All posts
August 2019·6 min read

WooCommerce security basics for Australian online stores

WooCommerce is the most widely used ecommerce platform in Australia. It's also a high-value target for attackers. Here's the security baseline every Australian store should have before accepting a single order.

Why WooCommerce stores are targeted

A compromised general WordPress site is useful to attackers for spam links and malware distribution. A compromised WooCommerce store has a higher-value target: customer names, addresses, email addresses, and potentially payment information. The data from a breached store can be sold, used for identity fraud, or leveraged in phishing attacks against your customers.

Under Australia's Notifiable Data Breaches scheme (in effect since February 2018), a breach of customer data also triggers mandatory notification obligations. The reputational cost of telling your customers their information was exposed is significant for an online store.

HTTPS is non-negotiable

Every WooCommerce store must run on HTTPS. Not just the checkout page — every page. Modern browsers flag HTTP sites as "Not Secure," which is a visible trust signal that directly affects conversion rates. More importantly, payment card data and customer personal information must be transmitted over an encrypted connection.

PCI DSS (the Payment Card Industry Data Security Standard) requires HTTPS for any page involved in card processing. If your store uses a payment gateway like Stripe, PayPal, or eWAY, they require HTTPS as a condition of their terms of service.

Use a payment gateway, don't store card data

WooCommerce supports payment gateways that handle card processing on their own servers — your store never sees the raw card number. Stripe, PayPal, Square, and Australian options like eWAY and Pin Payments all work this way.

Never configure WooCommerce to accept and store card numbers directly. Aside from the security liability, it triggers PCI DSS compliance requirements that are genuinely expensive for a small business to satisfy. Using a gateway eliminates that scope entirely.

Keep WooCommerce and its extensions updated

WooCommerce has a large ecosystem of extensions — payment gateways, shipping integrations, subscription tools, booking systems. Each one is a potential vulnerability. WooCommerce itself releases security patches regularly.

Update WooCommerce and its extensions promptly when new versions are available. This is more important than for a standard content site — WooCommerce extensions often handle sensitive data flows and have complex code with more attack surface.

Protect wp-admin and wp-login.php

Brute-force attacks targeting WordPress admin accounts are constant. For a WooCommerce store, a compromised administrator account means access to all customer data, all order history, and the ability to modify prices, redirect payments, or install malware.

At minimum: server-level rate limiting on wp-login.php, a strong unique admin password, and ideally two-factor authentication on all administrator accounts.

Manage admin access carefully

Give users the minimum access level they need. A staff member who only processes orders needs the "Shop Manager" role, not "Administrator." An Administrator account can install plugins, change site settings, and access all data — restrict that role to people who genuinely need it.

Remove accounts for people who no longer work with you immediately. Former employee credentials are a common entry point for compromises.

Backups for a WooCommerce store

For a standard content site, backups protect against data loss. For a WooCommerce store, they also protect against order data loss. If your site is compromised or has a technical failure, you need a recent backup to restore order history, customer accounts, and product configuration.

Daily backups stored offsite are the appropriate baseline for any store processing regular orders. The cost of a backup service is negligible compared to the cost of losing order data.


DownUnder WP is designed for content sites, blogs, and simple business WordPress. SSL is automatic, wp-admin protection is on by default, and daily backups are available as an add-on at $2/month. If you're running a simple WooCommerce store, get in touch to discuss whether our platform is the right fit.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.