was based on 2.4.8.
| Mage-OS | Released | Based on Magento Open Source | Notes |
|---|---|---|---|
| 3.5.0 | 8 Sep 2026 | 2.4.9 | Emergency release with Adobe's StyleSmuggler hotfix (APSB26-146) and September patch (APSB26-138) |
| 3.4.0 | 11 Aug 2026 | 2.4.9 | Adobe's August isolated patch (APSB26-92) |
| 3.3.0 | 5 Aug 2026 | 2.4.9 | Fix for a vulnerability in a Mage-OS-only Page Builder import and export module |
| 3.2.0 | 14 Jul 2026 | 2.4.9 | Adobe's July isolated patch |
| 3.1.0 | 18 Jun 2026 | 2.4.9 | Stability fixes |
| 3.0.0 | 18 May 2026 | 2.4.9 | First release on 2.4.9; PHP 8.2 dropped |
| 2.3.0 | 13 May 2026 | 2.4.8-p5 | Last planned release on the 2.x line |
Sources: Mage-OS releases page, Mage-OS release notes on GitHub and the package data on repo.mage-os.org, checked 6 October 2026. Release dates are Mage-OS's announcement dates.
What Mage-OS 3.x adds and removes
Comparing the packages that make up Mage-OS 3.5.0 with the last 2.x release, and with Magento Open Source 2.4.9, shows what Mage-OS does differently. Among the changes in the 3.x line:
- Added: a returns (RMA) module, an admin activity log, an interactive installer, the n98-magerun2 command-line tool, an extended Varnish configuration module and a custom admin logo module.
- Removed: Adobe's analytics modules and the Marketplace module. Mage-OS 3.x also no longer requires PHP's ftp extension.
- Carried from earlier releases: Mage-OS add-ons such as automatic translation, Page Builder template import and export, and a meta robots tag module.
- Security hardening of its own: the 3.5.0 notes describe extra protection around the StyleSmuggler attack that Mage-OS says is not part of Adobe's patch.
The full lists are in the Mage-OS 3.0.0 announcement and the release notes.
Mage-OS vs Magento Open Source, Adobe Commerce and OpenMage
Five names get mixed up in conversations about Mage-OS. The important split is between the Mage-OS Distribution, which is Mage-OS's own version of the code, and the Mage-OS Mirror, which serves Adobe's unchanged Magento Open Source packages without needing Adobe access keys.
| Name | What it is | Who runs it | Where the code comes from | Version line |
|---|---|---|---|---|
| Mage-OS Distribution | A distribution of Magento Open Source with Mage-OS's own changes | Mage-OS Association (non-profit) | mage-os/* packages from repo.mage-os.org, no Adobe account | Mage-OS 3.x is based on Magento Open Source 2.4.9 |
| Mage-OS Mirror | An unchanged copy of Adobe's Magento Open Source packages | Mage-OS Association | magento/* packages from mirror.mage-os.org, no Adobe account; Marketplace not included | Magento Open Source releases since 2.3.7-p3 |
| Magento Open Source | Adobe's free, open source edition of Magento 2 | Adobe | magento/* packages from repo.magento.com, with Adobe access keys | 2.4.x, currently 2.4.9 |
| Adobe Commerce | Adobe's licensed edition, with features not in Open Source | Adobe | Adobe's repository, under a paid Adobe licence | 2.4.x |
| OpenMage | A community long-term-support fork of Magento 1 | The OpenMage community | GitHub and Composer (openmage/magento-lts) | Magento 1, a separate codebase |
Sources: Mage-OS releases, Mage-OS FAQ, mirror.mage-os.org and the OpenMage README, checked 6 October 2026. Adobe Commerce Cloud is Adobe's own hosted service and is not covered here.
How Mage-OS handles security fixes
Adobe sometimes ships security fixes as isolated patches rather than new versions. Mage-OS ports those fixes into a new Mage-OS release, so a Mage-OS store gets them with a normal Composer update. Its releases page says updates typically follow Adobe's within days, and that only the latest release branch receives fixes. In the three recent cases we checked:
- Adobe's APSB26-92 (11 August 2026) was in Mage-OS 3.4.0 the same day.
- Adobe's APSB26-146, the StyleSmuggler hotfix (7 September 2026), was in Mage-OS 3.5.0 the next day.
- Adobe's APSB26-138 (8 September 2026) was in Mage-OS 3.5.0 the same day.
The practical point is the support policy. Mage-OS 2.3.0 was announced as the last planned 2.x release, so a store left on the 2.x line does not receive the fixes that went into 3.x. Running Mage-OS means keeping up with its releases. Our articles on StyleSmuggler and APSB26-138 cover those two bulletins.
Extensions, themes and compatibility
Mage-OS describes itself as highly compatible with existing Magento 2 extensions, and the package renaming makes that true for many of them. It is still worth treating every store as its own case:
- Extensions that depend on modules Mage-OS 3.x removed, such as Adobe's analytics or Marketplace modules, will not install as they are.
- Extensions bought from the Adobe Marketplace still come from Adobe's repository, so Composer needs that repository and your Marketplace keys alongside Mage-OS's.
- Mage-OS 3.5.0 tightened how CMS content directives behave. Custom code or content that relied on the old behaviour needs testing.
- Most vendors state compatibility against Magento versions. Map your Mage-OS release to its Magento base (2.4.9 for 3.x) and ask vendors directly where their statement is unclear.
The reliable answer comes from testing your own store, with its own extensions, theme and integrations, on a staging copy.
Switching a Magento store to Mage-OS
Converting a Magento Open Source store to Mage-OS is a change to the store's code, so it is a job for a developer. Mage-OS's migration script automates the Composer changes. On our check, the script required Magento Open Source 2.4.9 and developer mode, and warned against running it on production. Mage-OS's migration guide mentions earlier Magento versions in places; follow the script's own check.
- If the store is older than 2.4.9, upgrade it first. Our guide to the Magento 2.4.7 to 2.4.9 upgrade covers the order.
- Take full backups of the database, files, composer.json and composer.lock.
- On a staging copy in developer mode, run the script, or make the same changes by hand: add the Mage-OS repository, replace the Magento product package with the Mage-OS one, and update dependencies.
- Run the database upgrade, compile, deploy static content, reindex and flush the cache.
- Test every extension, the theme, checkout, payments and integrations.
- Release the tested code to production the way you release any update.
bash <(curl -s https://raw.githubusercontent.com/mage-os-lab/migrate-m2-to-mageos/refs/heads/main/migrate-to-mage-os.sh)Shown as published by Mage-OS Lab. Read any script before you run it, and run this one on staging only.
Mage-OS documents a way back to Magento Open Source with Composer, losing Mage-OS's own additions, and switching back means getting Adobe's packages again. Changing hosting provider is a separate job from changing the code: our Mage-OS hosting requirements guide explains the difference.
Is Mage-OS right for your store?
Reasons merchants and agencies choose it:
- Installing and updating needs no Adobe account or access keys.
- Adobe's security fixes arrive as ordinary releases rather than separate patches.
- Extra features such as returns and an admin activity log, and a project governed by its community.
Things to weigh up:
- Only the latest Mage-OS branch gets fixes, so you need a routine for regular updates.
- Extension vendors test against Magento versions; Mage-OS compatibility is often something you confirm yourself.
- There is no Adobe support for Mage-OS. Support comes from the community, your developer or agency, and your host.
- Your developer or agency should be comfortable working with it before you commit.
For an existing Magento store, there is no need to rush. Mage-OS and Magento Open Source 2.4.9 share their code base, so the server you need is the same either way.
Hosting Mage-OS
Because Mage-OS 3.x is built on Magento Open Source 2.4.9, it needs the same server stack: PHP, MySQL or MariaDB, OpenSearch, Valkey or Redis, Varnish and nginx at the right versions, with cron and Composer access. Our Mage-OS hosting requirements guide sets out the versions, where Mage-OS's and Adobe's figures differ, and how to size a server.
EveryHost hosts Mage-OS on our current Managed VPS, dedicated server and High Availability plans, built to order on our nginx stack in a UK data centre with staging included. Moving an existing Mage-OS store to us is covered by our free managed migration. If you are considering Mage-OS, we are happy to look at your store with you and your developer.
Frequently Asked Questions
Sources and further reading
All checked on 6 October 2026.
- Mage-OS and its About and imprint pages (the Association, founding, independence from Adobe)
- mage-os/mageos-magento2 on GitHub (distribution of Magento Open Source, licence, release notes)
- Mage-OS: Releases (support for the latest branch only, timing of security updates, mirrors)
- Mage-OS 3.0.0 announcement and Mage-OS 2.3.0 announcement
- repo.mage-os.org package data (Magento base per release, package replacements, added and removed modules)
- Mage-OS Mirror and the Mage-OS FAQ
- Mage-OS: Installation, Mage-OS: Migration guide and the migration script
- Adobe security bulletins APSB26-92, APSB26-146 and APSB26-138
- OpenMage magento-lts README
Thinking about Mage-OS?
Talk to our UK Magento engineers about the server your store would need, whether it runs Magento Open Source or Mage-OS.