Do you handle extension vulnerabilities?
Yes, third-party extensions are one of the most common entry points. Our extension & dependency CVE audit inventories every installed module and Composer package, cross-checks them against known CVEs and abandoned-package databases, and flags anything outdated, unmaintained or exploitable. We then patch, replace or sandbox the risky ones as part of the hardening engagement.