When an Indian business owner installs Razorpay on their website and sees the payment flow working, there is a reasonable assumption that the security is handled. Razorpay's role is significant — but it does not cover everything. The website itself remains your responsibility, and most Indian SMB websites accepting payments have identifiable security gaps that leave the business, and its customers, exposed to real risk. Here is a practical security checklist for business owners, not IT specialists.
The Security Basics Every Payment-Accepting Website Must Have
Valid HTTPS with a current SSL certificate. Check the padlock in your browser's address bar. If your site is still running on HTTP, any data transmitted between your customer's browser and your server is unencrypted. Free SSL certificates from Let's Encrypt are available through every reputable hosting provider in India — there is no reason for a business website to be without HTTPS in 2026. An expired SSL certificate is equally problematic — browsers display a prominent warning that most users will not bypass.
Up-to-date CMS, plugins, and themes. If your website is on WordPress, WooCommerce, or any CMS-based platform, outdated plugins are the single most common attack vector in India. Automated scanning tools continuously probe WordPress sites for known vulnerable plugin versions. Log in to your WordPress dashboard and check Updates — if you have unread update notifications for themes or plugins, update them now. A single vulnerable plugin can give an attacker complete control of your website and access to your customer data.
Strong, unique hosting credentials. Your cPanel password, your WordPress admin password, and your hosting account password must all be unique and strong (minimum 12 characters, a mix of letters, numbers, and symbols). A significant percentage of Indian SMB website compromises are the result of password reuse — the same credentials used for cPanel, email, and the CMS, meaning a breach of one compromises all three. Enable two-factor authentication on your hosting control panel wherever available.
Regular automated backups. If your hosting provider does not include daily automated backups, enable a plugin like UpdraftPlus (WordPress) or configure your hosting panel's backup schedule. Store backups both on the server and in a separate location (Google Drive, Dropbox, or an S3 bucket). A ransomware attack or a hosting failure without backups means permanent loss of your entire website and customer data.
Payment System-Specific Security for Razorpay and UPI
Using Razorpay's standard hosted checkout — where the payment page is served by Razorpay, not your website — is the right choice for most Indian SMBs. This means card numbers never touch your server; Razorpay's PCI DSS-compliant infrastructure handles the payment collection. Your responsibility is to ensure the integration itself is not exploited.
Verify webhook signatures. If your website uses Razorpay webhooks to confirm payment status, always verify the webhook signature using Razorpay's provided signature verification code. A payment confirmation that you accept without signature verification can be spoofed — an attacker could send a fake "payment successful" webhook to your server without actually completing a payment. This is a documented attack pattern against Indian e-commerce sites.
Do not log payment data. Ensure your website's error logs, analytics plugins, or debugging tools are not capturing customer name, card BIN, or UPI IDs in log files. Many WordPress debug logs accidentally capture this data when payment forms encounter errors. Disable WordPress debug mode (WP_DEBUG) on production sites.
Use Razorpay's payment link or hosted page for one-off transactions. For service businesses that send occasional payment requests to clients, Razorpay Payment Links provide a secure hosted payment experience without the need to integrate a full checkout on your website. This is the simplest and most secure option for consultants, service providers, and freelancers in Kerala collecting client payments online.
Security Headers That Protect Your Customers
HTTP security headers are server-level settings that instruct browsers to apply additional security policies when loading your website. Most Indian SMB websites are missing several of these. Check yours using securityheaders.com (enter your domain and the tool grades your current headers).
Content-Security-Policy (CSP): Controls which external scripts and resources your website can load. Prevents cross-site scripting (XSS) attacks where malicious scripts injected into your site capture customer data.
X-Frame-Options: Prevents your website from being embedded in an iframe on another site — a technique used in clickjacking attacks where users think they are interacting with your page but are actually clicking on invisible malicious elements.
Strict-Transport-Security (HSTS): Instructs browsers to always connect to your site over HTTPS, preventing protocol downgrade attacks.
These headers can be added to your hosting's .htaccess file (Apache servers) or through your hosting control panel's configuration. A web developer can implement all three in under an hour.
How to Check If Your Site Has Already Been Compromised
Many Indian business websites are compromised for weeks or months before the owner notices. Signs include: your website is loading slowly for some visitors; Google Search Console is showing a "Security Issues" alert; your site appears in Google search results with spam phrases ("buy cheap medicines," "online casino") in the description; or customers are being redirected to unrelated sites on mobile.
Check Google Search Console's Security Issues section (free, requires verification). Run a free scan at Sucuri SiteCheck. Open your site in a private browser window on a mobile device — attackers frequently only show malicious redirects to mobile users who are not logged in, while the site appears normal to a logged-in admin on desktop. If you have been compromised, restoring from a clean backup is faster and more reliable than trying to manually clean an infected site.
Frequently Asked Questions
Does using Razorpay mean my website is PCI DSS compliant?
Using Razorpay's hosted checkout means Razorpay bears the PCI DSS burden for payment collection — card data never touches your server. But your site still must be HTTPS, not log card data, and be free of redirection attacks. If you use Razorpay's API to collect card data directly on your site, your PCI DSS obligations are significantly higher.
What are the most common website security vulnerabilities for Indian small businesses?
Outdated WordPress plugins (biggest attack vector), weak or shared hosting passwords, missing or expired HTTPS, no Web Application Firewall, no regular backups, and default WordPress admin usernames. Most Indian SMB breaches exploit one of these six vectors — all are preventable.
How do I check if my business website has been hacked?
Check Google Search Console's Security Issues report. Run a free scan at Sucuri SiteCheck. Open your site in a private browser on mobile — many attackers only redirect mobile visitors who are not logged in. Also search Google for your business name and check whether your page descriptions show spam content you did not write.
How much does a website security audit cost in India?
Basic vulnerability scan and report: ₹5,000–₹15,000 from a freelance security consultant. Comprehensive penetration test: ₹25,000–₹1,00,000 depending on scope. For any business accepting online payments, an annual basic scan is a worthwhile preventive expense — the cost of a breach (customer notification, processor penalties, reputational damage) vastly exceeds it.