✦DevWebThemes Docs
FaithChurch Pro · v1.5.2 · Buyer Manual Revision 2
Live demoSoftware Store
DEVWEB THEMES · COMPLETE BUYER DOCUMENTATION

FaithChurch Pro
v1.5.2

This manual is written for a buyer who may never have installed a PHP website before. Follow it from top to bottom for your first installation, then use the configuration sections whenever you need to connect a payment provider, change colours, publish content, configure partners or move the site to another server.

PHP 8.2+MySQL / MariaDBcPanel readyDevWeb licensedFull source code
FaithChurch Pro public website and administration dashboard preview
No documentation section matched your search. Try a shorter term such as Paystack, colour, database or Google login.
1PRE-INSTALLATION

What you need before you upload anything

Prepare these items first. Doing this before extraction prevents the most common cPanel installation problems.

Hosting

PHP 8.2 or newer, MySQL/MariaDB, HTTPS, and the required PHP extensions.

Domain

A domain or subdomain already pointing to the hosting account where FaithChurch will run.

DevWeb purchase

Your FaithChurch license key and the same email address used for the DevWeb Themes purchase.

Empty database

A new MySQL/MariaDB database, a database user and that user's password.

Required PHP extensions

ExtensionWhy FaithChurch needs it
pdo + pdo_mysqlDatabase connection and prepared SQL queries.
curlDevWeb licensing, payments, OAuth and remote demo packages.
opensslSecure HTTPS integrations and cryptographic operations.
mbstringSafe handling of Unicode and long text fields.
fileinfoServer-side MIME checking for uploaded files.
sodiumVerification of signed DevWeb demo-content packages.
You do not need to import database/schema.sql manually.The installer connects to the empty database and creates the schema itself. Manual SQL import should only be used for advanced recovery or developer work.
2DOMAIN

Connect the domain and identify the document root

FaithChurch can run on a normal domain, a subdomain, or a supported subfolder. For a first-time buyer, a normal domain or subdomain is easiest.

Option A: the domain already exists in cPanel

Open cPanel → Domains.

Find the domain you want to use and open its management screen.

Read the Document Root.

This is the exact folder that serves files for the domain. It might look like /home/account/public_html, /home/account/example.com, or a hosting-provider-specific path.

Open that exact folder in File Manager.

This is where the FaithChurch buyer ZIP must be extracted for the direct shared-hosting installation.

Option B: create a new domain or subdomain

In cPanel's Domains interface, create the registered domain or subdomain and give it its own document root. Do not accidentally share the document root with another live website unless that is intentional.

DNS must resolve to this hosting account.If the domain is registered elsewhere, point the required DNS records to your host first. FaithChurch cannot fix DNS from inside the PHP application.

Enable HTTPS before payment or social-login testing

Use cPanel SSL/TLS Status or your host's AutoSSL interface and confirm that https://yourdomain.com loads without a certificate warning. Payment webhooks and OAuth callbacks should use HTTPS in production.

Official cPanel referencesDomains manages document roots; SSL/TLS Status shows certificate coverage. See the official reference links at the bottom of this manual.
3DATABASE

Create the empty MySQL database correctly

cPanel → Database Wizard / MySQL Databases
Create a database.

Example: faithchurch. cPanel may automatically prefix it, for example cpuser_faithchurch. The installer needs the full final database name.

Create a database user.

Use a strong, unique password and save it. The web admin password and database password are different credentials.

Add the user to the database.

Grant the privileges needed to create and manage the FaithChurch tables. On a new dedicated application database, choose All Privileges.

Write down four values.

Database host, database name, database username and database password. You enter these in Installer Step 3.

Installer fieldTypical cPanel valueImportant note
Host127.0.0.1 or localhostThe installer defaults to 127.0.0.1. If your host uses a remote DB host, use the hostname supplied by the host.
Port3306Use the host's actual port if different.
Databasecpuser_faithchurchInclude the cPanel prefix when cPanel shows one.
Usernamecpuser_fcuserInclude the full prefix.
PasswordYour generated passwordCase-sensitive. Do not reuse your cPanel or admin password.
4FILES

Upload and extract the FaithChurch ZIP

Open the domain's document root in File Manager.

Do not guess. Use the path confirmed in the Domain section above.

Click Upload and upload the buyer ZIP.

The file is normally named FaithChurch-Pro-v1.5.2-DevWebThemes.zip.

Select the ZIP and click Extract.

Extract directly into the document root.

Check the result before opening the site.

The document root itself must contain index.php, .htaccess, bootstrap.php, app/, public/, views/, database/, storage/ and documentation/.

your-domain-document-root/
├── .htaccess
├── index.php
├── bootstrap.php
├── app/
├── database/
├── documentation/
├── public/
├── server/
├── storage/
└── views/
If you see another FaithChurch folder before index.php, stop.A common mistake is ending up with public_html/FaithChurch-Pro-v1.5.2-DevWebThemes/index.php. If your domain points to public_html, move the package contents one level up so public_html/index.php is the FaithChurch front controller.

Permissions

Start with normal hosting permissions: directories 0755 and files 0644. The storage/ directory must be writable by the PHP process. If ownership on your host requires it, the host may recommend 0775 for writable directories. Avoid using 0777 as a permanent fix.

5INSTALLER

Complete the four-step installation wizard

After extraction, visit the domain in your browser. A fresh installation automatically redirects to /install.

Step 1 of 4: Verify your DevWeb Themes purchase

Sign in to DevWeb Themes.

Your customer area includes Purchases, Downloads and Licenses. The license page is at /customer/licenses when you are signed in.

Copy the FaithChurch license key.

The installer expects your DevWeb license/purchase code and the email used for the purchase.

Submit the form.

FaithChurch sends the license code, purchase email, product slug faithchurch, domain and version to the DevWeb Themes license API. The commercial installer does not contain an offline bypass.

Step 2 of 4: Server check

The installer checks pdo, pdo_mysql, curl, openssl, mbstring, fileinfo, sodium, and whether storage/ is writable. Do not continue by editing source code to bypass a missing extension; enable the missing module in cPanel/PHP Selector or contact the host.

Step 3 of 4: Connect the database

Enter the database values created earlier. On success FaithChurch writes the environment configuration, generates an application key when required, and creates the database tables from database/schema.sql.

Step 4 of 4: Create the church and administrator

FieldWhat to enter
Church / website nameThe public organisation name. You can change it later in Admin → Settings.
TaglineShort statement used by the public layout and metadata.
Admin nameName of the first Super Administrator.
Admin emailA real email address controlled by the site owner.
Admin passwordAt least 10 characters. Use a unique password, preferably much longer.
What happens when you click Finish installationFaithChurch creates the first super_admin, seeds base design/settings, ensures the default pages exist, writes storage/installed.lock, then sends you to the login page.
6FIRST LOGIN

Do these things immediately after installation

  • Open https://yourdomain.com/login and sign in with the administrator you created.
  • Open /admin and confirm the dashboard loads.
  • Go to Admin → Settings and replace the example church contact details.
  • Go to Admin → Appearance and set your colours, homepage copy and hero.
  • If you want starter content, use Admin → Demo Import before creating a large amount of your own content.
  • Configure payment gateways in test/sandbox mode and complete a real end-to-end test transaction.
  • Configure Google/Facebook login only after HTTPS and the final domain are correct.
  • Review every starter legal page and adapt it to the laws and procedures of your organisation.
  • Back up the new database and application once the first configuration is complete.
7DEVWEB LICENSE

Where the buyer finds the ZIP and license

Customer areaPurposePath after sign-in
PurchasesOrders, invoices and purchased products./customer/purchases
DownloadsGenerate a protected download for the purchased FaithChurch release./customer/downloads
LicensesCopy the DW license key, view license type, see domain seats, activate or deactivate a domain./customer/licenses

The installer activates against the current site hostname automatically. If you later move the production installation to a different domain, deactivate the old domain in the DevWeb customer license page before activating the new production domain.

License limits are governed by the current DevWeb Themes License Agreement.The product documentation explains the workflow, but the marketplace agreement is the source of truth for Regular and Extended usage rights.
8STARTER CONTENT

Import official demo content safely

Admin → Demo Import

FaithChurch provides three official presets:

Modern Church

Contemporary worship, sermons, events and ministries.

Global Ministry

Livestream, missions, campaigns and international ministry presentation.

Community Church

Families, local events, groups and first-visit journeys.

How the import works

The application downloads structured JSON from the configured DevWeb demo-content service. It verifies the package with the included Ed25519 public key before changing the database. Existing demo records with the same type and slug are updated instead of duplicated.

Import before heavy customisation.A later re-import can intentionally update matching demo records. Back up your database first if you have already rewritten demo pages or demo content that uses the same slugs.
9APPEARANCE

Change colours and typography without editing CSS

Admin → Appearance → Brand colours & typography
ControlDefaultWhat it changes
Primary#155EEFMain buttons, active states and prominent brand accents.
Navy#0B1F3ADark brand surfaces and strong contrast areas.
Accent#5EA1FFSecondary blue highlights and decorative accents.
Background#F8FAFCPrimary public-page background token.
Text#162033Main body/heading text token.

Font choices included

  • Modern System / Inter style – the default modern UI stack.
  • Aptos – a softer office/system presentation.
  • Editorial Serif – Georgia/Cambria style for a more traditional editorial feel.
Live previewThe Appearance screen previews the theme while you work. Nothing is permanent until you click Save appearance.
Brand mark limitation in v1.5.2The current release uses the built-in FaithChurch ✦ mark together with the editable Site Name. There is no logo-upload or favicon-upload field in the v1.5.2 Appearance screen, so the documentation does not pretend that control exists.
10HOMEPAGE

Configure the hero and homepage copy

Admin → Appearance

Hero media

FieldUse
Hero styleChoose the built-in FaithChurch graphic or an uploaded church photograph.
Hero imageJPG, PNG or WebP. The upload service accepts images up to 8 MB and validates MIME type and dimensions server-side.
Hero image alt textDescribe meaningful image content for accessibility and search context.
Hero card heading / supporting textThe small contextual message displayed in the hero media treatment.

Editable homepage text

The same Appearance screen lets you edit the Hero heading/text, Welcome heading/text, Giving heading/text, Giving quote/reference, Community heading/text and Visit heading/text.

Motion controls

Premium preloader controls the branded loading screen. Smooth reveal animations controls public reveal motion. Disable animation if the organisation prefers a more static presentation.

11GENERAL SETTINGS

Set the church identity and service details

Admin → Settings → Church identity
FieldWhere it appears / why it matters
Site namePublic header/footer branding and several default labels.
TaglineFooter copy and default page description when a page-specific description is not supplied.
EmailOrganisation contact identity stored in settings.
PhoneDisplayed in the public footer visit/contact area.
AddressDisplayed in the public footer visit area.
Main service dayUsed by homepage/service presentation.
Main service timeUsed by homepage/service presentation.

Click Save all settings after editing this screen. Payment, social login, storage and AdSense settings are on the same page and are explained separately below.

12CONTENT CMS

Publish sermons, events, ministries and other content

The admin sidebar has dedicated managers for Sermons, Events, Ministries, Leadership, Testimonies, Pages & Policies, and Blog.

Shared editor fields

Every content editor provides Title, Slug, Short description, Main content, Status, Publish date and Featured image. Draft content remains out of the published public queries until you publish it.

Content typeAdditional fields
SermonSpeaker, Scripture, Video URL and Audio URL. Media URLs must be valid HTTP/HTTPS URLs.
EventDate, Time and Venue.
MinistryLeader / Role.
LeadershipLeader / Role.
TestimonyUses the shared title, description, body, image and publication controls.
BlogUses the shared content fields in v1.5.2.

Featured-image rules

JPG, PNG and WebP images are accepted up to 8 MB. The server reads the real MIME type instead of trusting the filename and rejects invalid image dimensions.

13PAGES & SEO

Edit pages, menus, legal policies and search metadata

Admin → Pages & Policies

FaithChurch installs core pages such as About, Give, Prayer, Contact, Privacy Policy, Terms, Donation & Refund Policy, Cookie Policy and Accessibility. Core URLs are protected from accidental slug changes and deletion, but their public content remains editable.

Page settings

ControlMeaning
Page categoryStandard page or Legal / Policy page.
Navigation labelShort label used when the page is shown in navigation.
Show in headerAdds a published custom page to the header's custom page positions. The public header loads up to 3 of these custom page links before the fixed Sermons/Events/Ministries links.
Show in footerAdds the page to appropriate footer navigation. Legal pages marked for footer display are shown in the Legal & Policies column.
Hide from search enginesAdds a noindex directive for that page.
SEO titleOptional search/social title for the page.
SEO descriptionOptional short description, up to 320 characters.

Simple page formatting

## Section heading
### Smaller heading
- First bullet item
- Second bullet item

Normal paragraph text.

FaithChurch safely escapes page content; it is not a raw HTML editor. Use the simple heading and list syntax above.

Sitemap and robots

The public application exposes /sitemap.xml and /robots.txt. After launch, submit the sitemap URL to the search engines you use and confirm that pages you intentionally set to noindex are not submitted as important landing pages.

14USERS & ACCESS

Understand member accounts and staff roles

Public users can register and manage a member account. Staff accounts have additional capabilities based on their role.

RoleCapabilities in v1.5.2
Super Admin / AdminAll administrator capabilities.
PastorDashboard, content, messages, partners and system-health access.
EditorDashboard and content management.
FinanceDashboard, donations and partner-view access.
MemberNormal signed-in public account experience.
User-management limitation in v1.5.2Admin → Users is currently a user/role listing screen. It does not provide a full create/edit/promote workflow in this release. Do not tell staff that a control exists when the UI does not provide it.
15ONLINE GIVING

Connect payment gateways correctly

Only gateways with the required credentials appear on the public giving form. Configure one provider at a time, test it, then move to the next provider.

Admin → Settings → Gateway credentials

How FaithChurch protects the payment result

FaithChurch creates a pending donation record before redirecting to the gateway. On callback/webhook it verifies with the provider and compares the returned amount and currency with the local donation before marking the record paid. Webhook deliveries are signature-checked where the provider supplies signatures, then the transaction is re-verified through the provider API.

Never put secret keys into page content, JavaScript, screenshots or support messages.Secret gateway credentials are server-side values. The Admin settings form does not render stored secrets back to the browser after saving them.

Default currency

Enter a three-letter currency code such as ZAR, USD or another currency supported by the gateway and your merchant account. A syntactically valid three-letter code does not guarantee that every provider/account supports that currency.

FaithChurch requires: Paystack Secret Key. The same secret key is also used to validate the x-paystack-signature webhook signature.

Get the secret key from Paystack.

In Paystack, open the API Keys & Webhooks area and copy a test secret key first. Paystack documents secret keys as server-side credentials and says they should not be exposed in client code.

Paste it in FaithChurch.

Admin → Settings → Payments → Paystack secret. Save settings.

Add the webhook in Paystack.

Use https://YOUR-DOMAIN/webhooks/paystack. FaithChurch listens for a successful charge event and re-verifies the transaction by reference.

Run a test donation.

Open the public Give page, choose Paystack, complete a test payment and confirm Admin → Donations changes the donation to paid.

Go live carefully.

Replace the test secret with the live secret only after your Paystack business is activated and the test flow works. Re-test the live webhook with a small real transaction.

Webhook URL
https://YOUR-DOMAIN/webhooks/paystack

Automatic callback used by FaithChurch
https://YOUR-DOMAIN/payment/callback/paystack

FaithChurch requires: Flutterwave Secret Key and Flutterwave Webhook Secret/Secret Hash.

Get a test secret key.

Use Flutterwave's test environment first. Keep the secret server-side.

Create a webhook secret hash.

Flutterwave recommends a random secret hash for verifying incoming webhook requests. Use a long random value that is not reused elsewhere.

Save both values in FaithChurch.

Admin → Settings → Payments → Flutterwave secret and Flutterwave webhook secret.

Set the webhook URL at Flutterwave.

Use https://YOUR-DOMAIN/webhooks/flutterwave and use the exact same secret hash you entered in FaithChurch.

Complete a test donation.

After webhook signature validation, FaithChurch verifies the transaction by Flutterwave transaction ID or reference before marking it paid.

Webhook URL
https://YOUR-DOMAIN/webhooks/flutterwave

Automatic callback used by FaithChurch
https://YOUR-DOMAIN/payment/callback/flutterwave

FaithChurch requires: Stripe Secret Key and a webhook endpoint signing secret that begins with whsec_.

Start in Stripe test mode.

Copy the test secret key from Stripe's API keys area.

Paste the key in FaithChurch.

Admin → Settings → Stripe secret.

Create a Stripe webhook endpoint.

Endpoint: https://YOUR-DOMAIN/webhooks/stripe. FaithChurch handles checkout.session.completed when the session is paid.

Reveal the endpoint signing secret.

Stripe assigns a separate signing secret to each webhook endpoint. Copy the endpoint's whsec_... value, not another API key.

Paste it in Stripe webhook signing secret.

Save settings, then test Stripe Checkout from the public Give page.

Stripe test and live webhook secrets are different.When you create/use a live-mode endpoint, replace both the secret API key and the webhook signing secret with the live values.
Webhook URL
https://YOUR-DOMAIN/webhooks/stripe

Event FaithChurch expects
checkout.session.completed

Automatic success callback
https://YOUR-DOMAIN/payment/callback/stripe?session_id={CHECKOUT_SESSION_ID}

FaithChurch requires: PayPal Client ID, PayPal Secret, mode (Sandbox/Live), and PayPal Webhook ID.

Create or select a REST API app in PayPal Developer.

Use the Sandbox environment first. Copy the app's Client ID and Secret.

Save credentials in FaithChurch.

Admin → Settings → PayPal Client ID, PayPal Secret, and set PayPal mode = Sandbox.

Create the webhook on that PayPal app.

Use https://YOUR-DOMAIN/webhooks/paypal. Subscribe to events that cover PAYMENT.CAPTURE.COMPLETED and/or CHECKOUT.ORDER.COMPLETED.

Copy the webhook's Webhook ID.

Paste it into the FaithChurch PayPal Webhook ID field. This is not the same thing as the Client ID.

Test in Sandbox.

FaithChurch verifies PayPal's webhook signature through PayPal and then verifies the order before changing the donation status.

Move to Live.

Switch the PayPal app/dashboard to Live, use the live Client ID/Secret, create or select the live webhook and use its live Webhook ID, then change FaithChurch mode to Live.

Webhook URL
https://YOUR-DOMAIN/webhooks/paypal

Automatic return URL
https://YOUR-DOMAIN/payment/callback/paypal

Recommended events
PAYMENT.CAPTURE.COMPLETED
CHECKOUT.ORDER.COMPLETED
16SOCIAL LOGIN

Connect Google and Facebook sign-in

Admin → Settings → Google & Facebook

Google

Create a Google OAuth client for a web application.

Use Google Cloud/Google Auth Platform and configure the consent/app information required for your account.

Add the exact redirect URI.

https://YOUR-DOMAIN/auth/google/callback. Google requires the redirect URI in the request to match an authorised redirect URI.

Copy Client ID and Client Secret.

Paste them into Admin → Settings → Google Client ID / Google Client Secret.

Test with HTTPS.

FaithChurch requests openid email profile, exchanges the authorisation code server-side and reads the user's Google profile.

Facebook

Create/configure your Meta app with Facebook Login.

Use the app ID and app secret supplied by Meta.

Add the exact Valid OAuth Redirect URI.

https://YOUR-DOMAIN/auth/facebook/callback. Meta also checks redirect URI matching.

Paste App ID and App Secret into FaithChurch.

Admin → Settings → Facebook App ID / Facebook App Secret.

Test the public login page.

FaithChurch requests email and public_profile. If a Facebook account does not provide an email, the application cannot complete a normal email-based account flow reliably.

Google callback
https://YOUR-DOMAIN/auth/google/callback

Facebook callback
https://YOUR-DOMAIN/auth/facebook/callback
If you change the domain, update OAuth redirect URIs.Changing only APP_URL is not enough. The provider dashboards must also allow the new exact callbacks.
17MEDIA STORAGE

Choose local uploads or Amazon S3 / S3-compatible storage

Admin → Settings → Infrastructure → Storage driver

Local storage

This is the simplest option. Uploaded media is stored below public/uploads/ in folders such as content, hero, avatars and credentials. The application creates required upload folders as needed.

S3 storage

Select Amazon S3 / S3 compatible in Admin, but place infrastructure credentials in .env. FaithChurch intentionally does not expose S3 access keys through the normal admin form.

AWS_ACCESS_KEY_ID="YOUR_ACCESS_KEY"
AWS_SECRET_ACCESS_KEY="YOUR_SECRET_KEY"
AWS_DEFAULT_REGION="af-south-1"
AWS_BUCKET="your-bucket-name"
AWS_ENDPOINT=""
AWS_USE_PATH_STYLE=false
VariableMeaning
AWS_ACCESS_KEY_IDAccess key for the IAM/service credential allowed to put objects in the selected bucket.
AWS_SECRET_ACCESS_KEYSecret for that access key. Keep it private.
AWS_DEFAULT_REGIONS3 signing region. Default in the package is af-south-1.
AWS_BUCKETBucket name used for standard Amazon S3 host construction.
AWS_ENDPOINTOptional S3-compatible endpoint. In v1.5.2 the signer uses the endpoint host directly for object paths, so use the bucket-specific HTTPS endpoint required by your compatible provider.
Important v1.5.2 S3 behaviourThe current storage service returns a direct object URL after upload; it does not generate temporary signed GET URLs. Treat the S3 driver as public-media storage unless your endpoint/CDN provides an appropriate read-access layer. Be especially careful with uploaded credential PDFs or any document that should not be public.
18EMAIL

SMTP configuration and the current mail status

FaithChurch v1.5.2 includes an SMTP service and environment variables, but the core contact/prayer workflows currently store submissions in Admin → Messages & Prayer rather than automatically emailing them. There is also no SMTP settings form in Admin in this release.

Do not tell the buyer that email notifications are already wired when they are not.This documentation records the actual v1.5.2 behaviour.

If you are extending the bundled SMTP service or a later update connects it, the packaged environment keys are:

MAIL_DRIVER=smtp
MAIL_HOST=mail.yourdomain.com
MAIL_PORT=587
MAIL_USERNAME=no-reply@yourdomain.com
MAIL_PASSWORD="YOUR_MAILBOX_PASSWORD"
MAIL_ENCRYPTION=tls
MAIL_FROM_ADDRESS=no-reply@yourdomain.com
MAIL_FROM_NAME="Your Church Name"

The bundled mailer supports STARTTLS when MAIL_ENCRYPTION=tls. Port 587 + STARTTLS is the safest documented choice for this implementation. Do not assume implicit TLS on port 465 works without testing or code changes.

19ADS

Google AdSense settings

Admin → Settings → Infrastructure

You can enable AdSense and enter the publisher client ID such as ca-pub-.... When enabled with a client ID, the public layout loads the Google AdSense script.

Ad-slot status in v1.5.2The Admin screen stores a Default ad slot value, but the current core public templates do not render an actual <ins class="adsbygoogle"> ad unit from that stored slot. Enabling AdSense loads the provider script; placement of actual ad units still requires a compatible theme section/update. Review consent requirements before serving personalised advertising.
20PARTNER PROGRAMME

Configure Family and Covenant partnerships

Admin → Partners → Settings

The Partner area is more than a donation tier. It includes partner profiles, contribution state, care requests, prayer workflow, sessions/meetings, resources and Covenant formation tools.

Core partner settings

Administrators with partners.manage can configure partner currency, Family minimum amount, Covenant minimum amount, suggested contribution values, Covenant grace days, public headings/descriptions, benefit lists, formation copy, credential notes, integrity copy and partnership FAQs.

Operational sections

Family prayer

Track prayer items and ministry follow-up for Family Partners.

Meetings / sessions

Create scheduled partner sessions and attach secure HTTPS meeting links.

Resources

Publish resources for all, Family or Covenant audiences with HTTPS links.

Care requests

Move requests through new, reviewed, in prayer, contacted, completed or archived states.

Covenant training

Create modules and record individual progress.

Standing & credentials

Manage formation standing and issue verifiable ministry credentials.

21COVENANT FORMATION

Training, standing and ministry credentials

Covenant training modules support title, description, category, display order, HTTPS resource URL and draft/published status. Admin can record each Covenant Partner as not started, in progress or completed, together with a mentor note.

Formation standing values

formation, mentoring, ready_for_review, released, ordained or paused. Badge status can be active or suspended.

Credential types

Completion, Release, Ordination and Recognition. Issuing a credential creates a certificate number and random verification code. The public verification route is /credential/verify/{code}.

Optional uploaded certificate files use the normal storage driver. If you use S3, read the direct-object-URL warning in the Storage section before storing sensitive certificates there.

22INBOX

Manage contact messages and prayer requests

Admin → Messages & Prayer

Public Contact and Prayer forms create message records that appear in this admin screen. Staff with messages.manage can change message status to New, Reviewed or Archived.

This is the primary built-in inbox in v1.5.2. As noted in the Email section, the current core flows do not automatically send these records by SMTP.

23FINANCE VIEW

Read donation records

Admin → Donations

The donations table shows Reference, Donor, Amount, Gateway, Status and Date. Payment attempts begin as pending, can become paid only after provider verification, or become failed when initiation/verification fails.

Use the provider dashboard for financial reconciliation.The FaithChurch table is the application's record. Reconcile it against Paystack/Flutterwave/Stripe/PayPal settlement data and your bank records according to your organisation's financial controls.
24DEPLOYMENT

Apache/LiteSpeed shared hosting and Nginx/VPS

cPanel / Apache / LiteSpeed

The commercial package includes a root .htaccess for buyers who extract the full package directly into the domain document root. It blocks direct web access to application internals such as app/, database/, storage/, server/, views/ and documentation/; public assets are internally mapped from public/.

Nginx / VPS preferred layout

On a server where you control the virtual host, keep the application outside the public web root and set the virtual host root to the package's /public directory. An example configuration is included at server/nginx.conf.example.

server {
    listen 80;
    server_name example.com;
    root /var/www/faithchurch/public;
    index index.php;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location ~ \.php$ {
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        fastcgi_pass unix:/run/php/php8.4-fpm.sock;
    }

    location ~ /\. { deny all; }
}

Subfolder installation

The routing helpers detect a mount path such as https://example.com/church. OAuth, payment and webhook URLs must then include that same subfolder, for example https://example.com/church/webhooks/stripe. For less experienced buyers, a dedicated domain/subdomain is easier to configure and troubleshoot.

25SECURITY

Production security checklist

  • Use HTTPS before accepting logins, payments or OAuth callbacks.
  • Keep APP_ENV=production and APP_DEBUG=false.
  • Never publish or email your .env, database password, gateway secrets, OAuth secrets or S3 secret.
  • Keep the DevWeb license mode remote. Do not create a local bypass.
  • Use a unique administrator password and remove/restrict staff access when personnel change.
  • Keep PHP, MySQL/MariaDB and the web server updated through your host/server maintenance process.
  • Use real payment webhooks and test failed, cancelled, duplicate and successful payment cases.
  • Back up before theme/source updates and test restore procedures.
  • Keep normal file permissions and correct ownership; do not leave the whole site writable.
  • Review every starter legal policy for your jurisdiction before launch.

FaithChurch v1.5.2 includes CSRF protection for state-changing forms, login/payment rate limiting, prepared PDO queries, secure password hashing, strict session settings, upload MIME/size validation, upload execution protections, Content Security Policy, HSTS on HTTPS, X-Frame-Options and other browser security headers.

26MAINTENANCE

Back up before every update

Minimum backup set

  • Export the FaithChurch MySQL/MariaDB database.
  • Download or archive the application files, especially .env, storage/ and public/uploads/.
  • If using S3, confirm the bucket has the retention/versioning/backup policy appropriate to your organisation.
  • Keep backups outside the public website directory and preferably off the hosting server as well.

Applying future DevWeb updates

Read the update notes first. A safe update package should tell you exactly which files it replaces and whether a database change is required. Never overwrite your production .env with an example environment file.

27TROUBLESHOOTING

Fix the most common installation and configuration problems

ProblemWhat to check
404 immediately after extractionConfirm the FaithChurch index.php is directly in the domain's document root, not inside an extra ZIP folder. Confirm Apache rewrite support and the supplied .htaccess.
403 on the whole websiteCheck file/directory ownership and permissions. Confirm the domain points to the directory where FaithChurch was extracted.
Installer says extension missingUse cPanel PHP Selector/Select PHP Version to enable the named module, or ask the host. The installer intentionally refuses to skip required modules.
Database connection failedUse the full prefixed cPanel database/user names, verify password, add the user to the database, grant privileges, and try localhost if your host does not accept 127.0.0.1.
License cannot be verifiedConfirm the purchase email and license key, HTTPS/DNS, outbound cURL access and that the domain is within your license allocation. Check DevWeb Themes availability.
Images will not uploadUse JPG/PNG/WebP under 8 MB; verify PHP upload limits and that public/uploads can be created/written by PHP.
Payment gateway does not appearThe required gateway credentials are blank. PayPal needs both Client ID and Secret. Save settings and reload Give.
Payment returns but remains pending/failedCheck the webhook URL, provider secret/signing secret, event delivery logs, currency/amount, and that your server can call the provider API over HTTPS.
Google redirect_uri_mismatchThe authorised redirect URI in Google must exactly match the callback displayed by FaithChurch, including scheme, hostname, subfolder and path.
Facebook login fails after domain moveUpdate the Valid OAuth Redirect URI in Meta and then verify the new domain is allowed by the app's settings.
S3 upload failsCheck access key, secret, region, bucket, endpoint, IAM/object permission and outbound HTTPS. For compatible providers use the correct bucket-specific endpoint expected by the v1.5.2 signer.
Changes appear not to saveConfirm you are not using the read-only official DevWeb demo. Production installations do not set DEVWEB_DEMO_MODE=true.
28REFERENCE

Important URLs and configuration paths

PurposeURL / path
Public website/
Login/login
Register/register
Member account/account
Admin/admin
Appearance/admin/appearance
Settings/admin/settings
Demo import/admin/demo-import
Partners/admin/partners
System health/admin/system
Give/give
Paystack webhook/webhooks/paystack
Flutterwave webhook/webhooks/flutterwave
Stripe webhook/webhooks/stripe
PayPal webhook/webhooks/paypal
Google callback/auth/google/callback
Facebook callback/auth/facebook/callback
Sitemap/sitemap.xml
Robots/robots.txt
Environment file/.env (server-private; root .htaccess blocks direct access on shared hosting)
Install lock/storage/installed.lock
Local uploads/public/uploads/
Nginx example/server/nginx.conf.example

Environment variables shipped in .env.example

APP_NAME
APP_ENV
APP_DEBUG
APP_URL
APP_KEY
APP_TIMEZONE
SESSION_NAME

DB_CONNECTION
DB_HOST
DB_PORT
DB_DATABASE
DB_USERNAME
DB_PASSWORD

DEVWEB_PRODUCT_SLUG
DEVWEB_LICENSE_MODE
DEVWEB_LICENSE_ENDPOINT
DEVWEB_DEMO_BASE_URL
DEVWEB_DEMO_PUBLIC_KEY

MAIL_DRIVER
MAIL_HOST
MAIL_PORT
MAIL_USERNAME
MAIL_PASSWORD
MAIL_ENCRYPTION
MAIL_FROM_ADDRESS
MAIL_FROM_NAME

GOOGLE_CLIENT_ID
GOOGLE_CLIENT_SECRET
GOOGLE_REDIRECT_URI
FACEBOOK_CLIENT_ID
FACEBOOK_CLIENT_SECRET
FACEBOOK_REDIRECT_URI

AWS_ACCESS_KEY_ID
AWS_SECRET_ACCESS_KEY
AWS_DEFAULT_REGION
AWS_BUCKET
AWS_ENDPOINT
AWS_USE_PATH_STYLE
29GO LIVE

Final launch checklist

  • The final domain resolves to the correct hosting document root.
  • HTTPS loads without warnings and HTTP redirects according to your hosting policy.
  • The DevWeb license is active on the correct domain.
  • Administrator and member login work.
  • Primary, Navy, Accent, Background and Text colours have been reviewed on desktop and mobile.
  • Hero image/copy, service information, church address, phone and email are correct.
  • Demo/sample content has been replaced or intentionally retained.
  • Sermons, Events, Ministries and public pages open correctly.
  • Privacy, Terms, Donation & Refund, Cookie and Accessibility wording has been reviewed for the organisation's jurisdiction.
  • Every enabled gateway has been tested end-to-end, including webhook delivery.
  • Google/Facebook callbacks point to the production domain.
  • Storage uploads work and any S3 object-access policy is intentional.
  • Prayer/contact messages reach Admin → Messages & Prayer.
  • Partner registration, dashboard, meetings/resources and Covenant tools have been tested if enabled operationally.
  • /sitemap.xml and /robots.txt load correctly.
  • APP_DEBUG=false and production secrets are not exposed.
  • A complete post-configuration database/file backup exists off the public web root.
30PRIMARY REFERENCES

Official service documentation

Third-party dashboards change over time. If a menu label in this manual moves, use the provider's official documentation below and keep the FaithChurch-specific values (webhook paths, callback paths and fields) exactly as documented above.

cPanel File Managerdocs.cpanel.net/cpanel/files/file-manager/
cPanel Domainsdocs.cpanel.net/cpanel/domains/domains/
cPanel Database Wizarddocs.cpanel.net/cpanel/databases/database-wizard/
cPanel SSL/TLS Statusdocs.cpanel.net/cpanel/security/ssl-tls-status/
Paystack API keyspaystack.com/docs/api/authentication/
Paystack webhookspaystack.com/docs/payments/webhooks/
Flutterwave webhooksdeveloper.flutterwave.com/docs/webhooks
Stripe API keysdocs.stripe.com/keys
Stripe webhooksdocs.stripe.com/webhooks
PayPal REST productiondeveloper.paypal.com/api/rest/production
PayPal webhooksdeveloper.paypal.com/api/rest/webhooks
Google OAuth web server appsdevelopers.google.com/identity/protocols/oauth2/web-server
Meta/Facebook Login manual flowdevelopers.facebook.com/documentation/facebook-login/guides/advanced/manual-flow
Amazon S3 permissionsAWS S3 policies and permissions
DevWeb Themes License Agreementdevwebthemes.com/page/license-agreement