Client Portal

Private, branded client portals: phases, files, uploads, approvals, messages and reminders. Requires Statamic Pro.

1.1.1

October 3rd, 2026

  • Security: escape portal titles and every other plain-text field clients see (project status, phase and module titles, descriptions, button labels, file names, login heading and intro). A visitor who registered with HTML in their name could otherwise run script when staff viewed /portal. Thanks to the Statamic Marketplace team for the report.
  • Requirements now state that Statamic Pro is required: portals need client accounts besides yours and a client role, which Statamic Core doesn't allow.