OpenCart Installation and Configuration: Server, Security, Optimization

A fresh OpenCart installation and configuration often ends with a 500 error or exposes the storage folder from the browser. These are typical consequences of a standard provisioning, which we remediate within the first hour of engagement.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1414
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1285
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    982
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1241
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    982
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    995

A fresh OpenCart installation and configuration often ends with a 500 error or exposes the storage folder from the browser. These are typical consequences of a standard provisioning, which we remediate within the first hour of engagement.

Recently, a client came to us with an OpenCart store running on MySQL 5.6 and PHP 7.4. After upgrading to OpenCart 4, the store kept crashing with a 500 error. We identified incompatible extensions and missing opcache. After configuring PHP 8.2 with opcache and switching to MariaDB 10.6, the store ran twice as fast. The client saved about $2,000 in lost revenue from downtime and avoided a $500 emergency fix.

OpenCart is one of the most popular CMS for e-commerce, but its default installation leaves vulnerabilities and performance issues. In this article, I will explain how to perform proper OpenCart installation and server configuration to make your e-commerce platform fast and secure. Our team has 10 years of experience with OpenCart: we have helped launch over 50 online stores on this CMS. OpenCart 4 is 2 times faster than Magento 2 in TTFB and consumes half the memory. Clients who order a turnkey installation save up to 40% of time on launch and avoid common beginner mistakes.

Server Requirements

OpenCart 4.x requires:

Component Minimum Recommended
PHP 8.0 8.2+
MySQL 5.7 8.0
MariaDB - 10.6+
Web server Apache / nginx nginx
PHP extensions curl, zip, zlib, gd, mysqli, mbstring + opcache, redis
PHP memory 128 MB 256 MB+

Official OpenCart documentation recommends these parameters.

Source: OpenCart official docs

How to Configure PHP for OpenCart?

File php.ini or directive in nginx.conf:

memory_limit = 256M upload_max_filesize = 64M post_max_size = 64M max_execution_time = 300 max_input_vars = 10000 date.timezone = Europe/Minsk opcache.enable = 1 opcache.memory_consumption = 256 opcache.max_accelerated_files = 20000 opcache.revalidate_freq = 60 

max_input_vars = 10000 is mandatory for large forms (configuring product options).

nginx Configuration

Click for detailed nginx configuration with explanation
server { listen 443 ssl http2; server_name localhost www.localhost; root /var/www/opencart/public_html; index index.php; ssl_certificate /etc/ssl/certs/localhost.crt; ssl_certificate_key /etc/ssl/private/localhost.key; location / { try_files $uri $uri/ @opencart; } location @opencart { rewrite ^/(.+)$ /index.php?_route_=$1 last; } location ~ ^/(system|admin/config\.php|config\.php) { deny all; } location ~ \.php$ { fastcgi_pass unix:/run/php/php8.2-fpm.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; fastcgi_read_timeout 300; } location ~* \.(jpg|jpeg|png|gif|ico|css|js|woff2)$ { expires 30d; add_header Cache-Control "public, no-transform"; } } server { listen 80; server_name localhost www.localhost; return 301 https://localhost$request_uri; } 

This configuration enforces HTTPS, blocks access to sensitive paths, and sets aggressive caching for static assets.

How to Move Storage Outside the Web Root?

Moving storage outside the web root eliminates the possibility of direct access to log and cache files via URL. We recommend moving the folder immediately after installation.

Download and unpack the distribution, copy files to the public directory. Create a database and user. Then move the storage folder outside the web root.

cd /var/www/opencart wget https://github.com/opencart/opencart/releases/download/4.0.2.3/opencart-4.0.2.3.zip unzip opencart-4.0.2.3.zip cp -r upload/* public_html/ cd public_html cp config-dist.php config.php cp admin/config-dist.php admin/config.php chmod 775 system/storage/cache/ system/storage/logs/ system/storage/download/ system/storage/upload/ image/ image/cache/ chmod 664 config.php admin/config.php chown -R www-data:www-data /var/www/opencart/public_html/ # Create database mysql -e "CREATE DATABASE opencart CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;" mysql -e "CREATE USER 'opencart_user'@'localhost' IDENTIFIED BY 'strong_password';" mysql -e "GRANT ALL PRIVILEGES ON opencart.* TO 'opencart_user'@'localhost'; FLUSH PRIVILEGES;" # Move storage mv public_html/system/storage/ /var/www/opencart/storage/ 

In config.php and admin/config.php:

define('DIR_STORAGE', '/var/www/opencart/storage/'); 

Why is Setting Permissions Important?

After installation, delete the install folder: rm -rf public_html/install/. Incorrect permissions are a common cause of 500 errors. Ensure config.php and admin/config.php have 664, and writable directories have 775. Permissions 664 on config.php prevent accidental configuration changes via the web.

How to Secure the OpenCart Admin?

  • Rename /admin/ to an unpredictable name (e.g., /store-control-9x7k/).
  • Set up HTTP Basic Auth on the admin folder.
  • Update paths in admin/config.php.
  • Add an nginx block location /store-control-9x7k { auth_basic ...; }.
  • Install a two-factor authentication extension.
  • Enable captcha on the login page.

How We Install OpenCart in 1 Day (Real Case Example)

One of our recent projects was launching an electronics online store with a catalog of 5000 products. The client provided a dedicated server with nginx and MySQL. We performed:

  1. Server audit (discovered an outdated MySQL version).
  2. Configuration of PHP 8.2 with opcache and redis.
  3. Installation of OpenCart 4.0.2.3.
  4. Moving storage outside the web root.
  5. Renaming admin and setting up HTTP Basic Auth.
  6. SSL configuration via Let's Encrypt.
  7. Speed optimization: gzip, caching, Redis.

The whole process took 1 day. After launch, the store showed LCP 1.5 sec, meeting Core Web Vitals. The client saved an estimated $3,000 in development costs compared to hiring separate specialists.

What's Included

  • Audit of the current server (or hosting selection assistance).
  • Configuration of PHP 8.2+ with opcache and redis.
  • Nginx setup with SSL certificate (Let's Encrypt).
  • Installation of OpenCart 4.x with database migration.
  • Moving storage outside the web root.
  • Basic security measures (rename admin, HTTP Basic Auth).
  • Speed optimization: gzip, caching, Redis.
  • Delivery of documentation with access and instructions.
  • 1 hour of online training on working with the admin panel.
  • 2 weeks of support after launch (consultations on content).

Typical cost for this turnkey installation is $500, saving you up to $200 compared to individual component setup.

Comparison of OpenCart and Magento 2

Parameter OpenCart 4 Magento 2
TTFB ~200 ms ~300 ms
Memory consumption 128 MB 256 MB+
Support complexity Low High
Cost of ownership Low High

Contact us to get a consultation on turnkey OpenCart installation. We guarantee stable operation of your store after configuration. Order installation — get a store ready for content in 1–2 days. The cost is calculated individually after a server audit.