Path: Settings > Security
This section provides essential configuration options to enhance system security and safeguard both admin and user accounts.
Maximum Login Failed Attempt
Defines the number of failed login attempts allowed. Once the limit is reached, the user account is blocked and must contact the administrator to regain access.
Site SSL Link
Set your secure HTTPS site link to ensure encrypted access across the platform.
Master PIN
If enabled, users are required to enter a master PIN when placing orders. This adds an extra layer of transaction protection.
User Can Reset API IP
Allows users to reset their API IP restriction. If an IP is set, only that IP can connect to the API. If left blank, the IP is auto-assigned on first sync.
User Can Generate Temporary Password
Grants users the ability to generate a temporary password, valid for 2 hours. After expiration, it becomes inactive automatically.
User Password Expired On
Sets a password expiration period. After the defined number of days, the system will prompt the user to update their password.
Blocked Account on Country Mismatch
Automatically blocks user accounts if a login is detected from a country different than their previous login location.
Required Captcha on Login
Enables CAPTCHA verification on the login page to protect against brute force attacks and spam.
Send Email on Country Mismatch
When a login is detected from a different country, an email verification is sent to the user for security confirmation.
Admin Email Notification on Blocked Account
Sends an email alert to the administrator whenever a user account is automatically blocked.
Admin Allowed IP
Restricts access to the admin panel to only specified IP addresses for tighter control and security.
Password Security
Defines password strength policy by setting a required percentage score for user password input during registration or password update.
Automatic Security Check
Runs automated script scans via cron job. If any vulnerable or suspicious script is found, the admin is notified by email. (Cron setup required if enabled.)
Encryption Key
Allows the admin to change the encryption key used to secure user passwords and sensitive data.
Important: Changing the encryption key will invalidate all existing passwords. You must resend updated passwords to users via the “Update Multiple Accounts” tool.