Report security issues to info@makepay.io.
- Keep MakePay key secrets and webhook secrets in Shopware system configuration or a secret-backed config provider.
- Verify MakePay webhook signatures before changing Shopware transaction states.
- Do not expose MakePay partner keys to storefront JavaScript.
- Rotate MakePay credentials if Shopware admin or environment secrets are exposed.