E-Commerce Platforms & Shop Systems
Sylius
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Sylius · sylius.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Sylius is an open-source, headless e-commerce platform built on Symfony and positioned for mid-market and enterprise brands that need custom solutions. The bench's evidence concentrates on the developer surface: extensibility scores cluster at 8-9, crediting a REST API built with API Platform, headless and PWA readiness, an Addons Marketplace with over 500 indexed plugins, and a stack that runs on a standard VPS, Docker or Kubernetes. Data control follows at 7-8, where open-source code on merchant-chosen infrastructure makes ownership structural rather than promised. The commercial surface is thin: tax and legal scores sit at 0-1, catalog, checkout and operations at 1-2, and the judges found no public information on checkout flow, VAT handling or back-office features. The genuine split is sovereignty, spanning 3 to 6: the rationales credit the same facts — an Opole, Poland headquarters and self-hosting on the merchant's infrastructure, set against no published subprocessor list and no sovereignty attributes on record — and differ in how much weight the unevidenced middle of the chain carries. No prices are published for the Plus edition or services.
Speaks for it
- Extensibility scores cluster at 8-9 on an open-source Symfony core, a REST API built with API Platform, and headless and PWA readiness.
- The Addons Marketplace launched with over 500 indexed plugins, with 700-plus contributors and 10,000+ online stores recorded.
- The stack runs on a standard VPS, Docker or Kubernetes, putting infrastructure choice with the merchant.
- Data control and exit scores cluster at 7-8, with ownership judged structural because the shop can physically stay on the merchant's machines.
- A behavior-driven development approach signals a real engineering and testing culture, the developer-side rationales note.
Held against it
- Tax and legal scores sit at 0-1; the judges found no public information on VAT determination, OSS reporting, reverse charge or German checkout requirements.
- Catalog and checkout scores sit at 1-2; no public information appears on variants, bundles, pricing rules, payment methods or the checkout flow.
- Operations scores sit at 1-2; the only adjacent signal is a customer quote praising the Plus edition's integrations, naming no system.
- Sovereignty scores span 3 to 6, and the judges found no public information on a subprocessor list, hosting defaults or certification.
- No public prices appear for the Plus edition, plugins, hosting or services, so annual cost is not computable from the pages.
Best for
- You have a Symfony development team and want an open-source, headless platform you customise through a REST API.
- You want to run the entire shop on your own VPS, Docker or Kubernetes and treat data ownership as structural.
- You are a mid-market or enterprise brand needing custom solutions and are budgeting for a custom build rather than a turnkey shop.
Avoid if
- You want a shop you can launch and run without a development team — the platform is positioned for mid-market and enterprise brands that need custom solutions.
- You need to judge conversion and daily operations from published feature pages — as one judge put it, conversion cannot be judged on a stack diagram.
- Your compliance role requires you to answer where checkout-path data is processed — the data protection officer's sovereignty score of 4 rests exactly on that absence.
The scores
Catalogue & checkout
Show reasoningHide reasoning
How this is scored
Products, variants, pricing rules and the path to payment — the part that either converts or does not.
0 — Flat product list with one price and no variants; checkout is a form and one payment method.
3 — Variants and categories with a standard checkout and two or three payment methods, but no bundles, no tiered pricing and no guest checkout worth the name.
5 — Full variant matrix, product bundles, tiered and customer-group pricing, guest checkout, and the payment methods a German shop needs including invoice and direct debit.
8 — Configurable products, per-channel pricing, promotions and vouchers with rules, a checkout that can be customised without a rebuild, and payment via the major providers plus buy-now-pay-later where offered.
10 — Merchandising and checkout are the product: rule-driven pricing and promotions, A/B-testable checkout, multi-currency and multi-language as standard, and conversion features (abandoned cart, one-page checkout) shipped rather than bolted on.
The Merchant
I found no public information on payment methods, guest checkout, promotions, vouchers or variant handling, which are the things that decide whether my German shoppers can pay by invoice at all. The headless and PWA positioning tells me a checkout could be rebuilt to my needs without a vendor rebuild, but the captured pages show nothing of the conversion machinery itself. 1
The B2B Seller
The captured page positions the product as headless with a customizable REST API and a frontend of the buyer's choice, and we found no public information on variants, bundles, tiered or customer-group pricing, checkout flow or payment methods — least of all on net display for trade customers, VAT-ID handling or payment on account. A checkout I cannot see is a checkout I cannot judge. 1
The Developer
The captured pages say only that this is a headless platform for mid-market and enterprise brands needing custom solutions. We found no public information on the product catalogue, variants, pricing rules, checkout flow or payment methods, so I cannot credit anything beyond the minimum. 1
The Operations Lead
The page sells the architecture — open source, headless, API-first, with an addons marketplace of over 500 plugins — but we found no public information on variants, bundles, pricing rules, payment methods or the checkout flow a customer actually walks. I cannot judge conversion on a stack diagram. 1
The Data Protection Officer
The captured pages describe a headless platform with a plugin marketplace of over 500 extensions, but I found no public information on variants, bundles, tiered or customer-group pricing, guest checkout, or the payment methods a German shop actually needs. The conversion path itself is not evidenced beyond the headless claim. 1
The Skeptic
The page positions this as a headless platform for custom builds with a marketplace of over 500 indexed plugins, but we found no public information on variants, bundles, pricing rules, payment methods or any part of the checkout path. A merchant buying on these pages alone cannot tell what converts or what has to be built first. 1
Tax & German legal correctness
Show reasoningHide reasoning
How this is scored
VAT determination, OSS, B2B reverse charge, and the checkout requirements German law actually imposes — judged on what the platform does, not on a plugin someone could buy.
0 — A single VAT rate applied everywhere; no B2B handling, no country logic, no legal-text handling in checkout.
3 — Per-country VAT rates configurable by hand, net prices for B2B possible with effort, and legal texts as free-form pages.
5 — Automatic VAT by destination and customer type, VAT-ID validation with reverse charge, gross and net display per customer group, and the mandatory checkout elements (order button wording, withdrawal policy, price indications) handled.
8 — OSS thresholds tracked and reported, correct invoicing per case including reverse-charge notes, small-business and third-country handling, and e-invoicing (XRechnung/ZUGFeRD) for B2B orders.
10 — Tax and legal correctness are maintained by the vendor rather than the merchant: rates and thresholds updated as the law moves, OSS reporting produced, every invoice case correct out of the box, and documented conformity a lawyer could review.
The Merchant
Nothing published on VAT determination, OSS reporting, reverse charge, VAT-ID validation or the legal texts a German checkout must carry, so I cannot verify even a hand-configured per-country VAT setup from the vendor's own page. For a shop selling to consumers in Germany this is an information gap I would have to close before signing anything. 1
The B2B Seller
As someone who sells net to businesses across the EU, this page gives me nothing to work with: no VAT determination by destination or customer type, no VAT-ID validation or reverse charge, no OSS, no invoicing or e-invoicing statements. We found no public information on tax handling or German checkout-law requirements at all. 1
The Developer
We found no public information on VAT determination, OSS reporting, B2B reverse charge, German checkout requirements or e-invoicing formats. Nothing on the captured pages documents tax or legal handling of any kind. 1
The Operations Lead
We found no public information on VAT determination, OSS thresholds, reverse charge, invoicing formats or the German checkout requirements the law imposes. For a shop serving German customers, that silence decides the score. 1
The Data Protection Officer
I found no public information on VAT determination by destination and customer type, OSS reporting, reverse charge for VAT-registered business customers, or the mandatory checkout elements German law imposes such as order button wording and withdrawal policy. The captured page is silent on tax and legal correctness entirely, which scores at the bottom. 1
The Skeptic
We found no public information on VAT determination, OSS handling, B2B reverse charge, invoice formats, or the checkout elements German law requires such as order button wording and withdrawal policies. Nothing on the page evidences who keeps rates and legal texts current as the law moves. 1
Extensibility & developer surface
Show reasoningHide reasoning
How this is scored
Themes, apps, APIs and headless — whether the shop can be shaped to the business, and at what cost in lock-in.
0 — Fixed templates, no app ecosystem, no API.
3 — Theme editing within limits and a small app store; a read-mostly API and no local development story.
5 — Custom themes with a template language, an app or plugin ecosystem, a documented REST API, and webhooks for the core order events.
8 — Full storefront API for headless builds, an extension framework with its own lifecycle, staging environments, version control for themes, and documented rate limits.
10 — A platform a team can own: headless-first APIs, open-source or source-available core, plugin architecture with a real dependency model, local development and CI supported, and upgrade paths that do not orphan customisations.
The Merchant
This is the strong suit: an open-source core on Symfony, ready for headless and PWA, a REST API built with API Platform that can be customised, and an Addons Marketplace that launched with over 500 indexed plugins, backed by 700-plus contributors and 7,400-plus developers on Slack. I found no public information on staging environments, documented API rate limits or upgrade guarantees, which is what keeps it shy of the top mark. 1
The B2B Seller
The page states an open-source core on Symfony, a powerful and customizable REST API built with API Platform, headless and PWA readiness, and an Addons Marketplace with over 500 indexed plugins — a real developer surface with a behavior-driven testing culture, not a template shop. We found no public information on webhooks, rate limits, staging environments or upgrade paths for customisations, which is why I stop short of the top band. 1
The Developer
This is where the evidence concentrates: an open-source core on Symfony, a REST API built with API Platform for headless builds, an Addons Marketplace launched with over 500 indexed plugins, and a stack that runs on a plain VPS or under Docker and Kubernetes. The behaviour-driven testing story is a genuine developer-surface signal, but we found no public information on staging environments, theme version control, documented rate limits, or how upgrades treat customisations — the question I ask before committing five years to a platform. 1
The Operations Lead
Here the evidence is real: an open-source Symfony core, a REST API built with API Platform, headless and PWA readiness, and 700-plus contributors around a plugin marketplace of over 500. We found no public information on staging environments, documented rate limits or webhook coverage, so it stops short of the top band. 1
The Data Protection Officer
This is where the evidence is real: an open-source core, a headless-first REST API built with API Platform on Symfony, a marketplace with over 500 plugins, and a community of 700-plus contributors with over 120,000 downloads in thirty days. What is missing is public documentation of rate limits, staging environments and the upgrade path for customisations. 1
The Skeptic
This is the strong side: an open-source core on Symfony, a REST API built with API Platform, headless and PWA support, a marketplace of over 500 indexed plugins, and deployment on a standard VPS, Docker, Kubernetes or cloud. The behavior-driven development claim signals a real engineering story, though we found no public information on staging environments, rate limits or how upgrades treat customisations. 1
Order operations & back office
Show reasoningHide reasoning
How this is scored
What happens after checkout: order management, stock, returns, shipping, and the link to ERP or accounting.
0 — An order list and an email; stock is a number nobody trusts, returns are manual.
3 — Order statuses and basic stock, one shipping integration, and returns handled by hand.
5 — Order workflow with partial shipments, multi-warehouse stock, named carrier integrations with label printing, and a returns process in the system.
8 — Multi-channel order intake, automated fulfilment routing, supplier and dropshipping flows, and maintained interfaces to named ERP and accounting systems.
10 — The shop is the front of an operation: real-time stock across channels and warehouses, returns and refunds fully worked including partials, ERP integration the vendor maintains, and operational reporting a merchant runs the business from.
The Merchant
I found no public information on order workflow, partial shipments, stock, returns or carrier integrations; nothing on maintained interfaces to named ERP or accounting systems. The only adjacent signal is a customer quote praising the Plus edition's ability to integrate with existing systems, which is a testimonial rather than a documented interface I could hold anyone to. 1
The B2B Seller
The only operational signal is a customer quote praising the Plus edition's ability to integrate seamlessly with existing systems, with no carriers, stock, shipping, returns or ERP interfaces named. We found no public information on order management or back-office features. 1
The Developer
We found no public information on order management, stock, returns, shipping or ERP and accounting links. The adoption figures — 10,000+ stores and 76 partners — speak to usage, but the pages say nothing about what the back office actually does. 1
The Operations Lead
After checkout the page goes quiet: we found no public information on order workflow, stock across channels or warehouses, returns, carrier integrations with label printing, or interfaces to named ERP and accounting systems. The only operations-adjacent item is a customer quote praising Sylius Plus' 'ability to integrate seamlessly with our existing systems', which names nothing. 1
The Data Protection Officer
Beyond a customer quote that the Plus edition integrates with existing systems, I found no public information on order workflow, partial shipments, stock accuracy across warehouses, returns and refunds, or maintained interfaces to named ERP and accounting systems. 1
The Skeptic
We found no public information on order workflow, stock management, returns, carrier integrations or named ERP and accounting interfaces. The only related fact is a customer quote praising the Plus edition's ability to integrate with existing systems, which names no system and prices nothing. 1
Data ownership & exit
Show reasoningHide reasoning
How this is scored
Whether the catalogue, customers and order history remain the merchant's: export completeness, hosting choice, and what leaving actually costs.
0 — Export is a partial CSV; order history and customer records cannot leave intact, and hosting is the vendor's alone.
3 — CSV export of products and customers, order history partial, no self-hosting, no documented migration path.
5 — Complete export of catalogue, customers and orders via API or dump, documented deletion, and a stated data-return commitment.
8 — Full-fidelity export including media and order documents, self-hosting or a choice of hosting partner, and no metering that prices a migration out of reach.
10 — Ownership is structural rather than promised: open-source or source-available platform the merchant can run anywhere, database-level access, documented migration in both directions, and contractual data return.
The Merchant
Ownership here looks structural rather than promised: open-source code that runs on my own VPS, Docker or Kubernetes means my catalogue, customers and order history sit in my stack, not the vendor's. I found no public information on export completeness or a documented migration path, so the practical cost of leaving is my team's guesswork rather than a published commitment. 1
The B2B Seller
Open-source code that plays well on a standard VPS, Docker or Kubernetes under the merchant's own infrastructure is structural ownership rather than a promise — the shop can physically stay on the merchant's machines. We found no public information on export tooling, documented migrations in either direction or contractual data return, which keeps this below the top band. 1
The Developer
An open-source platform that plays well on a standard VPS and can be used with Docker and Kubernetes makes ownership structural: the merchant runs the whole stack wherever they choose. We found no public information on export tooling or a documented migration path in either direction, which is what keeps this short of the top. 1
The Operations Lead
Open source plus hosting the merchant picks — a standard VPS, Docker or Kubernetes — makes ownership structural rather than promised, and the REST API gives programmatic access. We found no public information on export completeness, documented migration in either direction or contractual data return, which is what holds it just under the top band. 1
The Data Protection Officer
Ownership looks structural rather than promised: the platform is open source and documented to run on a standard virtual server, Docker or Kubernetes, so the merchant holds the whole stack rather than renting it. However, I found no public information on export completeness for customers and order history, documented deletion of personal records, or a contractual data-return commitment. 1
The Skeptic
Ownership here looks structural rather than promised: the platform is open source and the vendor documents running it on a standard VPS, Docker, Kubernetes or cloud, so the catalogue and order history sit in infrastructure the merchant chooses. We found no public information on documented export and migration tooling in either direction or on any contractual data-return commitment. 1
European sovereignty
panel opinion
panel disagrees
Show reasoningHide reasoning
How this is scored
Where customer and order data live, who the contracting entity is, and which subprocessors sit in the checkout path. Independently sourced by the sovereignty pipeline.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — CDN, analytics, payment routing, support tooling — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that puts the shop entirely under the merchant's control.
The Merchant
The vendor's home is Opole, Poland, and a self-hosted deployment on my own infrastructure keeps the shop under my roof, both good signs for keeping customer and order data in Europe. But no sovereignty attributes are on record, there is no published subprocessor list and no certification to review, so I cannot see who or what sits in the checkout chain. 1
The B2B Seller
The headquarters and contracting address are in Opole, Poland, and the platform runs on infrastructure the merchant chooses, including their own stack, which puts both ends of the chain in Europe or under merchant control. We found no public information on a published subprocessor list, named hosting infrastructure as a standard offering, or certifications, so the middle of the chain is unevidenced. 1
The Developer
The headquarters address places the vendor at Książąt Opolskich 30/4, 45-006 Opole, Poland, so the contracting entity is European. Beyond that, no independently sourced sovereignty attributes are on record, and we found no public information on hosting arrangements as standard or on any subprocessor list. 1
The Operations Lead
The headquarters address in Opole, Poland points to a European contracting entity, and the hosting model puts infrastructure choice with the merchant. We found no published subprocessor list, no certification and no statement on where checkout-path data is processed, so it cannot rise past the middle. 1
The Data Protection Officer
The vendor address is Opole, Poland, which puts the company on the EU side of the ledger, and self-hosting on the merchant's own infrastructure is possible given the open-source model. But I found no public information on hosting defaults, no published subprocessor list, and no certification — as the person who must answer where the CDN, analytics and payment routing sit in the checkout, that absence decides the score. 1
The Skeptic
The vendor address is in Opole, Poland, so the company is European, but we found no public information on the contracting entity, hosting arrangements for the commercial edition, or any subprocessor list, and no certification is named. The sovereignty pipeline also records no attributes for this vendor. 1
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a merchant can compute the real annual cost — licence, transaction fees, apps, hosting — from public pages alone. The category where the headline price is least often the invoice.
0 — No public prices at all; every tier is a sales conversation.
3 — A monthly headline exists, but transaction fees, mandatory apps or hosting costs are unstated — the invoice is unknowable from the page.
5 — Tier prices public with billing period stated and transaction fees given, but at least one commonly needed piece (a required app, hosting, payment gateway rate) is unpriced.
8 — Every tier priced publicly including transaction or revenue-share rates, order or GMV limits, and the cost of the extensions most shops need; VAT treatment and minimum term stated.
10 — Complete price computability: annual cost derivable for a given order volume and GMV including licence, transaction fees, hosting and typical extensions — and for open-source platforms, an honest statement that the licence is free and where the money actually goes.
The Merchant
The open-source positioning tells me the base licence is free to obtain, but beyond that I found no public prices at all: not for the Plus edition, not for marketplace plugins, not for hosting or services. My real annual cost is a sales conversation, not a calculation I can do from the vendor's own pages. 1
The B2B Seller
The page states the platform is open source, which prices the community licence at nothing, but the Plus edition is presented without any figure, and no transaction fees, implementation, support or hosting costs appear anywhere on the page. A merchant cannot compute an annual cost from what is published — every paid tier is a sales conversation. 1
The Developer
The captured page describes the platform as open source and names a Sylius Plus edition, but we found no public information on what Plus costs or what any tier includes. Without prices, support rates or implementation costs stated anywhere, the annual spend is not computable from the page. 1
The Operations Lead
The page names an open-source platform and a Sylius Plus edition but attaches no figures to either; we found no public information on licence, subscription, implementation or support pricing. An operator cannot compute an annual cost from this — the price is a sales conversation. 1
The Data Protection Officer
I found no public prices at all: a commercial Plus edition is named without a figure, and the captured pages state nothing about licence cost, transaction or revenue-share fees, order limits, term or VAT treatment. The open-source description is the only pricing-relevant signal on the page, and no annual cost is computable from it. 1
The Skeptic
No price appears anywhere on the captured page — not for the Plus edition, not for partner implementation, not for support — so the only figure a merchant can rely on is the licence being open source and free. Every euro beyond that licence is a sales conversation, and the page does not say where the money actually goes. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 2 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. This is only a no-third-country-transfer clause for Clients' Personal Data under the website's commercial-services terms; no hosting location or hosting provider for the service itself is named anywhere in the excerpts.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any pricing information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- We could not confirm any compliance information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 15 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (4)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page sylius.com Checked 22 Sep 2026 Details →
- 2 Terms of service — found from the homepage sylius.com Checked 30 Sep 2026 Details →
- 3 Catalogue & checkout — found from sitemap sylius.com Checked 1 Oct 2026 Details →
- 4 Extensibility & developer surface — found from sitemap sylius.com Checked 1 Oct 2026 Details →