Purpose of the article
After a cleanup intervention (removal or quarantine of files, restoration, fixes), the Securantis license is not always immediately mandatory. However, subscribing to the license enables continuous protections (conservative WAF, integrity scanner, upload scans, quarantine management, centralized alerts, 2FA/CAPTCHA) and allows monitoring the site to detect any reinfection or suspicious behavior. This article helps you decide, activate and configure the license after a cleanup, specifying platform-specific details.
Prerequisites
- Administrator access to the Securantis panel (client area) and to the CMS back office.
- Cleanup intervention completed: signed cleanup report (or client validation) indicating actions performed and files placed in quarantine. Note that the final deletion of files in quarantine must remain a human decision.
- Recent and tested backup (files + database) made before any new modification.
- For paid interventions, the necessary accesses are provided only after payment via the secure client area.
- Never transmit passwords by email or chat.
Recommended steps (step-by-step procedure)
-
Read and validate the cleanup report
- Verify the list of files marked as suspicious, in quarantine or corrected.
- Explicitly validate the chosen remediation method (restore, delete or keep in quarantine).
-
Decide the desired level of protection
- Monitoring only: scheduled scans and alerts, without automatic blocking by the WAF.
- Active protection: WAF in observation then progressive blocking, real-time scans and quarantines available.
-
Subscribe/activate the Securantis license
- From the client area, choose the appropriate plan (1 license per site). After payment, link the license to the site domain following the provided procedure.
- If you prefer to wait, you can activate later; however, note that without a license you have no centralized protection or private updates.
-
Initial cautious configuration
- WAF mode: start in observation (learning/monitor) for 24–72 hours to detect false positives.
- Scans: enable a full integrity scan then set daily or real-time scans according to server load.
- PHP uploads: if your site does not require executing PHP from upload folders, enable upload scanning to block/alert on executable files.
- 2FA & CAPTCHA: enable first for administrator accounts.
-
Post-activation verification
- Monitor the Securantis dashboard: firewall events, login attempts, files in quarantine.
- Review any new detection before deleting anything. Quarantine preserves evidence while awaiting your decision.
Platform-specific behaviors
WordPress & WooCommerce
- Specifics: protections for wp-login / administration URL, WooCommerce-specific rules (checkout, webhooks).
- Recommendations: enable login protection, 2FA for all administrator accounts, CAPTCHA on critical forms (login, registration, checkout), start the WAF in observation to avoid blocking third-party plugins.
- Integrity scans: enable core WordPress checks if your installation is standard; if you use deep modifications or many proprietary plugins, prepare a baseline (allowed list) to reduce false positives.
PrestaShop 1.7 to 9
- Specifics: back office and front controllers specific to PrestaShop, compatibility with e-commerce modules.
- Recommendations: protect back-office access with 2FA if available, limit aggressive WAF rules regarding checkout and API URLs, enable scheduled scans on upload folders and modules.
- Tests: verify the payment flow and third-party modules in observation mode before switching to full blocking.
Expected outcome
- The site remains available to legitimate users; automated attacks and known attempts are detected and/or blocked according to the chosen mode.
- Suspicious files are isolated in quarantine and reported in the security report — no automatic deletion is performed without your decision.
- You receive centralized alerts (email / dashboard) in case of a critical event.
Cautious settings and best practices
- Start in observation: 24–72 hours minimum to reduce false positives.
- Enable 2FA for all privileged accounts and keep at least one backup account to recover access.
- Keep a recent backup before applying strong blocking rules.
- Do not immediately delete files in quarantine: analyze them, restore if necessary from a tested backup.
- Do not enable very restrictive WAF rules during periods of high commercial activity (sales, campaigns).
Common mistakes and points of attention
- False positives on proprietary plugins or modules: resolve by adding to the allowlist after verification.
- Blocking of APIs or webhooks: occurs if the WAF blocks specific inbound or outbound requests; place the IP/URL in the temporary allowlist then adjust the rule.
- Increased server load after enabling real-time scans: reduce frequency or switch to incremental scans if available.
- Loss of administrative access after changing connection settings: maintain an alternative access channel (SSH, FTP or another administrator account) and test 2FA before enforcing it.
Step-by-step troubleshooting
-
A legitimate service is blocked
- Temporarily set the WAF to observation mode.
- List the rules that blocked the event via the dashboard and add a targeted exception (IP, URL, signature) after verification.
-
False positives from the integrity scanner
- Examine the proposed diff, restore from backup if necessary, or add the path/file to the allowlist.
-
Too many notifications or non-critical alerts
- Adjust alert sensitivity and scan frequency; group non-urgent notifications into daily reports.
Legal precautions and access security
- We will never request passwords by email/chat. Use the secure client area to transmit accesses if a paid intervention is planned — only after payment.
- The permanent deletion of files marked as malicious must be validated by an authorized person: Securantis keeps the quarantine as possible evidence.
- Store your backups off the production server if possible, and document any restoration actions.
When to contact Securantis support
Contact support if:
- You observe a spike of repeated attacks despite protections being active.
- A critical component (payment, API, webhook) is blocked and you do not know which rule to adjust.
- You need assisted intervention (paid package) for deep cleanup, forensics or restoration: accesses will be requested via the secure client area after confirmation and payment.
Quick summary and final recommendations
After a cleanup, the Securantis license is strongly recommended to maintain active monitoring and to have a conservative WAF, integrity scanner and managed quarantines. Start in observation, enable 2FA for administrator accounts, manually validate any quarantine deletions, and contact support for critical blocks or a deep intervention. These steps reduce the risk of reinfection and keep human control over quarantine and deletion decisions.