Retail operations lead and security specialist reviewing checkout, payments and administrator access

E-commerce Security Checklist: Checkout, Payments and Admin Access

Use this e-commerce security checklist to review admin access, platform updates, payment-page scripts, apps, customer data, recovery and incident response.

An e-commerce security checklist must protect the administrator route, storefront code, payment journey, customer data and operational integrations together. A valid certificate and a reputable payment provider are important, but they do not prevent stolen admin sessions, vulnerable extensions, malicious scripts or unsafe fulfilment access.

Reviewed: 9 September 2026

E-commerce security checklist at a glance

Area Minimum check Evidence
Admin access Named users, MFA, least privilege and prompt offboarding User and role review
Platform Supported software, controlled updates and minimal apps Version and change record
Checkout Authorised scripts, trusted payment flow and tamper monitoring Script inventory and test order
Data Minimised access, retention and protected recovery Data and backup map
Response Owned alerts, provider contacts and containment route Tested incident card

This is a practical starting point, not a PCI DSS assessment, penetration test or legal compliance opinion. Confirm payment-security scope with your acquirer, payment provider and qualified adviser.

1. Protect every administrator account

Give staff and suppliers individual accounts, require strong multifactor authentication and assign the smallest role needed. Do not share one store-owner login across marketing, warehouse and development teams. Review active users, collaborators, API credentials and recovery methods on a schedule and whenever somebody changes role or leaves.

Reserve highly privileged accounts for administration. Everyday browsing and email increase exposure. Alert on unexpected owner, administrator, payment or app-permission changes.

2. Keep the platform and extensions supported

For hosted platforms, monitor platform notices and maintain themes, apps, custom code and store configuration. For WooCommerce, also maintain WordPress, hosting, PHP, plugins and server controls. Remove unused components rather than leaving disabled but vulnerable code in place.

Use a change route with backup or rollback, staging for higher-risk work and post-update checkout tests. Prioritise actively exploited vulnerabilities and internet-facing components. Record any deferred update with an owner, reason, mitigation and review date.

3. Reduce payment-data exposure

Use a supported payment integration that keeps sensitive card handling within the provider’s intended flow. Do not log, email or store full card data in ordinary application fields. Understand whether the customer is redirected, an iframe is used or payment components run directly on your page, because the design affects responsibilities and risk.

Shopify states that its platform is certified Level 1 PCI DSS compliant; merchants still need to operate their accounts, apps and business processes securely. WooCommerce’s security guidance distinguishes hosted and integrated payment gateways and notes that wider WordPress and hosting security still applies.

4. Inventory payment-page scripts

Marketing tags, chat widgets, consent tools, reviews and optimisation scripts can all reach sensitive pages. Maintain an inventory, business justification and owner. Restrict which scripts load on checkout, use platform controls such as content security policy where appropriate, and monitor unexpected changes.

PCI DSS 4.x includes specific e-commerce controls for authorising payment-page scripts, assuring integrity and detecting unauthorised changes. Use the current PCI Security Standards Council material and professional assessment to determine how requirements apply.

5. Secure apps, plugins and API integrations

For each component, record the supplier, purpose, permissions, data, support, update history and exit path. Avoid overlapping apps with broad access. Protect API keys and webhook secrets outside source code, restrict scopes, rotate exposed credentials and remove integrations that no longer serve a business process.

Validate webhook signatures where the provider supports them. Design retries and idempotency so a repeated event does not create duplicate orders, refunds or fulfilment.

6. Protect domains, DNS and TLS

Secure registrar and DNS accounts with strong authentication, named access and recovery details. Lock transfers where appropriate, monitor unexpected changes and alert before domain and certificate expiry. Keep previous DNS values and a rollback plan for deliberate changes.

Use ACA’s domain registration lookup and TLS certificate checker for point-in-time public evidence.

7. Minimise and control customer data

Collect the information genuinely needed for orders and service. Define access, purpose, retention and deletion across the commerce platform, CRM, email, analytics, fulfilment, support and exports. Avoid unrestricted spreadsheets of customer data and stale administrator exports.

Test role boundaries: warehouse staff may need address and product details without access to marketing exports or payment settings. Review data-sharing agreements and privacy wording with appropriate advisers.

8. Prevent fraud without blocking every customer

Configure the payment provider’s supported fraud controls and a manual review route for unusual orders. Train staff not to change delivery or refund details solely from an email request. Separate high-risk actions and confirm them through trusted account or contact data.

Monitor refund, discount, gift-card, account and fulfilment abuse as well as card fraud. Tune controls using evidence; aggressive rules can create customer harm and operational work.

9. Back up and practise recovery

Protect catalogue, content, orders, configuration, custom code and integration settings according to the platform model. Confirm what the platform retains, what an app protects and what must be exported or backed up separately. Test recovery without overwriting current orders.

10. Monitor the customer and operational journey

Use controlled synthetic or test journeys for storefront, checkout, order creation and notifications. Alert on payment or order anomalies, administrator changes, failed backups, integration queues and security events. Keep logs long enough for the incidents and disputes the business needs to investigate.

ACA’s e-commerce readiness check can surface public configuration signals, but it cannot inspect private accounts, code integrity or business processes.

11. Prepare an incident route

Record who can pause checkout, contact the payment and hosting providers, revoke sessions, rotate integrations, preserve evidence and communicate with customers. Keep provider identifiers and contacts outside the store. Test a scenario such as an unexpected administrator, altered checkout script or charge with no matching order.

Create the first-response contacts and decisions with ACA’s incident response card builder.

12. Review after every material change

New payment methods, apps, themes, markets, warehouses and agencies change the security boundary. Update the inventory, permissions, tests and recovery plan as part of delivery rather than waiting for an annual audit.

ACA provides e-commerce development and support across Shopify and WooCommerce, with security and ongoing responsibility defined in the service scope.

Frequently asked questions

Does using Shopify make a store automatically secure?

Shopify operates the hosted platform and checkout infrastructure, but merchants still control users, apps, domains, content, payment settings and business processes.

Does an SSL certificate make checkout safe?

No. TLS protects data in transit to the validated endpoint. It does not prove that administrator access, scripts, applications, integrations or stored data are safe.

How often should access be reviewed?

Review whenever people or suppliers change and on a regular schedule. High-privilege, payment and integration access deserves more frequent attention.

Leave a Reply

Your email address will not be published. Required fields are marked *