BIT403 E Commerce

E CommerceUnit 1012 min read

E-Commerce Website Development & Deployment: Tech Stack, CMS, SEO, Security & Hosting

Unit 10 of E-Commerce covers the technical and operational aspects of building, deploying, and optimizing e-commerce websites, including CMS selection, frontend/backend architecture, security integration, SEO best practices, and hosting solutions.

TAKEAWAYS:

  • Tech Stack Matters: E-commerce websites rely on a layered architecture (frontend, backend, database, hosting) with tools like WordPress + WooCommerce, Magento, or Shopify for scalability.
  • CMS Choices: Open-source (WordPress, Drupal) vs. proprietary (Shopify, BigCommerce) systems differ in cost, customization, and maintenance—pick based on budget and technical expertise.
  • SEO is Non-Negotiable: On-page SEO (meta tags, URL structure, mobile-friendliness) and off-page (backlinks, social signals) directly impact rankings and sales.
  • Security is Layered: Protect against SQL injection, XSS, DDoS, and payment fraud using HTTPS, firewalls, PCI-DSS compliance, and regular audits.
  • Hosting Decisions: Shared hosting (cheap, limited), VPS (flexible), or cloud (scalable) must align with traffic, budget, and uptime needs.
  • Deployment Pipeline: Follow Agile/DevOps practices (CI/CD, testing, staging) to ensure smooth launches and updates.

1. E-Commerce Website Architecture: The Backbone

E-commerce websites are multi-layered systems combining frontend (user interface), backend (server logic), database (product/data storage), and hosting (infrastructure). The architecture determines performance, security, and scalability.

Key Components

Database Queries → Database (MySQL, MongoDB, PostgreSQL)Static Files → CDN (Cloudflare, Akamai)Backend: Server (Node.js, PHP, Python)API Calls → BackendFrontend: HTML/CSS/JSSecurity: Firewall, SSL, PCI-DSSHosting: Server (Shared/VPS/Cloud)User (Browser)
Simplified e-commerce architecture hierarchy (real components)
  • Frontend: What users see (e.g., product pages, checkout). Built with React, Vue.js, or WordPress themes.
  • Backend: Handles logic (e.g., inventory updates, payments). Uses Node.js, Django, Laravel, or Magento.
  • Database: Stores products, user data, orders. MySQL (relational) or MongoDB (NoSQL) are common.
  • Hosting: Where the site lives. Options range from shared hosting (cheap, limited) to cloud (AWS, Google Cloud) for scalability.
015304560Shared Hosting10VPS Hosting30Cloud Hosting (AWS/Azure)60
Cost vs. Scalability for Nepali e-commerce startups (sample data)

Real-World Example: Daraz’s Architecture

Daraz (Alibaba’s Nepalese platform) uses:

  • Frontend: React-based for fast, responsive UI.
  • Backend: Microservices (Python/Node.js) for scalability.
  • Database: Hybrid (MySQL for transactions, Redis for caching).
  • Hosting: Cloud-based (AWS) to handle peak traffic during sales (e.g., Daraz Great Republic Day Sale).
  • Security: PCI-DSS compliant for payments, DDoS protection during high traffic.
2012Launched in Nepal(Alibaba-backed)2015Migrated to AWSfor scalability2020ImplementedPCI-DSS Level 1 compli
Key milestones in Daraz Nepal’s tech evolution

2. Choosing a Content Management System (CMS)

A CMS simplifies website management without deep coding. For e-commerce, options vary by cost, customization, and ease of use.

CMS Type Pros Cons Best For
WordPress + WooCommerce Open-source Free, huge plugin ecosystem, easy to use Slower with large catalogs, less secure by default Small to medium stores, blogs
Magento (Adobe Commerce) Open-source/Enterprise Highly customizable, scalable Steep learning curve, expensive hosting Large enterprises (e.g., Nepal’s Ncell e-store)
Shopify Proprietary All-in-one, secure, easy setup Monthly fees, transaction charges Startups, small businesses
PrestaShop Open-source Lightweight, good for SMEs Smaller community than WordPress European/Nepalese SMEs (e.g., local handicraft stores)
BigCommerce Proprietary Built-in SEO, no transaction fees Less flexible than Magento Mid-sized stores with global reach

How to Pick?

  • Budget: Free (WordPress) vs. paid (Shopify: ~$29/month).
  • Technical Skills: Need developers? Magento. No-code? Shopify.
  • Scalability: Expect 10K+ visitors? Avoid shared hosting with WordPress.
  • Features: Need multi-language? PrestaShop or Magento.

3. On-Page SEO for E-Commerce: Ranking and Revenue

SEO drives organic traffic, which converts to sales. For e-commerce, focus on:

  1. Technical SEO: Site speed, mobile-friendliness, SSL.
  2. Content SEO: Product descriptions, blog posts.
  3. Structural SEO: URL structure, schema markup.

Step-by-Step On-Page SEO for an E-Commerce Site

Worked Example: Optimizing a Kathmandu Thamel Store’s Website

Problem: A local souvenir shop’s website ranks poorly for "Kathmandu souvenirs." Solution:

  1. Keyword Optimization:
    • Target long-tail keywords: "handmade Kathmandu souvenirs for tourists."
    • Add to product titles/descriptions (e.g., "Thangka Painting – Authentic Nepalese Art for Tourists").
  2. URL Structure:
    • Bad: website.com/product?id=123
    • Good: website.com/kathmandu-thangka-painting-nepalese-art
  3. Schema Markup:
    {
      "@context": "https://schema.org",
      "@type": "Product",
      "name": "Thangka Painting",
      "image": "thangka.jpg",
      "description": "Handcrafted Nepalese Thangka for meditation.",
      "offers": {
        "priceCurrency": "NPR",
        "price": "5000"
      }
    }
    
  4. Mobile-Friendliness:
    • Use Google’s Mobile-Friendly Test to fix issues (e.g., tiny buttons).
  5. Internal Links:
    • Link from a blog post "Top 10 Kathmandu Souvenirs" to the product page.

Result: 30% increase in organic traffic in 3 months.


4. Security Threats and Protections

E-commerce security is critical to protect customer data and transactions. Common threats:

Threat How It Works Protection
SQL Injection Hacker inserts malicious SQL code Use prepared statements, input validation
Cross-Site Scripting (XSS) Injects malicious scripts into web pages Sanitize user inputs, use Content Security Policy (CSP)
Phishing Fake emails/websites to steal credentials Multi-factor authentication (MFA), employee training
DDoS Attacks Overwhelms site with traffic Cloudflare, AWS Shield
Payment Fraud Stolen credit cards PCI-DSS compliance, 3D Secure (3DS)

Real-World Example: Khalti’s Security Measures

Khalti (Nepal’s leading digital wallet) protects transactions with:

  • PCI-DSS Level 1 Compliance: Highest security standard for payments.
  • Tokenization: Replaces card details with tokens to prevent theft.
  • Biometric Authentication: Fingerprint/Face ID for high-value transactions.
  • Real-Time Fraud Detection: AI flags suspicious activities (e.g., sudden large transactions).

5. Hosting and Deployment: Where and How to Launch

Choosing the right hosting affects speed, security, and cost. Options:

Hosting Type Pros Cons Example Providers
Shared Hosting Cheap (~$3/month) Slow, limited resources Hostinger, Bluehost
VPS (Virtual Private Server) More control, scalable Requires technical knowledge DigitalOcean, Linode
Cloud Hosting High scalability, pay-as-you-go Expensive for small sites AWS, Google Cloud, Azure
Dedicated Server Full control, highest performance Very expensive (~$100+/month) Liquid Web

Deployment Pipeline: From Code to Live Site

sequenceDiagram
    participant Developer
    participant GitHub
    participant CI/CD
    participant Staging
    participant Production

    Developer->>GitHub: Push code
    GitHub->>CI/CD: Trigger build/test
    CI/CD->>Staging: Deploy to staging server
    CI/CD->>CI/CD: Run automated tests
    CI/CD->>Production: Deploy if tests pass
    Production->>Users: Live site update

Example: eSewa’s Deployment

  • Uses AWS for cloud hosting.
  • CI/CD Pipeline: Automated testing before every update to prevent downtime.
  • Blue-Green Deployment: Reduces risk by running new versions alongside old ones.

6. Post-Launch: Maintenance and Scaling

A live e-commerce site needs continuous optimization:

  • Performance: Use CDNs (Cloudflare), optimize images, enable caching.
  • Security: Regular penetration testing, update plugins (e.g., WordPress vulnerabilities).
  • Analytics: Track Google Analytics, Heatmaps (Hotjar) to improve UX.
  • Scaling: Upgrade hosting (e.g., from shared to VPS) as traffic grows.

Real-World Example: NEPSE’s Website During IPO Rush

During high-traffic events (e.g., NEPSE IPO openings), their site:

  • Uses cloud auto-scaling to handle 10x traffic.
  • Implements rate limiting to prevent abuse.
  • Monitors server response times in real-time.

In the Real World

  1. Khalti’s Payment Gateway

    • Idea Used: PCI-DSS Compliance + Tokenization
    • How: When you pay via Khalti for a Daraz order, your card details are never stored on their servers. Instead, a token (a random string) is used for future transactions, reducing fraud risk.
  2. Daraz’s Mobile App (React Native)

    • Idea Used: Cross-Platform Development + Microservices
    • How: Daraz’s app works on both Android and iOS using React Native. The backend uses microservices (separate services for inventory, payments, user profiles) to handle 1M+ daily orders efficiently.
  3. Ncell’s E-Commerce Store

    • Idea Used: Magento + PCI-DSS Security
    • How: Ncell’s online store uses Magento for its large product catalog (phones, accessories). Security includes 3D Secure payments and DDoS protection to handle traffic spikes during promotions.
  4. Pathao’s Driver App (Real-Time Tracking)

    • Idea Used: WebSockets + Real-Time Database (Firebase)
    • How: When you book a ride, Pathao’s app uses WebSockets to push live driver locations to your phone instantly, without refreshing. The backend relies on Firebase for real-time updates.

Exam Tip

  1. For Short Questions (2-5 marks):

    • Define terms precisely (e.g., "PCI-DSS compliance" = "Payment Card Industry Data Security Standard").
    • Compare two CMS (e.g., WordPress vs. Shopify) in a bullet-point table.
    • List 3 security threats and their solutions.
  2. For Long Questions (10-15 marks):

    • Structure your answer like this:
      1. Introduction: Briefly define the topic (e.g., "E-commerce website deployment involves...").
      2. Step-by-Step Process: Use a flowchart (like the deployment pipeline above).
      3. Real-World Example: Tie to a Nepalese company (e.g., "Like Daraz, a scalable site uses...").
      4. Pros/Cons: Discuss trade-offs (e.g., "Shared hosting is cheap but slow").
    • Diagrams are worth marks: Always draw a tech stack diagram or SEO checklist if asked about architecture or optimization.
  3. Common Pitfalls:

    • Vague answers: Avoid "SEO is important" without explaining how (e.g., meta tags, backlinks).
    • Ignoring security: Always mention PCI-DSS for payments and HTTPS for data protection.
    • Overlooking hosting: Compare shared vs. cloud hosting in deployment questions.

Quick Revision Checklist

Before exams, ensure you can: ✅ Draw the e-commerce website architecture (frontend/backend/database/hosting). ✅ Compare 3 CMS platforms (WordPress, Shopify, Magento) in a table. ✅ List 5 on-page SEO techniques with examples. ✅ Explain 3 security threats and their fixes (e.g., SQL injection → prepared statements). ✅ Describe how Daraz or Khalti implements a specific concept (e.g., tokenization, microservices). ✅ Outline the steps to deploy an e-commerce site (GitHub → CI/CD → Staging → Production).

Based on the TU BIT syllabus for E Commerce (BIT403), unit 10.

Discussion

Loading…