Security baseline
- Force HTTPS and secure cookies.
- Use unique administrator accounts and multifactor authentication.
- Apply least-privilege roles and review access regularly.
- Keep PHP, the database, web server, and WBAMS dependencies supported.
- Protect
settings.php, the encryption hash, backups, logs, and private storage. - Run scheduler tasks as a constrained service account.
- Monitor failed sign-ins, control activity, gateway callbacks, email, and scheduler completion.
Sessions
PHP session storage must be writable only by the appropriate runtime users. Keep the administrator's user agent, password hash, encryption hash, and IP-check policy stable within a session. Unexpected session invalidation should be investigated rather than hidden with compatibility code.
Reverse proxies
Trust forwarded headers only from configured proxy addresses. Confirm the application sees the correct HTTPS scheme, host, and client IP before enabling IP-dependent security checks.
Incident response
- Preserve logs and record timestamps.
- Contain affected credentials, endpoints, or integrations.
- Determine impacted customers, records, money movement, and files.
- Restore trusted code/data only after identifying the cause.
- Rotate credentials and verify every connected system.
- Document corrective controls and test them.