# SixPreflight: check if your server is ready for 6amMart

> Source: https://test-allsweb.allsweb.net/sixpreflight
> Markdown for agents: https://test-allsweb.allsweb.net/sixpreflight.md
> Publisher: AllsWeb (www.allsweb.com)

SixPreflight checks whether a server is ready to run 6amMart: upload one folder, open it in a browser, and up to 169 checks end in one plain answer — ready to open, or not ready — with a list of exactly what to fix. It is for 6amMart owners on any hosting panel or none, sold as a one-time purchase on CodeCanyon, and already built into SixPanel.

## At a glance

- **checks at most, in ten steps:** 169
- **sentence at the end of it:** 1
- **grade, with every blocker named:** A–F
- **is all it needs on the server:** PHP 8.2+
- **Price:** Free
- **Where to get it:** https://codecanyon.net/search/sixpreflight
- **Documentation:** https://test-allsweb.allsweb.net/sixpreflight/docs

## What is SixPreflight?

A 6amMart shop can look fine in a browser while its payment gateway has no working credentials, push notifications go nowhere, its .env file can be downloaded by anyone, and scheduled jobs have never run. Usually a real customer's failed order is how you find out.

SixPreflight finds those problems first. It looks at the server the way a careful engineer would — hardware, PHP, database settings, web server, file permissions and what the internet can reach — and makes real test calls to your email, maps and push-notification services.

Then it gives you one sentence, a letter grade and an ordered list of what to fix, each with the exact setting, the file it lives in and the command to run.

### What you know before you open

|  | Without SixPreflight | With SixPreflight |
| --- | --- | --- |
| How you find out something is wrong | A real customer places a real order and something quietly goes wrong. That is your first signal, and it costs you the order and the customer. | You find out before you open, from a scan you run yourself — each item naming the exact line to change, the file it lives in, and what it costs your shop to leave it alone. |
| A credential that is present but wrong | It looks exactly like one that works. A config file with a value in it tells you the value is there, not that it is correct. | Real calls settle it: a real Firebase token minted and posted to Google’s token endpoint, a real SMTP conversation with EHLO / STARTTLS / AUTH, and a live geocoding call to Google Maps. Present-but-wrong fails here — the only place it can be caught before a customer finds it. |
| What the internet can already reach | You assume the files that should not be public are not public. Nothing on the server tells you otherwise, because nothing is making the requests. | It fetches a fixed list of known-risky addresses off your own live site — /.env, /.git/config, /artisan, the installer’s database.sql, and the tool’s own files — and reports what actually came back. |

## How to check a server for 6amMart

1. **Upload the folder** — Put the preflight/ folder in your site's public/ directory, or in any web folder on a bare server.
2. **Set a password** — Open https://your-domain/preflight/ and choose a password on the first screen. Do it straight away: whoever opens the page first sets it.
3. **Run a check** — Check now takes a second or two. Deeper check takes about ten seconds and adds the live tests: what the internet can reach, and your real credentials.
4. **Fix, check again, remove** — Work down the fix list, run the check again, and delete the folder when you are done.

[Read the install guide](https://test-allsweb.allsweb.net/sixpreflight/docs/install)

## What SixPreflight checks

Up to 169 checks in ten steps, cheapest and most likely to be broken first. The last two steps make outside calls, so they only run on a Deeper check.

| Step | What it looks at | Checks | Real examples |
| --- | --- | --- | --- |
| System & hardware | The machine you are paying for | 7 | vCPU count, RAM, swap, free disk, load average, OS release, whether any backup tool exists at all |
| PHP runtime | The language the shop runs on | 21 | PHP version band, 25 required extensions, memory_limit, effective max_execution_time, display_errors, OPcache on/off, OPcache memory and file count, hit rate |
| Application health | Laravel and 6amMart itself | 23 | .env tracked in git, pending migrations, failed jobs, queue backlog, log size, error count in the log, whether the scheduler has ever run, module list valid, trusted proxies, install settings present |
| Environment (.env) | The one file everything reads | 14 | duplicate keys (the last one wins, so your edit does nothing), invisible \r characters, an invalid or shipped APP_KEY, APP_DEBUG=true, a malformed APP_URL, keys nothing reads, keys that go null once config is cached |
| Host identity & permissions | Who owns the files | 9 | public IPv4 and IPv6, the PHP user, file ownership, the six directories that must be writable, world-writable files, a world-readable .env, anything writable and executable inside public/ |
| Web server | nginx or Apache in front | 17 | handler type, gzip, server tokens, FastCGI read timeout, Apache modules and MPM, php-fpm worker count vs memory, the upload size chain, live compression, static caching, HSTS, certificate expiry |
| Cache, queue & realtime | Background work | 11 | queue connection, whether a queue worker is actually running and supervised, session and cache drivers, Redis, Memcached, Reverb credentials and scheme, Pusher credentials |
| Database configuration | Where the money lives | 34 | InnoDB buffer pool sized against your real data and RAM, redo log, flush method, max_connections against php-fpm workers, skip_name_resolve, sql_mode, charset, PHP-vs-database clock skew, buffer-pool hit rate, temp tables on disk, database user privileges |
| Public exposure (Deeper check) | What a stranger can fetch | 12 | HTTPS, .env readable over the web, .git/config readable, laravel.log served, an uploaded .php file actually executing, Debugbar or Telescope answering, installer database dumps left in place, this tool's own files served as text |
| Payments, email & SMS (Deeper check) | The services that must work | 21 | a real SMTP conversation, a real Firebase token mint, a real Google Maps geocode call, payment methods usable, SMS gateway credentials, storage disk writable, maintenance mode, reCAPTCHA, timezone, currency |

Two more pages sit outside the score: live delivery tracking, with 15 checks of its own, and a test order alert that sends a real push notification to a store or rider device.

### The three ways it runs

- **On a plain server — no application installed yet** — Use this while you choose or prepare a server. Hardware, PHP, the database server, the web server, permissions and public exposure are all checked; the application checks simply have nothing to read yet.
- **Inside your shop — at the 6amMart admin codebase** — Upload it into public/ of your 6amMart install and every check runs — including the ones written for 6amMart itself: the scheduler that pays stores and riders, modules switched on but missing, the PHP extensions it needs, and the websocket behind live tracking.
- **Embedded in SixPanel** — SixPanel includes it as the Shop check-up page. Settings the panel manages point to the panel page that owns them, and the checks on your shop's own settings — payments, mail, SMS, maps — stay.

## How to read the result

Every check ends as one of four things: pass, warning, problem, or not measured.

| Score | Grade | What it means |
| --- | --- | --- |
| 90 and above | A | Production ready |
| 75–89 | B | Good. Clear the amber items and re-check |
| 55–74 | C | Workable, but leaving real performance on the table |
| 35–54 | D | Not ready. Several settings will hurt under load |
| Below 35 | F | Do not go live on this configuration |

### Blockers cap the grade

Some failures mean the shop cannot trade — no working payment method, mail failing, the database unreachable, .env readable over the web, a certificate expiring within 14 days. One blocker caps the score at 74, two at 54 and three or more at 34, and a single red row caps it at 88. Read the red rows, not just the number.

### What it cannot see, it does not grade

On a managed panel, PHP is often locked to your site's folder, so a few checks cannot be read. Those rows say so and are left out of the score: a locked-down server is never marked down for being locked down.

### The fix list

Every warning and problem lands on one list, the most serious first, each labelled from “Stops orders” down to “Tidying”. Each card shows the current value, the right value, the file it lives in, the command to run, and how to check that the change worked.

### It also remembers

The tool keeps the last 60 scans on disk. The history page shows a “since the last scan” card — what newly broke and what you newly fixed — you can compare any two saved checks side by side, and export a run as a text file.

## Is it safe on a live shop?

Yes, and here is exactly why.

- **The scan only reads** — Database probes can only run read-only queries, in a read-only session, with a 15-second limit. Row counts and order totals were compared before and after a scan: identical.
- **Nothing is sent to real people** — The email test stops after signing in to your mail server, so nothing is delivered. The exposure tests only fetch pages from your own site.
- **The benchmark uses its own table** — The optional database benchmark creates one table with a random name, uses it and removes it — even if the page is interrupted.
- **Changes happen only when you ask** — Four buttons can write: clearing a log file, sending a test order alert to a store or rider, the benchmark's table and saving the tool's own password. The separate setup script changes server settings only when you run it with --apply.

## SixPreflight requirements

| Requirement | What it needs |
| --- | --- |
| PHP | 8.2 or newer, with the pdo_mysql, json, mbstring and session extensions |
| Web server | Anything that serves your site's public/ directory |
| Write access | preflight/config.php (or paste a password hash by hand) and preflight/history/ |
| Application | None required. It runs on a bare server |
| Panels it recognizes | cPanel · aaPanel · CloudPanel · DirectAdmin · Plesk · CWP · plain server |

### 6amMart server requirements

| Resource | Floor | What to pick |
| --- | --- | --- |
| vCPU | 2 | 4 |
| RAM | 4 GB | 8 GB |
| Free disk | 20 GB | 40 GB+ |
| Storage type | SSD | NVMe |
| Hosting type | VPS or dedicated | VPS with root |

The stack it recommends: Ubuntu 26.04 LTS with the PHP and MariaDB it ships (PHP 8.5 and MariaDB 11.8), nginx with PHP-FPM, and Redis. Choose MariaDB, not MySQL — MySQL does not run 6amMart as shipped.

## Tested on our own servers

On our own servers, running a real shop, it scored 97 and 96 out of 100 — grade A, with no red rows. That is us scanning our own machines, so treat it as a starting point: run it on yours and compare the rows.

## What SixPreflight cannot do

- **The exposure step is not a penetration test** — It fetches a fixed list of known-risky addresses off your own URL and reports what came back. It does not look for unknown vulnerabilities and it is not a code audit.
- **It cannot see what the server will not show it** — Checks that need shell_exec or /proc degrade to “not measured” rather than guessing. Managed panels disable different things, so some rows are blank on one host and populated on another.
- **A “Check now” cannot see six of the web-server rows, and one of them is a blocker** — Compression, static caching, live keep-alive, the server banner, HSTS and certificate expiry are read off a real response, so they only appear on a Deeper check — and cert_expiry is on the blocker list. Run the Deeper check before you trust a green result.
- **One thing genuinely cannot be tested from a server** — The Google Maps client key is restricted by browser referrer, so the tool can tell you it is missing, or that it is dangerously identical to your server key — but it cannot verify a correctly-restricted one from the server side, and says so rather than passing it.
- **The benchmarks measure this machine at this moment** — A noisy neighbour makes every number pessimistic — check the load-average row before drawing conclusions.

## SixPreflight FAQ

### How do I know if my server is ready for 6amMart?

Run SixPreflight on it. Upload the folder, open it in a browser and press Check now, then run a Deeper check before you launch. Up to 169 checks cover the hardware, PHP, the application, .env, permissions, the web server, caching, the database, public exposure and outside services, and end in one sentence, an A–F grade and an ordered fix list.

### How much does SixPreflight cost?

It is a one-time purchase on CodeCanyon — the price is on the CodeCanyon item page — with updates included and your first setup done free. Nothing in it checks a licence, an account or an expiry date, and it reports nothing back to AllsWeb. On a SixPanel server it is already included as the Shop check-up page.

### Does SixPreflight change anything on my server?

The scan does not: it only reads, never writes to an application table and never sends mail or SMS to anyone. Four buttons can write when you press them — clearing a log, sending a test order alert, the benchmark's own table and saving the tool's password. The separate setup script changes settings only when you run it with --apply.

### Is it safe to run on a live shop that is taking orders?

Yes. Its database probes can only run read-only queries in a read-only session, and the optional benchmark uses a table it creates with a random name and then removes. Row counts and order totals were compared before and after a scan, and they were identical.

### Do I need 6amMart to use it?

No. On a bare server it still checks the hardware, PHP, the database server, the web server, permissions and what the internet can reach — useful before you buy hosting. On any other Laravel app the server checks apply, and the 6amMart-only checks are skipped.

### Does it work on cPanel, aaPanel, CloudPanel or a plain VPS?

Yes. It recognises cPanel, aaPanel, CloudPanel, DirectAdmin, Plesk, CWP and plain servers, and gives install commands and paths for the one you use. If a setting keeps reverting after a restart, your panel is rewriting it — change it in the panel instead.

### What score do I need before I go live?

90 or above is an A — production ready. Blockers such as no working payment method, failing mail or an exposed .env cap the score at 74, 54 or 34, and one red row caps it at 88, so fix the red rows first. Run a Deeper check before you trust the number: certificate expiry is only checked there.

### Does it only tell me what is wrong, or can it fix it?

Both. The fix list tells you the exact change to make. For the command line, the included setup script can make the safe changes for you: it is a dry run by default, --check reports and --apply acts — and it asks before anything risky, even with --yes.

### I run SixPanel. Do I need to download this?

No. SixPanel includes it as the Shop check-up page. Settings the panel manages point to the panel page that owns them, because a value pasted in by hand there is lost at the next deploy.

### What PHP and database version should I actually install?

Ubuntu 26.04 LTS with what it ships: PHP 8.5 and MariaDB 11.8. PHP 8.3, 8.4 and 8.5 all run 6amMart at the same speed, and so do MariaDB 10.11 and 11.8. What matters is MariaDB over MySQL — MySQL does not run 6amMart without code changes.

### Can I plug the result into my own dashboard?

Yes. ?api=findings returns the last saved check as JSON over HTTP Basic auth, with a stable contract version. It never starts a scan, and the payload carries run.age_seconds so your dashboard can say “this reading is two weeks old” instead of presenting stale news as current.
