CMS Admin Gateway

Protect CMS, commerce and ERP admin areas behind a managed session.

BusinessProxy closes CMS login and admin paths from direct traffic and opens them only after a verified, short-lived gateway session. Bots and password spraying stop before the CMS login form, while admins still use their normal CMS accounts.

Modules are provided through the BusinessProxy account downloads area after registration or access approval.

Admin surfaces

Start with a ready module or a reviewed app path

Ready modules and reviewed app paths keep the same product boundary: BusinessProxy protects the admin entry path, while the application remains responsible for its own users, roles and business logic.

WordPress

Admin Gateway plugin

Protects wp-login.php, /wp-admin, authenticated REST/admin-ajax/admin-post, XML-RPC and application passwords. Uses local JWT verification, JWKS, audit, revocation and emergency access.

Status: Available for pilot

Drupal / Magento

Private App review

For Drupal, Magento / Adobe Commerce and similar self-hosted admin areas, start with Private App Access and connector review. Dedicated modules require a separate product rollout and are not ready-made packages today.

Status: Reviewed per deployment

SAP / ERP portals

Connector-backed app access

For SAP, ERP and corporate admin portals, BusinessProxy can review the web app as a protected internal application through a connector, session policy and audit trail. This is not represented as a one-click SAP plugin.

Status: Enterprise review

Coverage

What each module protects

Use this table to compare the access path, protected admin surfaces, supported site exposure modes and readiness status.

CMSAccess pathAdmin surfacesSite exposureStatus
WordPressAdmin Gateway pluginwp-login, wp-admin, REST, XML-RPCPublic site / ConnectorAvailable for pilot
Drupal / MagentoPrivate App reviewadmin paths, commerce admin, APIsPublic site / ConnectorReviewed per deployment
SAP / ERP portalsConnector-backed app accessERP web portal, admin console, partner portalPublic site / ConnectorEnterprise review

Connection flow

From module install to protected admin access

Step 1

Install the CMS module

The module denies direct access to admin surfaces by default and waits for a signed BusinessProxy gateway token.

Step 2

Connect the site to BusinessProxy

Bind the site to a workspace, private app and policy. The site can be reachable publicly or only through an outbound connector.

Step 3

Open admin pages through a managed session

Users pass BusinessProxy access checks first; every allow, deny and revocation event can be recorded in the workspace audit log.

User access

Portal first, browser extension when policy needs it

BusinessProxy does not make the browser extension a universal prerequisite for every CMS deployment. The launch path depends on the protected app policy and the browser controls you enable.

Portal launch

Users open the CMS from BusinessProxy

A user signs in to BusinessProxy, passes the configured access policy, and opens the protected CMS app from the portal. For portal-capable aliases, no browser extension is required.

Site exposure

Public origin or internal connector

A hosted CMS can be protected at its public origin. A private CMS can stay inside the network: the connector opens outbound-only access to the internal address while users open a BusinessProxy alias.

Billing recovery

CMS protection should not lock the owner out of the site

The exact grace period, temporary access window and speed limits are returned by the BusinessProxy platform and shown in the product where available. The CMS modules follow those platform values instead of hardcoding dates locally.

Active

Normal access policy applies

Users open the CMS according to the configured app policy: portal, extension launch, connector route and audit behavior remain unchanged.

Grace

CMS soft access can continue

When the platform returns CMS soft access, the protected CMS keeps working for the returned period and limits. Other protected apps may remain blocked until billing is restored.

Recovery

Local plugin falls back to Monitor when needed

During recovery or blocked billing states, CMS modules avoid a local lockout: if Enforce is active, they use Monitor so the site owner can reach the administration area and access events continue to be logged.

Internal sites

Works with public sites and connector-only sites

For ordinary hosted CMS, the module can validate gateway sessions on a public origin. For internal sites, BusinessProxy Connector keeps the site private: users enter through the gateway, and the connector opens outbound-only access to the protected origin.

Data leakage deterrence

Watermark and copy/print/screenshot deterrents

Per protected app, you can add a dynamic watermark with user/session attribution and controls that discourage copying, printing and screenshots on admin pages.

Scope

Where CMS Admin Gateway applies

  • Access control for CMS admin areas, not a WAF, antivirus or DDoS platform.
  • The CMS still owns authentication, roles and application permissions after the gateway lets a request through.
  • Screenshot and copy deterrents reduce casual leakage risk; watermarking adds attribution but does not make screen capture impossible.

Ready to protect a CMS admin area?

Register to get access to connector and CMS module downloads, or send us the target CMS and hosting model if you want help with the first installation.