Run a safe and responsible WhatsApp group directory

A link directory sits between people who share links and people who join them. That makes you responsible for more than uptime: your visitors trust you not to send them into scams, and your admin panel holds your members' data. These are the habits of directories that last.

Protect your visitors

  • Keep the leaving page on. A short countdown with a safety notice — never share OTPs, never pay strangers — prevents real harm. You can edit the notice under Directory settings.
  • Moderate before publishing, at least for guests. Scams look obvious to a moderator and convincing to a newcomer.
  • Use reports. Let guests report links and hide a link automatically after a few open reports.
  • Separate adult content. Mark categories and links as 18+ and keep them off the public site unless your directory is meant for adults and your local law allows it.
  • Act on removal requests quickly. "I own this and want it removed" is one of the report reasons for a reason.

Respect the platforms

WAGroups is an independent product and is not affiliated with WhatsApp or Meta. It lists links that people choose to share publicly and reads only the public preview page of each link. Do not present your directory as an official WhatsApp service, avoid WhatsApp's logo in your branding, and show the disclaimer in your footer — WAGroups includes one you can edit.

Protect your admin panel

  • Strong, unique passwords for every admin and staff account, and staff permissions limited to what each person needs.
  • Captcha on login, registration, password reset, submit and contact forms.
  • Login lock-out after repeated failed attempts is built in.
  • Keep WAGroups updated. Updates fix issues as soon as they are found; download them from your client area.
  • HTTPS everywhere, with a free certificate from your host.

Protect your data

  • Back up your database and the public/uploads folder regularly — most cPanel hosts offer automatic backups.
  • Never share your .env file. It holds your database password and application key. The bundled .htaccess blocks it from the web; keep that file in place.
  • Collect only what you need. Submitter emails are optional, and guest emails and IP addresses are never shown to the public.

Publish your policies

Use the Pages extension for clear rules: what may be listed, how to report or remove a link, and a privacy policy that explains what you store. Link them in your footer. Clear rules make moderation decisions easy to explain — and easy to defend.

0 comments

Leave a comment

Not shown publicly.
Chat with us
Hi! Send us a message and we will reply here as soon as we can.