Available for projects & agency overflow · Quick reply, from the person who does the work

Admin passwords and shared access

A password reused across three services, FTP access given to a provider and never revoked, an admin account created "just to help out" and forgotten: these are human flaws, not technical ones, and they’re among the easiest to fix.

Describe my issue Send a message

A different category of flaw

SQL injections or outdated modules are flaws in the code. The ones on this page aren’t: they come from how access is created, shared, and never withdrawn. A password reused across your inbox, your host and your CMS back office means a data leak on a completely unrelated service can hand someone access to your store. FTP credentials sent by email to a provider, never revoked after the job ends, stay valid indefinitely as long as nobody remembers to change them.

This type of flaw never shows up in a vulnerability report and never carries a CVE identifier. Yet it’s one of the most direct entry points, because it doesn’t require any technical flaw at all: the attacker simply logs in, with valid credentials.

A detail few merchants know about

PrestaShop offers, directly within its installer, an option to randomise the admin folder name instead of keeping the predictable /admin path. This isn’t a third-party extension to install separately: it’s a native, documented feature offered right from the CMS installation. It obviously doesn’t replace a strong password, but it takes your back office out of the path that bots test first and with no effort, filtering out a meaningful share of the most basic automated attempts.

Practical habits to put in place

  1. One unique password per service

    The CMS back-office password must never be the same as your inbox, host, or any other account. A password manager can generate and store a strong, distinct password for each one.

  2. Turn on two-factor authentication where it exists

    Many CMS platforms and hosts offer two-factor authentication, which still protects you even if a password alone leaks elsewhere. It’s worth enabling on the most sensitive accesses: back office, hosting, database.

  3. Revoke provider access once a job is done

    Any FTP, SSH or admin access given to an external provider should be disabled, or its password changed, as soon as the work is finished, not only once a problem is spotted.

  4. Apply the principle of least privilege

    A secondary account created for a specific need, such as order management or catalogue updates, shouldn’t have super-administrator rights it doesn’t actually need.

  5. Review active accounts regularly

    The list of admin accounts on a CMS grows over time, with no automatic clean-up. An account forgotten for two years is still a valid way in.

Related reading

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

constat
plateforme
depuis-quand (facultatif)
sauvegarde
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

How do I know if my password has already leaked elsewhere?
Some public services let you check whether an email address appears in a known data breach. If it does, every password reused on other accounts needs changing, not just the one for the affected service.
Should I change the admin password after every provider job?
Not necessarily if they used a dedicated, revocable account, but yes if they shared an existing one. The safest approach is always creating a named, temporary access for each external contributor.
Does two-factor authentication slow down my daily work?
Adding one extra step to logging in takes a few seconds, on an access you rarely use several times a day. The trade-off is heavily in its favour given what it prevents.
Is renaming the admin folder enough to secure my site?
No, it’s a complementary measure that reduces the most basic automated attempts, not a protection against an attacker specifically targeting your store or one who already holds valid credentials.
How many admin accounts should my store have?
The minimum needed for actual activity. Every extra account, especially with elevated rights, is one more door to protect and monitor over time.