The Complete Guide to Website Security and External Media

Questions:

  • Why did my external tool, widget, video, map, font, or image stop working?
  • How do I allow trusted third-party services in my shop?
  • Why is my shop always redirecting to HTTPS?
  • How do I enable camera, location, microphone, or payment permissions?
  • Why is my custom code snippet not running?
  • How do I authorize external connections and integrations?
  • How can I verify my shop's security grade?

Tags: SecurityManagement, ContentSecurityPolicy, ExternalWidgets, HTTPS, HSTS, PermissionPolicies, CustomCode, WebsiteSecurity, ThirdPartyIntegrations, SecurityConfiguration

Description:

This guide provides simple, easy-to-understand answers to common questions that shop owners may have after enabling the new security protection. No technical expertise is required. Each article explains what changes you may notice, why they occur, and the steps you can take to resolve them, including information you can share with your web agency if assistance is needed.

Important: Once the security feature is enabled, your shop only allows content from trusted sources. If an external tool, widget, or service stops working, it usually only needs to be added to the trusted source list. For security reasons, the protection should never be disabled to restore functionality.

Solution:

  1. Assess and Manage Core Security

    Understand why your old HTTP web address is unsecured and why your old website now always redirects to HTTPS. How to manage HSTS security settings and secure HTTPS connections: Learn to enforce secure connections across your entire site. Discover more

    How to check website security grade: Discover how to test and verify your site's current safety score. Discover more

    How to unblock and authorize external connections: Safely allow necessary third-party connections without risking your core security. Discover more

  2. Fix Broken Media and Display Issues

    Resolve common visual problems with unrendered media and external design assets. How to fix missing external fonts and images: Quickly restore visibility to your site's custom fonts and pictures. Discover more

    How to fix blank embedded videos and maps on your website: Learn exactly why your embeds appear blank and how to fix them. Discover more

  3. Enable Scripts, Widgets, and Permissions

    Properly authorize external tools and user device features for a seamless shopping experience. How to allow external tool widgets and scripts in website: Safely integrate powerful third-party tools into your pages. Discover more

    Why pasted custom code snippets do not run on your pages: Understand security blocks and learn how to run your code. Discover more

    How to enable device permissions like camera and location for shop features: Request and manage user device access securely and reliably. Discover more

Tips and Tricks:

Pro-Tips:

  • Trusted lists live in System →  System Configuration → Security Configuration .

  • Always approve only the specific provider your feature requires.

  • Save and reload the page after updating security settings.

  • Use your own hosted fonts and images whenever possible for better privacy and performance.

  • When testing HTTPS changes, use a private/incognito browser window.

  • Keep a list of approved external providers for easier maintenance and audits.

  • If you are unsure which trusted source to add, contact your web agency or support team.

Warnings:

  • Never disable security protection to make a feature work.
  • Only approve trusted and verified providers.
  • Avoid allowing unrestricted access or unknown scripts.
  • If something stops working, it usually just needs to be added to the trusted sources list.
  • Keep security settings enabled and approve only the services you actively use.

Subscribe to our newsletter

Stay informed at all times. We will gladly inform you about product news and offers.