Client Area

Keep your installation secure: an operator's checklist

Please read: this update needs your attention.
The layers of a WBAMS installation
Notice 1 min read

WBAMS holds your customers' invoices and the keys to your payment gateways. Six habits keep it safe, and none of them takes more than a few minutes.

Do these once

  • Turn on two-factor authentication for every administrator. It is under My Account in the control panel. A password alone is not enough for an account that can refund money.
  • Serve the site over HTTPS only. Set the System URL to https:// and let your web server redirect plain HTTP. Payment gateways refuse callbacks to insecure addresses.
  • Keep the shipped .htaccess files in place. The storage directory carries its own, so uploaded files, caches and logs are never served directly; a deployment that strips dot-files loses that guard.
  • Rename the control panel folder - customadminpath in settings.php - and restrict it to your office addresses at the web server if you can.

Do these regularly

  • Install updates when they are offered. The control panel checks for new releases and installs them in place; the changelog tells you what each one fixes.
  • Keep a backup you have actually restored. The database and the storage directory are the whole installation. Test the restore on a spare server once, so the first time is not during an outage.

If something looks wrong

Change every administrator password, rotate the API keys in your payment gateways, and read Platform › Activity Log for actions you do not recognise. Then open a ticket with us and tell us what you found.

Never send a gateway secret key, an API token or a database password in a support ticket. We will never ask for one.

More updates

All updates

Welcome to WBAMS: your billing workspace is ready

Everything a subscription business needs to bill, collect and support its customers now lives in one place. This is the first update in your newsroom; here is what you have, and where to start.

Powered by WBAMS