Magento Security: 12 questions answered.
Frequently asked questions about Magento security audits, hardening, APSB patches, penetration testing and PCI-DSS compliance.
Do you handle extension vulnerabilities?
Yes, third-party extensions are one of the most common entry points. Our extension & dependency CVE audit inventories every installed module and Composer package, cross-checks them against known CVEs and abandoned-package databases, and flags anything outdated, unmaintained or exploitable. We then patch, replace or sandbox the risky ones as part of the hardening engagement.
How do you harden the Magento admin?
The admin panel is the most-attacked surface on any store. We harden it with: two-factor authentication (2FA) enforced for all users, a custom admin path (no default /admin), brute-force lockout and rate-limiting, IP allow-listing where practical, removal of stale accounts, and least-privilege role review. Combined, these close the credential-stuffing and brute-force routes that account for most admin compromises.
Will hardening slow my site down?
No, done right, hardening is performance-neutral and often a net win. Security headers (CSP, HSTS), 2FA and a custom admin path add no measurable front-end cost. A well-tuned WAF and bot protection actually reduce server load by filtering malicious traffic before it hits PHP. We benchmark Core Web Vitals before and after so you can see there’s no regression.
Do you offer ongoing managed security?
Yes, the Managed Security retainer provides continuous cover: we monitor every new APSB bulletin and apply patches as they land, run scheduled quarterly re-audits, maintain your PCI-DSS readiness documentation, and give you an emergency-fix fast lane for zero-day patches. You also get a dedicated security contact and a monthly status report. Pricing is custom, scoped to your stack and traffic.
Is my Magento store PCI compliant?
It depends on how you handle card data. Stores using a hosted/off-site gateway (Stripe, Adyen, PayPal redirect) have a smaller PCI-DSS scope than those capturing card details on-site. Our PCI-DSS v4.0 readiness review maps your setup to the relevant requirements, secure configuration, access control, logging, patching, encryption, and gives you a clear list of what passes today and what needs remediation before your next assessment.
Do you do Magento penetration testing?
Yes. Our audit includes Magento penetration testing built on the OWASP methodology, we actively probe the storefront, admin and REST/GraphQL APIs for injection, broken authentication, access-control flaws and misconfigurations, not just run an automated scanner. Testing is scoped and authorised in writing first (rules of engagement), and runs against staging where possible to avoid disrupting live traffic.
How much does a Magento security audit cost?
Fixed-price tiers, billed at $25/hr:
- Security Audit: $499 (~20h), OWASP-based audit, CVE scan, APSB gap analysis and a prioritised written report
- Audit + Hardening: $999 (~40h), everything in the audit, plus all missing patches applied, admin hardening, header/server hardening, WAF + bot protection and a re-scan
- Managed Security: custom retainer, continuous patch monitoring, quarterly re-audits and an emergency fast lane
Anything out of scope after the audit is quoted upfront, never billed silently.
What does a Magento security audit cover?
A full Magento security audit covers four layers: (1) the application, OWASP Top 10 testing of the storefront, admin and APIs (XSS, SQL injection, CSRF, broken access control); (2) patches, an APSB security patch gap analysis against your exact version; (3) dependencies, a CVE audit of every third-party extension and Composer package; and (4) infrastructure, HTTP headers, server config and admin exposure. You get a single prioritised report at the end.
How long does a Magento security audit take?
A standard audit (~20 hours) typically runs over 3-4 business days: scope on day one, scanning and manual OWASP testing over days one to three, and the written report on day four. Audit + hardening (~40 hours) adds roughly four to five more days for applying patches, admin hardening and the verification re-scan. Emergency engagements for suspected compromises can start same-day on the Managed Security retainer.
Are my Magento security patches up to date?
Most stores aren’t, and the gap is invisible until something breaks. Adobe ships security patches on a rolling schedule (APSB bulletins), and applying a patch is separate from upgrading the platform. Our audit runs a security patch gap analysis that compares your installed version and applied hotfixes against the full APSB list, then flags every missing fix by severity so you can see your exposure window at a glance.
Do you provide a written security report?
Always. Every audit ends with a prioritised written report: each finding rated by severity and exploitability, with reproduction notes, the affected component, and a clear, costed remediation step. Hardening engagements also include a before/after report from the verification re-scan, so you have documented proof every finding was closed, useful for stakeholders, insurers and PCI assessors.
What is an APSB security patch?
APSB stands for Adobe Product Security Bulletin, the official advisories Adobe publishes for Magento / Adobe Commerce vulnerabilities (for example APSB26-49). Each bulletin lists the affected versions, severity, CVE IDs and the patch or version that fixes it. A Magento security patch closes one or more of these CVEs. Keeping current with APSB releases is the single most important thing you can do to stay safe; our hardening service applies every missing one.
Not answered above?
Send the question as a brief; the answer comes back in writing within 24 hours, with a quote if it needs work.