Policy: Moodle™ Third-Party Plugins

Last updated: 23 July 2026

1. Purpose

This policy sets out the conditions under which third-party plugins may be assessed, installed, maintained and supported on Moodle™ sites hosted, managed or supported by Pukunui.

Third-party plugins can extend the functionality of Moodle™ but may introduce additional security, privacy, compatibility, accessibility, licensing, support and operational risks.

This policy should be read together with the applicable Moodle™ Support Agreement, hosting agreement, proposal, statement of work and Pukunui’s Third-Party Integrations Policy.

Where there is any conflict between this policy and a signed agreement between Pukunui and the Client, the signed agreement will take precedence.

2. Definitions

For the purposes of this policy:

Client means the person or organisation receiving hosting, support, development or other Moodle™ services from Pukunui.

MSA means the Moodle™ Support Agreement or other applicable support or services agreement between Pukunui and the Client.

Moodle Marketplace means the marketplace operated by Moodle Pty Ltd through which third-party plugins and integrations may be distributed free of charge or for a fee.

Plugin Provider means the individual or organisation responsible for developing, supplying, licensing, maintaining or supporting a TPP.

Pukunui means Pukunui Technology in Australia, Pukunui Limited in Hong Kong, Pukunui Sdn Bhd in Malaysia, and their employees, contractors and authorised service providers.

Third-Party Plugin or TPP means any plugin, extension, add-on, theme, integration component or other software installed into or used with Moodle™ that is not part of the standard Moodle™ core distribution maintained by Moodle Pty Ltd.

A TPP remains a third-party product whether it is obtained through Moodle Marketplace, directly from a developer, from a public code repository, through another marketplace, or from any other source.

3. Scope

This policy applies to:

  • Requests to install a new TPP.
  • Existing TPPs already installed on a Client’s Moodle™ site.
  • Updates, upgrades, replacements or removal of TPPs.
  • Free, paid, subscription-based and custom TPPs.
  • TPPs obtained through Moodle Marketplace or another source.
  • TPPs that connect Moodle™ to an external platform or service.
  • Forked, modified, privately maintained or abandoned TPPs.
  • TPPs installed or modified by the Client or another service provider.

Where a TPP connects Moodle™ to an external product or service, both this policy and Pukunui’s Third-Party Integrations Policy may apply.

4. Third-party status

A TPP is supplied and controlled by its Plugin Provider.

Unless expressly agreed otherwise in writing, Pukunui is not:

  • The developer, owner, supplier or licensor of the TPP.
  • The merchant or reseller responsible for its sale.
  • A party to the agreement between the Client and the Plugin Provider.
  • Responsible for the Plugin Provider’s services, support, documentation or business practices.
  • Responsible for setting or controlling the TPP’s price, licence terms, subscription conditions or release schedule.

The Plugin Provider is responsible for the TPP’s functionality, quality, documentation, licensing, security updates, maintenance, compatibility and product-level support.

Pukunui cannot require a Plugin Provider to maintain, update, repair or continue supplying a TPP.

5. Moodle Marketplace listings

The presence of a TPP on Moodle Marketplace does not mean that Pukunui has approved, endorsed, certified or independently tested it.

Any Marketplace review, rating, badge, compatibility statement, supported-version information or other listing information is not a warranty from Pukunui that the TPP:

  • Is suitable for the Client’s requirements.
  • Is secure or free from defects.
  • Will operate correctly in the Client’s environment.
  • Complies with applicable privacy or accessibility requirements.
  • Will remain available or free of charge.
  • Will receive future maintenance or security updates.
  • Will remain compatible with future versions of Moodle™ or related infrastructure.

Pukunui may consider Marketplace information when assessing a TPP but is not required to rely on it.

A TPP does not have to be listed on Moodle Marketplace for Pukunui to consider installing it. However, plugins obtained from other sources may require additional assessment and may present greater maintenance or security risks.

6. Requesting a plugin

Requests to install, update or replace a TPP must be submitted to Pukunui through an approved support or project channel.

The request should include, where available:

  • The name and purpose of the TPP.
  • A link to its Marketplace listing, source repository or supplier website.
  • The required Moodle™ version.
  • The relevant licence and subscription terms.
  • Technical and user documentation.
  • Privacy and data-processing information.
  • Details of any external service used by the TPP.
  • Information about the data the TPP accesses, stores or transmits.
  • Any installation package, licence key or account credentials required.
  • The Client’s required implementation timeframe.

Pukunui may request additional information before assessing or installing the TPP.

Pukunui may decline to assess or install a TPP where sufficient information, documentation, source code or supplier support is unavailable.

7. Approval and technical assessment

Pukunui may approve a TPP based on prior experience with the plugin and the relevant version.

For other TPPs, Pukunui may perform a limited technical assessment before approving installation.

The scope of an assessment may include:

  • Compatibility with the Client’s Moodle™ version.
  • Compatibility with the hosting environment.
  • Known security vulnerabilities.
  • Code quality or maintenance concerns visible during the assessment.
  • Performance or resource-use concerns.
  • Conflicts with Moodle™ core or other installed plugins.
  • Scheduled tasks, background processes or external communications.
  • The reputation and activity of the Plugin Provider.
  • The availability of documentation and support.
  • The plugin’s release and maintenance history.

Any assessment performed by Pukunui is limited to the code, documentation, environment and information available at the time.

An assessment is not:

  • A comprehensive source-code audit.
  • A penetration test.
  • A guarantee that the TPP is free from defects, malicious code or vulnerabilities.
  • A privacy, legal or regulatory assessment.
  • An accessibility audit or certification.
  • A guarantee of future compatibility or support.

Approval only applies to the version assessed and the environment in which it was assessed. Pukunui may reassess a TPP following an update, change of ownership, change of licence, security incident or significant Moodle™ or infrastructure upgrade.

Assessment work may be chargeable where it falls outside the MSA or requires substantial investigation.

8. Assessment outcomes

Following an assessment, Pukunui may:

  1. Approve the TPP for installation.
  2. Approve the TPP subject to specified conditions.
  3. Recommend testing or installation on a staging environment first.
  4. Identify issues that should be corrected before installation.
  5. Provide a quotation to modify, remediate or integrate the TPP.
  6. Recommend an alternative TPP or approach.
  7. Decline to install the TPP.
  8. Require an existing TPP to be disabled, updated, replaced or removed.

Pukunui may decline installation where it reasonably considers that a TPP presents an unacceptable security, stability, privacy, compatibility, legal, licensing, performance or operational risk.

Approval of one version of a TPP does not constitute automatic approval of later versions.

9. Client responsibilities

Before requesting or approving the use of a TPP, the Client is responsible for determining whether the TPP is appropriate for its operational, educational, technical and legal requirements.

The Client is responsible for:

  • Reviewing the TPP’s functionality and suitability.
  • Reviewing the Plugin Provider’s licence and terms of sale.
  • Reviewing applicable subscription, renewal, cancellation and refund terms.
  • Maintaining valid licences and subscriptions.
  • Paying all TPP purchase, subscription, renewal, tax and supplier-support fees.
  • Maintaining an appropriate relationship with the Plugin Provider.
  • Obtaining any necessary internal, procurement, legal or regulatory approvals.
  • Reviewing the Plugin Provider’s privacy policy and data practices.
  • Determining whether the intended use complies with applicable laws and organisational policies.
  • Completing user-acceptance testing.
  • Reporting TPP issues to Pukunui with sufficient information to investigate them.
  • Informing Pukunui of changes to the TPP’s licence, ownership, support status or commercial terms.

Unless otherwise agreed, licences and Marketplace purchases should be registered in the Client’s name and under an account controlled by the Client.

10. Fees, licences and subscriptions

TPP licence, subscription, purchase, renewal and supplier-support fees are not included in the MSA unless expressly stated otherwise.

The Client is responsible for purchasing and renewing all required licences and subscriptions.

Where Pukunui agrees to purchase a TPP on the Client’s behalf, the following must be agreed in writing:

  • The party responsible for payment.
  • The owner of the Marketplace or supplier account.
  • The licence holder.
  • The renewal process.
  • Any reimbursement or administrative charges.
  • The procedure for transferring the licence or account to the Client.

Pukunui is not responsible for disruption or loss of functionality caused by:

  • An expired or suspended licence.
  • Failure to renew a subscription.
  • A failed payment.
  • A change in the Plugin Provider’s commercial terms.
  • A Plugin Provider withdrawing a free version.
  • A previously free TPP becoming a paid product.
  • The Client losing access to its supplier or Marketplace account.

Pukunui is not required to purchase, renew or maintain a licence on the Client’s behalf unless this responsibility is expressly included in a written agreement.

11. Installation and deployment

Pukunui may require a TPP to be installed and tested on a staging or test environment before installation on a production site.

Installation may be subject to:

  • A maintenance window.
  • A current backup.
  • A rollback plan.
  • Technical testing.
  • User-acceptance testing by the Client.
  • Testing of scheduled tasks and background processes.
  • Testing of affected integrations.
  • Performance or security monitoring.
  • Written acknowledgement of identified risks.

The Client is responsible for confirming that the TPP meets its functional requirements.

Successful installation or testing does not constitute a guarantee that the TPP will remain free from defects or continue to work after future changes.

12. Support

Pukunui will provide support for Moodle™ core in accordance with the applicable MSA.

TPP support is outside the standard scope of the MSA unless expressly included in the relevant agreement, proposal or statement of work.

TPP-related services may include:

  • Installation and initial configuration.
  • Investigation of compatibility issues.
  • Troubleshooting plugin behaviour.
  • Liaison with the Plugin Provider.
  • Applying plugin updates or patches.
  • Custom development or remediation.
  • Replacement or migration to another plugin.
  • Data recovery following a plugin failure.
  • Testing following Moodle™ or infrastructure upgrades.

These services may be quoted and charged separately.

Pukunui may provide occasional assistance with a TPP without creating an ongoing obligation to provide the same assistance in the future.

Where an incident is caused or materially contributed to by a TPP, time spent identifying, isolating or resolving the issue may be chargeable unless the applicable agreement expressly includes that work.

Product-level support, refunds, feature requests and defects within the TPP remain the responsibility of the Plugin Provider.

13. Compatibility and upgrades

Pukunui does not guarantee that a TPP will be compatible with:

  • The Client’s current Moodle™ environment.
  • Future versions of Moodle™.
  • Future versions of PHP, the database, operating system or other infrastructure.
  • Other installed TPPs.
  • Changes made by the Plugin Provider.
  • Changes to an external service used by the TPP.

Compatibility information supplied through Moodle Marketplace or by the Plugin Provider is provided by that third party and is not independently guaranteed by Pukunui.

Pukunui may reassess installed TPPs before a Moodle™ or infrastructure upgrade.

Where a TPP is incompatible with a proposed upgrade, Pukunui may:

  • Postpone the upgrade where it is reasonable and safe to do so.
  • Recommend updating or replacing the TPP.
  • Recommend removing the TPP.
  • Quote for remediation, redevelopment or migration work.
  • Require the Client to accept a temporary or permanent loss of TPP functionality.
  • Proceed with an essential security or infrastructure upgrade where postponement would create an unacceptable risk.

Pukunui is not obligated to delay an essential security update indefinitely because of an incompatible TPP.

Where an upgrade is delayed because of a TPP, Pukunui may require the Client to approve an alternative remediation plan.

14. Security and emergency action

The Plugin Provider is primarily responsible for providing security patches and maintaining the security of its TPP.

Pukunui may temporarily disable, isolate, restrict or remove a TPP without prior approval where Pukunui reasonably considers this necessary to protect:

  • The security of the Client’s site.
  • Personal or confidential information.
  • The availability or integrity of the site.
  • Pukunui’s hosting infrastructure.
  • Other clients or services.
  • Backups, scheduled tasks or system resources.
  • Pukunui’s legal or regulatory obligations.

Examples include suspected exploitation, malicious behaviour, data corruption, excessive resource usage, spam activity, unauthorised external communication or a serious unpatched vulnerability.

Where reasonably practicable, Pukunui will notify the Client before taking action. In an urgent situation, Pukunui may act first and notify the Client as soon as reasonably practicable afterwards.

Any remediation, investigation, replacement or recovery work may be chargeable in accordance with the applicable agreement.

15. Privacy and data protection

A TPP may access, collect, modify, export, transmit, store or delete information held within the Client’s Moodle™ site.

This may include:

  • User identity and profile information.
  • Course and enrolment information.
  • Assessment results and submissions.
  • Communications and activity records.
  • Authentication information.
  • Analytics and usage information.
  • Personal, confidential or sensitive information.

The Client is responsible for determining whether use of the TPP complies with applicable privacy, data-protection, records-management and sector-specific requirements.

Before approving a TPP that processes or transfers data, the Client should review:

  • The Plugin Provider’s privacy policy.
  • The categories of data processed.
  • The purposes for which the data is used.
  • Data-hosting and storage locations.
  • International data transfers.
  • Retention and deletion practices.
  • Subprocessors and connected services.
  • Security measures.
  • Data-breach notification arrangements.
  • Contractual or data-processing terms.

Pukunui’s technical approval or installation of a TPP does not constitute legal, privacy or regulatory approval.

Unless separately commissioned, Pukunui is not responsible for completing privacy impact assessments, obtaining consent, preparing legal notices or reviewing the Plugin Provider’s compliance with applicable law.

Pukunui may decline installation where adequate privacy or data-processing information is unavailable.

16. Accessibility

Unless expressly included in an agreed scope of work, Pukunui does not warrant or certify that a TPP complies with WCAG or any other accessibility standard or legal requirement.

The Client is responsible for determining its accessibility requirements and assessing whether the TPP satisfies them.

Accessibility testing, remediation or alternative functionality may be quoted separately.

17. External services and integrations

Where a TPP connects to an external service, platform or API, the Client may also be subject to the Plugin Provider’s or external service provider’s terms, fees, privacy practices, service limits and availability.

Pukunui is not responsible for:

  • Outages or changes to an external service.
  • API changes or usage limits.
  • Changes to third-party authentication requirements.
  • Changes to external service pricing.
  • Data processed outside Pukunui’s systems.
  • The acts or omissions of the external service provider.

Pukunui’s Third-Party Integrations Policy also applies to these arrangements.

18. Discontinuation, delisting and abandonment

A TPP may be withdrawn, delisted, suspended, sold, transferred, abandoned or discontinued by its Plugin Provider or by the marketplace through which it is distributed.

A Plugin Provider may also:

  • Stop providing updates.
  • Stop supporting particular Moodle™ versions.
  • Change the TPP’s licence.
  • Introduce a subscription or fee.
  • Transfer the TPP to another maintainer.
  • Stop issuing security patches.
  • Replace the TPP with another product.
  • Restrict access to future releases.

Pukunui is not responsible for these decisions.

Where a TPP becomes unsupported, unavailable or unsuitable, Pukunui may recommend or require that it be:

  • Retained temporarily with documented risks.
  • Disabled.
  • Removed.
  • Replaced.
  • Modified or forked.
  • Rebuilt as custom functionality.

Any assessment, replacement, migration or development work may be quoted separately.

Pukunui does not guarantee that a suitable replacement will be available or that data can be transferred to an alternative plugin without modification or loss.

19. Modified, custom and forked plugins

A TPP that has been modified from its standard release may no longer be supported by its original Plugin Provider.

Modifying or forking a TPP may:

  • Prevent standard updates from being applied.
  • Require modifications to be reviewed and reapplied after future updates.
  • Create additional testing requirements.
  • Introduce security or compatibility risks.
  • Require ongoing custom maintenance.

Pukunui is not obligated to maintain a modified or forked TPP indefinitely unless a separate maintenance agreement is in place.

Any ownership, licensing, source-code access and ongoing maintenance arrangements for custom or modified plugins should be documented separately.

20. Unapproved installations and changes

Where Pukunui manages the hosting environment or Moodle™ codebase, the Client and its other suppliers must not install, update, replace, remove or modify server-side TPPs without Pukunui’s prior approval.

The Client must disclose:

  • TPPs installed outside Moodle Marketplace.
  • Plugins installed directly from a code repository.
  • Custom or privately developed plugins.
  • Forked or modified plugins.
  • Manual changes to plugin source code.
  • Licence-restricted or encoded software.
  • Changes made by another supplier.

Where an unapproved TPP or modification causes or contributes to an incident:

  • Pukunui is not responsible for the resulting disruption, loss or incompatibility except to the extent required under the applicable agreement or law.
  • Relevant service levels may not apply while the TPP causes or contributes to the incident.
  • Investigation and remediation work may be chargeable.
  • Pukunui may require the TPP to be disabled or removed.
  • Pukunui may suspend affected services where necessary to protect its systems or other clients.

A material or repeated breach may be managed under the suspension or termination provisions of the applicable MSA rather than automatically voiding the entire MSA.

21. No continuing approval or warranty

Approval, installation, testing, updating or previous support of a TPP does not create a continuing warranty or obligation.

Pukunui does not warrant that a TPP will:

  • Meet all of the Client’s requirements.
  • Operate without interruption or error.
  • Remain secure.
  • Remain supported.
  • Remain free of charge.
  • Continue to work with future software or infrastructure.
  • Remain available from the Plugin Provider or Moodle Marketplace.

Any liability relating to Pukunui’s services remains subject to the applicable MSA and other signed agreements.

22. Policy updates

Pukunui may update this policy to reflect changes in Moodle™, Moodle Marketplace, technology, security practices, legal requirements or Pukunui’s services.

Where reasonably practicable, Pukunui will notify affected clients of material changes.

The version published on Pukunui’s website will be the current version of this policy unless a signed agreement expressly provides otherwise.

23. Contact

Clients with questions about an existing or proposed TPP should contact Pukunui through their usual support channel.

Pukunui can assist with:

  • Preparing quotations for remediation, migration or custom development.
  • Reviewing currently installed TPPs.
  • Identifying plugins affected by Moodle™ upgrades.
  • Assessing potential replacements.
  • Reviewing installation and support requirements.