WordPress
Admin Gateway plugin
Protects wp-login.php, /wp-admin, authenticated REST/admin-ajax/admin-post, XML-RPC and application passwords. Uses local JWT verification, JWKS, audit, revocation and emergency access.
Status: Available for pilot
CMS Admin Gateway
BusinessProxy closes CMS login and admin paths from direct traffic and opens them only after a verified, short-lived gateway session. Bots and password spraying stop before the CMS login form, while admins still use their normal CMS accounts.
Modules are provided through the BusinessProxy account downloads area after registration or access approval.
Admin surfaces
Ready modules and reviewed app paths keep the same product boundary: BusinessProxy protects the admin entry path, while the application remains responsible for its own users, roles and business logic.
WordPress
Protects wp-login.php, /wp-admin, authenticated REST/admin-ajax/admin-post, XML-RPC and application passwords. Uses local JWT verification, JWKS, audit, revocation and emergency access.
Status: Available for pilot
Drupal / Magento
For Drupal, Magento / Adobe Commerce and similar self-hosted admin areas, start with Private App Access and connector review. Dedicated modules require a separate product rollout and are not ready-made packages today.
Status: Reviewed per deployment
SAP / ERP portals
For SAP, ERP and corporate admin portals, BusinessProxy can review the web app as a protected internal application through a connector, session policy and audit trail. This is not represented as a one-click SAP plugin.
Status: Enterprise review
Coverage
Use this table to compare the access path, protected admin surfaces, supported site exposure modes and readiness status.
| CMS | Access path | Admin surfaces | Site exposure | Status |
|---|---|---|---|---|
| WordPress | Admin Gateway plugin | wp-login, wp-admin, REST, XML-RPC | Public site / Connector | Available for pilot |
| Drupal / Magento | Private App review | admin paths, commerce admin, APIs | Public site / Connector | Reviewed per deployment |
| SAP / ERP portals | Connector-backed app access | ERP web portal, admin console, partner portal | Public site / Connector | Enterprise review |
Connection flow
Step 1
The module denies direct access to admin surfaces by default and waits for a signed BusinessProxy gateway token.
Step 2
Bind the site to a workspace, private app and policy. The site can be reachable publicly or only through an outbound connector.
Step 3
Users pass BusinessProxy access checks first; every allow, deny and revocation event can be recorded in the workspace audit log.
User access
BusinessProxy does not make the browser extension a universal prerequisite for every CMS deployment. The launch path depends on the protected app policy and the browser controls you enable.
Portal launch
A user signs in to BusinessProxy, passes the configured access policy, and opens the protected CMS app from the portal. For portal-capable aliases, no browser extension is required.
Browser extension
Use the extension when policy requires extension launch, managed browser routing, watermarking or copy/print/screenshot deterrents.
Chrome Web Store · Firefox Add-ons · Edge, Opera and other packages
Site exposure
A hosted CMS can be protected at its public origin. A private CMS can stay inside the network: the connector opens outbound-only access to the internal address while users open a BusinessProxy alias.
Billing recovery
The exact grace period, temporary access window and speed limits are returned by the BusinessProxy platform and shown in the product where available. The CMS modules follow those platform values instead of hardcoding dates locally.
Active
Users open the CMS according to the configured app policy: portal, extension launch, connector route and audit behavior remain unchanged.
Grace
When the platform returns CMS soft access, the protected CMS keeps working for the returned period and limits. Other protected apps may remain blocked until billing is restored.
Recovery
During recovery or blocked billing states, CMS modules avoid a local lockout: if Enforce is active, they use Monitor so the site owner can reach the administration area and access events continue to be logged.
Internal sites
For ordinary hosted CMS, the module can validate gateway sessions on a public origin. For internal sites, BusinessProxy Connector keeps the site private: users enter through the gateway, and the connector opens outbound-only access to the protected origin.
Data leakage deterrence
Per protected app, you can add a dynamic watermark with user/session attribution and controls that discourage copying, printing and screenshots on admin pages.
Scope
Register to get access to connector and CMS module downloads, or send us the target CMS and hosting model if you want help with the first installation.