Size: 14.02 KB
# LIGHTWEIGHT SOCIAL MEDIA PLATFORM β MASTER DEVELOPMENT PROMPT Build a professional, modern, secure, responsive and lightweight **standalone Social Media Platform** from scratch. **Do NOT use WordPress, BuddyPress, WordPress plugins/themes, OneSignal or any third-party social-media CMS.** Build the complete system with its own backend, database, frontend, authentication, social features, notification system, messaging, moderation and custom Super Admin Panel. The main priorities are: **Simple + Fast + Secure + Mobile-first + Responsive + Low Hosting Usage + Complete Admin Control** --- ## 1. TECHNOLOGY Use a lightweight production-ready stack. Recommended: - PHP 8.2+ - MySQL/MariaDB - HTML5 - CSS3 - Vanilla JavaScript/lightweight JavaScript The platform must work on normal shared hosting initially and be scalable to VPS/cloud later. Use clean modular architecture. Do not put the complete application in one PHP file. --- ## 2. USER REGISTRATION & AUTHENTICATION Implement: - Registration - Login/logout - Email verification - Forgot/reset password - Change password - Edit profile - Account deletion - Secure password hashing - Secure sessions - CSRF protection - XSS protection - SQL injection protection - Rate limiting - Brute-force protection Each user's private data must be completely isolated from other users. --- ## 3. USER PROFILE Public profile URL: `platform.com/@username` Profile includes: - Profile photo - Cover photo - Username - Display name - Bio - Website link - Followers - Following - Posts - Communities - Verification badge Profile actions: - Follow/Unfollow - Message - Block - Report - Share profile --- ## 4. VERIFICATION SYSTEM Create a blue verification system inspired by modern social networks but with an original implementation. Default rule: **500 followers = verification eligible** 500 followers should make the user eligible to request verification, not automatically verified. Flow: `500 Followers β Eligible β Request β Admin Review β Approve/Reject β Blue Badge` Admin must be able to change the required follower number from the Admin Panel without editing code. Example: `500 β 1,000 β 5,000` Admin can also manually verify/unverify any user. Users must clearly see verification information: > βReach 500 followers to become eligible for profile verification.β Show progress: `420 / 500 followers` After reaching the threshold: > βCongratulations! You are eligible to request verification.β --- ## 5. HOME FEED Create a fast social feed containing: - Posts from followed users - User's own posts - Public recommended posts - Community posts Load only 10β20 posts initially. Use pagination/infinite loading, lazy loading and efficient queries. Never load thousands of posts at once. --- ## 6. POST SYSTEM Users can create: ### Text Posts Normal text and lightweight formatting. ### Image Posts Multiple images per post. Automatically: - Validate MIME type - Compress images - Resize large images - Convert to WebP/AVIF where appropriate - Generate thumbnails - Limit file size - Secure uploads Do not allow executable files. Post actions: - Like - Reaction - Comment - Reply - Repost - Share - Bookmark - Edit own post - Delete own post - Report - Copy link - Pin post --- ## 7. VIDEO POLICY To reduce hosting/storage usage: **Do not allow direct video uploads initially.** Allow safe external video links/embeds such as YouTube/Vimeo. Direct video uploads may be added in the future. --- ## 8. REACTIONS & COMMENTS Reactions: - Like - Love - Laugh - Wow - Sad - Angry Comments support: - Comment - Reply - Like/react - Edit own comment - Delete own comment - Report Use pagination for large comment sections. --- ## 9. FOLLOW & BOOKMARK Users can: - Follow - Unfollow - View followers - View following Bookmarks should store only: `user_id + post_id` Do not duplicate post content. --- ## 10. PRIVATE MESSAGING Any registered user can privately message another user by default. Chat supports: - Text - Emoji - Optimized image - Read/unread - Timestamp - Delete own message - Block - Report Do not allow large video uploads. Message privacy settings: - Everyone - Followers only - Nobody Default: **Everyone** Admin must be able to globally enable/disable messaging. Use pagination for chat history. --- ## 11. NOTIFICATION SYSTEM Do NOT use OneSignal. Build notifications using the platform's own database and code. Notifications: - New follower - Follow request - Like - Reaction - Comment - Reply - Mention - Repost - New private message - Verification status - Community activity - Admin announcements Header notification bell: `π 5` Support unread/read and βMark all as readβ. ### Notification Retention Default: **Delete notifications older than 30 days automatically.** Admin can change retention: `7 / 15 / 30 / 60 / 90 days` Do not delete private messages through notification cleanup. Optional native browser push can use Web Push API + Service Worker without OneSignal. --- ## 12. MENTIONS & HASHTAGS Support: `@username` Mention creates a notification. Support: `#technology` Hashtag pages: `platform.com/hashtag/technology` Normalize hashtags to prevent duplicates. --- ## 13. SEARCH & EXPLORE Search: - Users - Posts - Hashtags - Communities Use database indexes and efficient queries. Explore page: - Trending hashtags - Popular public posts - Suggested users - Popular communities Keep recommendation logic lightweight and cache results. --- ## 14. COMMUNITIES Users can create communities. Community: - Name - Description - Logo - Cover - Rules - Public/private setting Features: - Join - Leave - Posts - Comments - Members - Admin - Moderators - Reports Community admins can moderate their communities. --- ## 15. BLOCK, MUTE & REPORT Users can: - Block/unblock - Mute/unmute - Report Reports can target: - User - Post - Comment - Community - Message where appropriate Reasons: - Spam - Harassment - Abuse - Fake account - Inappropriate content - Copyright concern - Other All reports go to Admin moderation. --- # 16. CUSTOM SUPER ADMIN PANEL Create a completely independent Admin Panel: `platform.com/admin` No WordPress admin. Admin Panel must also be fully responsive. ### Dashboard Show: - Total users - New users - Active users - Posts - Comments - Communities - Pending reports - Verification requests - Storage usage - Database size - Media usage ### User Management Admin can: - Search/view users - Activate - Suspend - Ban - Delete - Verify/unverify - View reports - Manage limits ### Content Management Manage: - Posts - Comments - Communities - Reports - Hashtags - Media ### Admin Roles Support: - Super Admin β full access - Moderator β moderation - Support Admin β user support Use granular permissions. --- ## 17. ADMIN GLOBAL SETTINGS Important platform features must be controlled from Admin Panel without editing source code. Settings: - Registration ON/OFF - Email verification - Posts - Comments - Follow system - Messaging - Notifications - Browser push - Communities - Verification - Affiliate system - Digital products - Sponsored posts - Media uploads - Storage limits - User limits - Anti-spam - Security - SEO - Maintenance mode - Platform branding --- ## 18. LIGHT & DARK MODE **Light Mode must be the default.** Every new user starts in Light Mode. User can manually switch to Dark Mode. Remember the user's selected preference. Apply modes to: - Home - Profile - Feed - Posts - Comments - Messages - Notifications - Search - Communities - Settings - Login - Admin Panel Dark Mode must never be the default. --- ## 19. RESPONSIVE DESIGN The entire platform must be mobile-first and responsive. Support: - Android - iPhone - Tablet - Laptop - Desktop - Large screens Mobile navigation can use: `Home | Explore | Create | Notifications | Profile` Admin Panel must also work properly on mobile. --- ## 20. LOW HOSTING USAGE This is a critical requirement. Use: **One shared application + shared theme/assets + user-specific database records/media.** Do NOT create separate application installations for each user. Do not duplicate: - PHP files - CSS - JavaScript - Themes - Framework files for each user. ### Storage Optimization - Compress images - Resize images - WebP/AVIF - Generate thumbnails - Limit upload size - Limit user storage - Do not store images as MySQL BLOBs - Store media files separately - Store only file path/metadata in database - Do not store unnecessary logs - Do not duplicate repost content For reposts store: `original_post_id + user_id` For bookmarks store: `user_id + post_id` --- ## 21. DATABASE PERFORMANCE Use proper indexes for: - user_id - username - post_id - created_at - followers - comments - notifications - hashtags - reports Use pagination everywhere. Never fetch entire tables unnecessarily. Use prepared statements. --- ## 22. AUTOMATIC CLEANUP Automatically clean: - Expired sessions - Old notifications - Temporary files - Failed uploads - Deleted media - Old security logs - Cache files Admin can configure retention periods. --- ## 23. STORAGE LIMITS Admin can configure: - Profile image size - Post image size - Storage per user - Images per post - Maximum posts - Maximum communities - Message media limits No important limits should be permanently hard-coded. --- ## 24. SECURITY & ANTI-SPAM Implement: - Secure password hashing - CSRF - XSS prevention - SQL injection prevention - Prepared queries - Rate limiting - Secure sessions/cookies - Security headers - Secure file uploads - MIME validation - Permission checks - Admin authorization - Login protection Anti-spam limits for: - Posts - Comments - Follows - Messages - Login attempts - Reports Add CAPTCHA support for suspicious activity. --- ## 25. SEO Public content supports: - SEO title - Meta description - Canonical URL - Open Graph - Sitemap - Robots.txt Private content must not be indexed when privacy settings prohibit it. --- # 26. USER EARNING SYSTEM Do NOT implement: - Paid Subscription - Referral System - Ad Revenue Sharing - Virtual Coins - Gifts - Creator Bonus Users can earn only through: ### Affiliate Marketing Users can add approved affiliate links to posts. ### Sponsored Posts Brands/advertisers can work with creators for sponsored content. ### Digital Products Users can sell eligible digital products such as: - PDF - Ebook - Template - Design - Other digital files These features must be controlled by Admin. --- ## 27. DIGITAL PRODUCTS If enabled, creators can: - Add product - Upload digital file - Set price - Add description - Add cover image - Publish - View sales Use secure download URLs. Admin controls: - Enable/disable marketplace - Maximum file size - Commission % - Product limits - Allowed file types - Refund settings --- ## 28. PLATFORM MONETIZATION Platform owner can earn through: - Google AdSense where policy-compliant - Direct sponsorship - Platform affiliate marketing - Digital product transaction commission Do NOT implement creator AdSense revenue sharing. --- ## 29. SPONSORED CONTENT Sponsored posts must be clearly identified. Structure: `Advertiser β Creator β Sponsored Post` Payment can initially be handled outside the platform. Admin can moderate sponsored content. --- ## 30. AFFILIATE SYSTEM Admin can: - Enable/disable affiliate links - Configure allowed domains - Review reported links - Remove inappropriate links Validate URLs and block malicious links. --- ## 31. PRIVACY Provide: - Public/private profile - Message privacy - Content privacy - Account deletion - Data export architecture - Privacy policy - Terms page Collect only necessary user information. --- ## 32. BACKUP & INSTALLATION Create installation wizard: `Database β Admin Account β Platform Settings β Email β Storage β Security β Finish` After installation disable/lock installer. Prepare: - Database backup - Media backup - Configuration backup - Restore architecture Do not keep unlimited backups on the same hosting account. --- ## 33. CODE QUALITY Use clean modular architecture with separate modules for: - Authentication - Users - Profiles - Posts - Comments - Reactions - Followers - Messaging - Notifications - Communities - Media - Verification - Affiliate - Digital Products - Sponsored Content - Moderation - Admin - Settings Never expose database credentials, API keys or secrets. Normal users must never see server/database errors. --- # FINAL PRODUCT REQUIREMENTS The finished platform must be: - Standalone - WordPress-free - BuddyPress-free - OneSignal-free - Fully responsive - Mobile-first - Light Mode by default - Dark Mode optional - Secure - Lightweight - Low-storage - Low-hosting-load - Scalable - Easy to use - Fully controlled by custom Admin Panel Core user flow: **Register β Profile β Follow β Post β Like/Comment/Repost β Message β Communities β Reach 500 Followers β Request Verification β Admin Approval β Blue Badge** User earning: **Affiliate + Sponsored Posts + Digital Products** Platform earning: **AdSense + Sponsorship + Affiliate + Digital Product Commission** Do not add features that were explicitly excluded above. Prioritize **speed, simplicity, security, low hosting usage and maintainability** over unnecessary complexity.β¬οΈ Download Now