{"id":3523,"date":"2026-09-09T17:34:45","date_gmt":"2026-09-09T17:34:45","guid":{"rendered":"https:\/\/acatechsolutions.co.uk\/blog\/ecommerce-security-checklist\/"},"modified":"2026-09-09T21:02:46","modified_gmt":"2026-09-09T21:02:46","slug":"ecommerce-security-checklist","status":"publish","type":"post","link":"https:\/\/acatechsolutions.co.uk\/blog\/ecommerce-security-checklist\/","title":{"rendered":"E-commerce Security Checklist: Checkout, Payments and Admin Access"},"content":{"rendered":"<p><strong>An e-commerce security checklist must protect the administrator route, storefront code, payment journey, customer data and operational integrations together.<\/strong> A valid certificate and a reputable payment provider are important, but they do not prevent stolen admin sessions, vulnerable extensions, malicious scripts or unsafe fulfilment access.<\/p>\n<p><em>Reviewed: 9 September 2026<\/em><\/p>\n<h2>E-commerce security checklist at a glance<\/h2>\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Area<\/th>\n<th scope=\"col\">Minimum check<\/th>\n<th scope=\"col\">Evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Admin access<\/td>\n<td>Named users, MFA, least privilege and prompt offboarding<\/td>\n<td>User and role review<\/td>\n<\/tr>\n<tr>\n<td>Platform<\/td>\n<td>Supported software, controlled updates and minimal apps<\/td>\n<td>Version and change record<\/td>\n<\/tr>\n<tr>\n<td>Checkout<\/td>\n<td>Authorised scripts, trusted payment flow and tamper monitoring<\/td>\n<td>Script inventory and test order<\/td>\n<\/tr>\n<tr>\n<td>Data<\/td>\n<td>Minimised access, retention and protected recovery<\/td>\n<td>Data and backup map<\/td>\n<\/tr>\n<tr>\n<td>Response<\/td>\n<td>Owned alerts, provider contacts and containment route<\/td>\n<td>Tested incident card<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This is a practical starting point, not a PCI DSS assessment, penetration test or legal compliance opinion. Confirm payment-security scope with your acquirer, payment provider and qualified adviser.<\/p>\n<h2>1. Protect every administrator account<\/h2>\n<p>Give staff and suppliers individual accounts, require strong multifactor authentication and assign the smallest role needed. Do not share one store-owner login across marketing, warehouse and development teams. Review active users, collaborators, API credentials and recovery methods on a schedule and whenever somebody changes role or leaves.<\/p>\n<p>Reserve highly privileged accounts for administration. Everyday browsing and email increase exposure. Alert on unexpected owner, administrator, payment or app-permission changes.<\/p>\n<h2>2. Keep the platform and extensions supported<\/h2>\n<p>For hosted platforms, monitor platform notices and maintain themes, apps, custom code and store configuration. For WooCommerce, also maintain WordPress, hosting, PHP, plugins and server controls. Remove unused components rather than leaving disabled but vulnerable code in place.<\/p>\n<p>Use a change route with backup or rollback, staging for higher-risk work and post-update checkout tests. Prioritise actively exploited vulnerabilities and internet-facing components. Record any deferred update with an owner, reason, mitigation and review date.<\/p>\n<h2>3. Reduce payment-data exposure<\/h2>\n<p>Use a supported payment integration that keeps sensitive card handling within the provider\u2019s intended flow. Do not log, email or store full card data in ordinary application fields. Understand whether the customer is redirected, an iframe is used or payment components run directly on your page, because the design affects responsibilities and risk.<\/p>\n<p>Shopify states that its platform is certified Level 1 PCI DSS compliant; merchants still need to operate their accounts, apps and business processes securely. WooCommerce\u2019s <a href=\"https:\/\/woocommerce.com\/document\/woocommerce-security-faq\/\" target=\"_blank\" rel=\"noopener\">security guidance<\/a> distinguishes hosted and integrated payment gateways and notes that wider WordPress and hosting security still applies.<\/p>\n<h2>4. Inventory payment-page scripts<\/h2>\n<p>Marketing tags, chat widgets, consent tools, reviews and optimisation scripts can all reach sensitive pages. Maintain an inventory, business justification and owner. Restrict which scripts load on checkout, use platform controls such as content security policy where appropriate, and monitor unexpected changes.<\/p>\n<p>PCI DSS 4.x includes specific e-commerce controls for authorising payment-page scripts, assuring integrity and detecting unauthorised changes. Use the current <a href=\"https:\/\/www.pcisecuritystandards.org\/standards\/pci-dss\/\" target=\"_blank\" rel=\"noopener\">PCI Security Standards Council material<\/a> and professional assessment to determine how requirements apply.<\/p>\n<h2>5. Secure apps, plugins and API integrations<\/h2>\n<p>For each component, record the supplier, purpose, permissions, data, support, update history and exit path. Avoid overlapping apps with broad access. Protect API keys and webhook secrets outside source code, restrict scopes, rotate exposed credentials and remove integrations that no longer serve a business process.<\/p>\n<p>Validate webhook signatures where the provider supports them. Design retries and idempotency so a repeated event does not create duplicate orders, refunds or fulfilment.<\/p>\n<h2>6. Protect domains, DNS and TLS<\/h2>\n<p>Secure registrar and DNS accounts with strong authentication, named access and recovery details. Lock transfers where appropriate, monitor unexpected changes and alert before domain and certificate expiry. Keep previous DNS values and a rollback plan for deliberate changes.<\/p>\n<p>Use ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/domain-registration-lookup\/\">domain registration lookup<\/a> and <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/ssl-tls-certificate-checker\/\">TLS certificate checker<\/a> for point-in-time public evidence.<\/p>\n<h2>7. Minimise and control customer data<\/h2>\n<p>Collect the information genuinely needed for orders and service. Define access, purpose, retention and deletion across the commerce platform, CRM, email, analytics, fulfilment, support and exports. Avoid unrestricted spreadsheets of customer data and stale administrator exports.<\/p>\n<p>Test role boundaries: warehouse staff may need address and product details without access to marketing exports or payment settings. Review data-sharing agreements and privacy wording with appropriate advisers.<\/p>\n<h2>8. Prevent fraud without blocking every customer<\/h2>\n<p>Configure the payment provider\u2019s supported fraud controls and a manual review route for unusual orders. Train staff not to change delivery or refund details solely from an email request. Separate high-risk actions and confirm them through trusted account or contact data.<\/p>\n<p>Monitor refund, discount, gift-card, account and fulfilment abuse as well as card fraud. Tune controls using evidence; aggressive rules can create customer harm and operational work.<\/p>\n<h2>9. Back up and practise recovery<\/h2>\n<p>Protect catalogue, content, orders, configuration, custom code and integration settings according to the platform model. Confirm what the platform retains, what an app protects and what must be exported or backed up separately. Test recovery without overwriting current orders.<\/p>\n<h2>10. Monitor the customer and operational journey<\/h2>\n<p>Use controlled synthetic or test journeys for storefront, checkout, order creation and notifications. Alert on payment or order anomalies, administrator changes, failed backups, integration queues and security events. Keep logs long enough for the incidents and disputes the business needs to investigate.<\/p>\n<p>ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/ecommerce-readiness-check\/\">e-commerce readiness check<\/a> can surface public configuration signals, but it cannot inspect private accounts, code integrity or business processes.<\/p>\n<h2>11. Prepare an incident route<\/h2>\n<p>Record who can pause checkout, contact the payment and hosting providers, revoke sessions, rotate integrations, preserve evidence and communicate with customers. Keep provider identifiers and contacts outside the store. Test a scenario such as an unexpected administrator, altered checkout script or charge with no matching order.<\/p>\n<p>Create the first-response contacts and decisions with ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/incident-response-card-builder\/\">incident response card builder<\/a>.<\/p>\n<h2>12. Review after every material change<\/h2>\n<p>New payment methods, apps, themes, markets, warehouses and agencies change the security boundary. Update the inventory, permissions, tests and recovery plan as part of delivery rather than waiting for an annual audit.<\/p>\n<p>ACA provides <a href=\"https:\/\/acatechsolutions.co.uk\/ecommerce\/\">e-commerce development and support<\/a> across Shopify and WooCommerce, with security and ongoing responsibility defined in the service scope.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Does using Shopify make a store automatically secure?<\/h3>\n<p>Shopify operates the hosted platform and checkout infrastructure, but merchants still control users, apps, domains, content, payment settings and business processes.<\/p>\n<h3>Does an SSL certificate make checkout safe?<\/h3>\n<p>No. TLS protects data in transit to the validated endpoint. It does not prove that administrator access, scripts, applications, integrations or stored data are safe.<\/p>\n<h3>How often should access be reviewed?<\/h3>\n<p>Review whenever people or suppliers change and on a regular schedule. High-privilege, payment and integration access deserves more frequent attention.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Use this e-commerce security checklist to review admin access, platform updates, payment-page scripts, apps, customer data, recovery and incident response.<\/p>\n","protected":false},"author":1,"featured_media":3524,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,17],"tags":[],"class_list":["post-3523","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber_hygiene","category-information_technology"],"blocksy_meta":{"page_structure_type":"type-1","styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"_links":{"self":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=3523"}],"version-history":[{"count":1,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3523\/revisions"}],"predecessor-version":[{"id":3536,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3523\/revisions\/3536"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media\/3524"}],"wp:attachment":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=3523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=3523"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=3523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}