WBAMS holds your customers' invoices and the keys to your payment gateways. Six habits keep it safe, and none of them takes more than a few minutes.
Do these once
- Turn on two-factor authentication for every administrator. It is under My Account in the control panel. A password alone is not enough for an account that can refund money.
- Serve the site over HTTPS only. Set the System URL to https:// and let your web server redirect plain HTTP. Payment gateways refuse callbacks to insecure addresses.
- Keep the shipped .htaccess files in place. The storage directory carries its own, so uploaded files, caches and logs are never served directly; a deployment that strips dot-files loses that guard.
- Rename the control panel folder -
customadminpathin settings.php - and restrict it to your office addresses at the web server if you can.
Do these regularly
- Install updates when they are offered. The control panel checks for new releases and installs them in place; the changelog tells you what each one fixes.
- Keep a backup you have actually restored. The database and the storage directory are the whole installation. Test the restore on a spare server once, so the first time is not during an outage.
If something looks wrong
Change every administrator password, rotate the API keys in your payment gateways, and read Platform › Activity Log for actions you do not recognise. Then open a ticket with us and tell us what you found.
Never send a gateway secret key, an API token or a database password in a support ticket. We will never ask for one.
