Forma

Forma won't shut up about your default password

A non-dismissible red bar now stays on every admin screen until you change the default password or fix a failing hosting check, and uploads/ gets an automatic deny-PHP .htaccess.

Every CMS ships with a default admin password on first boot. Almost none of them keep bothering you about it after setup day. That's the gap — not the existence of a weak default, but how quickly the reminder to fix it disappears. Forma now keeps a red bar on every single admin screen until the actual problem is actually fixed.

What triggers the bar

Two categories, both loud, both non-dismissible:

  • The password is still admin / admin. Forma checks this directly against the stored hash — not a flag you can accidentally leave checked, an actual password_verify() against the string admin. Change the password and the check goes away on its own.
  • A hosting check is failing. World-writable database/, uploads/, feeds/, or fallback/, display_errors on in production, a leftover install.php still sitting in the site root, a missing .htaccess. Anything Settings → Server would flag as a hard fail also surfaces here, with a one-click link straight to the fix.

Both checks run locally — no outbound request, nothing that slows down a page load waiting on a remote ping. The bar reads current state on every admin request and disappears the moment the underlying thing is actually true, not the moment you click something that says it is.

Uploads get a second lock

Permission checks catch a folder that's writable when it shouldn't be. They don't catch what happens after someone gets a file into it. So Forma also drops a deny-PHP .htaccess into uploads/ automatically:

# Generated by Forma — uploads must never execute PHP
<FilesMatch "\.(?i:php[0-9]?|phtml|phar)$">
    Require all denied
</FilesMatch>

If a .php file ever ends up in uploads/ — a bad file that slipped past validation, a leftover from migrating an old site, anything — Apache refuses to execute it. It's just a static file at that point, dead on arrival. This is the kind of thing that's supposed to be part of every hosting checklist and is, in practice, the first line skipped when someone's in a hurry to launch.

The design decision underneath this

A security setting that lives in a menu you don't visit again after setup isn't a security setting — it's a one-time suggestion. The bar exists because the alternative, a settings page that's technically correct and practically invisible, is how "default admin/admin" survives in production long enough to matter. Loud beats thorough when thorough only gets read once.