Do I still need an external penetration test on top of this?

Yes, the audit and a pentest serve different purposes.

The audit (this tool): A self-assessment of 25 controls based on what you know about your environment. Catches policy + config gaps. Fast (5 min). Free. Repeatable quarterly.

A penetration test: An external party tries to actively exploit your environment using the same techniques as a real attacker. Catches implementation bugs the policy review can’t see. Slow (1-3 weeks). Costs $4k, $30k depending on scope. Done annually.

You need both because:

  • An audit might show "WAF active = Yes", but a pentest might find the WAF rules don’t catch obscure injection variants.
  • An audit might show "2FA enforced = Yes", but a pentest might find a forgotten /staging/ subdomain with a 2FA-bypassable admin.
  • An audit might show "TLS 1.2+ = Yes", but a pentest might find one legacy SOAP API endpoint still accepting TLS 1.0.

Compliance angle: PCI DSS v4 requires annual external + internal pentests for SAQ A-EP and SAQ D. SOC 2 Type II auditors expect to see a recent pentest report. ISO 27001 + NIST CSF reference one.

Sequencing: Run this audit + remediate everything you can, then commission the pentest. A pentest on a partially-fixed environment is money wasted on findings you already knew about.

For Magento-specific pentests, I work with two firms I trust (HackerOne-listed, Magento-experienced) and can refer. Or commission directly, ~$8k, $15k for a typical mid-market Magento scope.

Kishan Savaliya
Kishan Savaliya
Adobe Certified Magento Commerce Developer
Ahmedabad [IN]working hours, replies within four hours
When do you need it

Read personally. Never shared. Or email the brief.

More on magento security score checker

Need it fixed, not just explained?

Send the brief with your store URL; the written quote comes back within 24 hours.