Essential practices

  • Use unique passwords and individual accounts.
  • Grant the minimum permissions required.
  • Protect API keys, backups and server configuration.
  • Keep PHP and server software updated.
  • Review access after every team or partner change.
  • Maintain a tested incident response and restore procedure.

Continue through the module

The Security module provides detailed instructions for account protection, server hardening, secure uploads, integrations, backup safety and incident response.

Recommended next step

Open the Security Review Checklist and verify the live installation item by item.