Policy
Security
Security guidance for imported WordPress sites and CanaryWP testing environments.
Last updated August 3, 2026
Protect production data
Imported archives can contain real users, orders, credentials, tokens, API keys, private media, and operational history. Treat every import as sensitive until verified otherwise.
Recommended precautions
- Rotate production credentials that appear in test copies.
- Disable or sandbox outbound email, webhooks, payment gateways, and automation plugins.
- Review wp-config.php, SMTP settings, cron events, and plugin secrets after import.
- Restrict workspace access to users who need the data.
Testing URLs
Do not use CanaryWP testing URLs for production traffic. Testing environments are designed for validation and can be stopped, rebuilt, or deleted.
Report a security issue
Send the affected URL, workspace, instance name, timeline, impact, and reproduction steps through the CanaryWP support channel.