Skip to content
Back to skills

Wiki Js

ASecurity

Deploy and manage Wiki.js documentation sites avoiding common configuration traps.

  • 17 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 6, 2026
databasessqlgitdatabasedocumentation

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill wiki-js --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Wiki Js?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Wiki Js
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-wiki-js/badge)](https://www.skillsdirectory.com/skills/clawic-wiki-js)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Wiki.js
slug: wiki-js
version: 1.0.0
description: Deploy and manage Wiki.js documentation sites avoiding common configuration traps.
homepage: https://clawic.com/skills/wiki-js
metadata:
  clawdbot:
    emoji: 📖
    os:
    - linux
    - darwin
    - win32
    displayName: Wiki.js
---

## Critical Initial Config
- Site URL must be correct from first setup — changing later breaks all internal links, no easy fix
- PostgreSQL over SQLite for any multi-user setup — SQLite locks under concurrent writes
- HTTPS terminates at reverse proxy — Wiki.js runs HTTP internally, don't configure SSL in Wiki.js

## Editor Traps
- Visual Editor uses HTML underneath — switching from Markdown loses formatting, can't switch back cleanly
- Markdown editor is the safe default — WYSIWYG has rendering quirks and sync issues
- Internal links require locale prefix — `[Link](/en/path/to/page)` not just `/path/to/page`

## Permission Pitfalls
- Deny rules take precedence over allow — overlapping patterns cause unexpected lockouts
- Page rules use path patterns — `/engineering/*` covers subpages, `/engineering` is exact match only
- Default "Users" group applies to all new accounts — configure before inviting users

## Storage and Sync
- Git sync is one-way by default — Wiki.js to Git only, external edits don't sync back
- Asset storage in database bloats backups — use S3/GCS for images on larger wikis
- Database backup IS the complete backup — all content, users, permissions stored there

## Search Behavior
- Search respects permissions — users don't find pages they can't access (can cause confusion)
- Search index rebuilds automatically — large imports need patience, no manual trigger helps
- Elasticsearch optional — built-in DB search works but lacks relevance ranking

## Troubleshooting Specifics
- Login redirect loops — almost always HTTPS/HTTP mismatch in Site URL config
- Assets not loading — Site URL doesn't match actual access URL
- Page shows 404 after creation — special characters in path, use lowercase alphanumeric
- Slow after import — search reindexing in progress, wait or check Admin > Utilities

Files in this skill

  • SKILL.md2.1 KB
  • _meta.json166 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…