Documentation
Getting Started
- Introduction
- Setup
- General Settings
- WooCommerce
- Tools
- Analytics Reports
- Dashboard
- License
- Generator
- Activations
- Applications
- Installed On
- API Logs
- WooCommerce Products
- Customer License Manager Flow
Integrations
For Developer
Security
Enhancing Security for License Manager for WooCommerce
Folder Protection Details
When the plugin is activated, it automatically creates a .htaccess file inside the following directory:
wp-content/uploads/lmfwc-files
This file prevents direct browser access to the folder, helping keep your cryptographic secrets secure and private.
Important Note
If your server is running NGINX instead of Apache, the .htaccess file will not work because NGINX ignores .htaccess rules.
In this case, you should manually configure an NGINX directive to properly secure the directory.
Recommended: Move Cryptographic Secrets to wp-config.php
For improved security and better performance, it is highly recommended to move your cryptographic secrets to the wp-config.php file. This helps reduce unnecessary server requests and provides stronger protection for sensitive data.
Steps to Move Secrets to wp-config.php
- Locate the wp-config.php File
This file is located in the root directory of your WordPress installation. - Add the Following Code
define(‘LMFWC_PLUGIN_SECRET’, ‘secret.txt’);
define(‘LMFWC_PLUGIN_DEFUSE’, ‘defuse.txt’);
Replace secret.txt and defuse.txt with the actual contents of those files.
- Create a Backup
Store secure backups of both secret.txt and defuse.txt before proceeding. - Delete the lmfwc-files Directory
Once you have confirmed that the secrets were successfully added to wp-config.php, delete the following directory: wp-content/uploads/lmfwc-files