CubeCart now records every admin action with actor, IP and a diff, logs outbound HTTP calls, and deduplicates error rows so the log is actually readable.
Other sites displaying your images from your server costs you bandwidth and gives away your product photography. Blocking it is a checkbox, and breaking your own Google Images traffic is just as easy.
Almost nobody attacking your site has chosen you. That is good news, because the defences that stop automated attacks are unglamorous, mostly free, and take an afternoon.
CubeCart now hashes passwords with Argon2id and migrates existing accounts transparently on login. Why memory-hard hashing matters, and the hosting requirement that could mean you are not getting it.
WordPress sites are recruited into attacks on other people constantly, and the owner usually notices nothing beyond the site feeling slow. How to check your logs, and the two-minute fix.
When email goes missing, lands in spam, or looks forged, the answer is in the headers. Where to find them in every major mail client, and how to read the one line that answers most questions.
Nearly every CubeCart vulnerability fixed this year requires an existing admin session. Two-factor authentication is the control that breaks that chain, and it takes five minutes per account.
We first wrote about the end of passwords in 2013 and the candidates all failed. Passkeys are different, because the browser and operating system makers built it in themselves. How they work, and where they still fall short.
Your email account can reset almost every other account you own, which makes it the most valuable thing you have online. The checks that matter, including the one almost everyone misses.
Register a domain and the emails start: submit your site to hundreds of search engines, for a fee. It is a scam, the submission tools they claim to use no longer exist, and here is what to do instead.