Importing a module
Generation isn’t the only way a module ends up in your library. If you already have an Odoo module as a ZIP — something you built by hand, downloaded from the Apps Store, or generated somewhere else — you can import it instead. OdoMate checks it for security and quality, extracts a specification from its code, writes it a user guide, and adds it to your Modules Library as a first-class module, version 1.
Starting an import
Section titled “Starting an import”Open the Modules Library and click Import module, next to the library’s heading.
-
Choose a language. This is the language OdoMate writes the module’s specification, summary and user guide in — it defaults to your interface language, but you can pick a different one for this import.
-
Drop or choose the ZIP. Drag a
.ziponto the drop area, or click it to pick a file — up to 10 MB. The import starts the moment a file is accepted; there’s no separate submit step.
What happens during the import
Section titled “What happens during the import”The dialog shows five steps as OdoMate works through them, with an elapsed timer next to them:
- Uploading and unpacking the ZIP
- Scanning the code for security risks
- Reading the module, writing its specification and user guide
- Packaging a clean copy for your library
- Test-installing it in a fresh Odoo database
This runs on OdoMate’s servers, not in your browser, and usually finishes in a few minutes. You can close the dialog without stopping it — it keeps going, and the finished module appears in your library on its own. Reopen the Modules Library later and, if the import is still running, it reattaches to the same progress instead of losing track of it.
The security gate
Section titled “The security gate”Before anything else, OdoMate scans the module’s code for a small set of dangerous patterns — dynamically executing code, or shelling out to the operating system — without running any of it. A module that trips this gate is rejected outright and never reaches the install step. Everything else the scan notices — an unvetted external dependency, an install hook that reaches outside the ORM, a data file with raw SQL — is recorded as a finding in the analysis report rather than blocking the import.
When it finishes
Section titled “When it finishes”- Imported. The dialog shows Module imported with a View in library button that jumps straight to the new tile. The module behaves like any generated one from here: it has a spec, a user guide, and can be enhanced, rolled back, downloaded, or pushed to GitHub. If the test install didn’t fully verify, the tile carries the same unverified badge a generation would.
- Rejected. The dialog shows Import rejected and, if the security gate is what stopped it, the specific findings that triggered it. Use Try another file to attempt a different ZIP — nothing was added to your library.
- Failed. The dialog shows Import failed — the platform hit a problem that had nothing to do with your module (storage, an LLM call, the install sidecar). Use Try another file to retry.
The analysis report
Section titled “The analysis report”Every import — imported, rejected, or failed with a partial scan — can have its report reopened later. For an imported module, the same report the dialog showed is also worth revisiting from the library if you want to check what OdoMate found. It covers:
- Odoo version — the series detected from the module’s manifest, flagged
if it isn’t Odoo 19, alongside specific deprecated-API signals (like
attrs=/states=or a<tree>view) found in the code. - Security and quality observations — an advisory pass over the code, separate from the security gate above; it can’t block the import, only inform you.
- Automated checks — syntax and semantic errors or warnings from the same validation generation uses.
- Install verification — whether the test install into a fresh Odoo database actually succeeded.
Rejected uploads
Section titled “Rejected uploads”An upload that never became a module isn’t discarded right away. Below the main library list, a Rejected uploads section (collapsed by default) lists uploads that failed the security gate, kept for 30 days. Each row shows when it was uploaded, how many findings it had, and a View report button that reopens the same analysis report.
