Platform guide
Magento security scanner
Magento stores are usually self-hosted, which puts the server configuration in your hands, and that is where many findings come from. SecurityScan checks the storefront from outside: TLS, response headers, reachable files, server banners, JavaScript libraries and cookie consent.
What the scan checks
Security headers
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
Exposed files and server settings
Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.
SSL/TLS certificate
A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.
Outdated JavaScript
Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.
Cookies before consent
Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.
Where Magento findings usually come from
Security headers
Headers such as HSTS, Content-Security-Policy and Referrer-Policy are set in Nginx, Apache or a proxy in front of Magento. Magento 2’s CSP module runs in report-only mode on the storefront by default, and a report-only policy blocks nothing, so the scan reports Content-Security-Policy as missing.
Files reachable from the web
Repository and deployment files such as .git/config, composer.json, .env or error logs sometimes end up reachable. Serving Magento 2 from the project root instead of the pub/ folder is a common cause. The scan requests a fixed list of such paths and reports any that answer.
Version-revealing headers
Server and X-Powered-By headers that include software versions, which tell an attacker exactly what to look up.
Extensions and themes with old JavaScript
Third-party extensions and themes can bundle older libraries. The scan compares the versions the storefront loads with versions that have known vulnerabilities.
How the scan recognises Magento
The scan recognises Magento from its cookies, such as mage-cache-storage, its JavaScript objects and its static asset paths. Recognition is informational: the checks are the same on every site, and the platform never changes the score.
Keeping it fixed
Deployments, extension installs and server changes can each undo a fix. With a plan, the store is re-scanned automatically and the report is emailed to you.
Questions
- Does it work on Magento 1 and Magento 2?
- Yes. The checks look at what the storefront serves, so they work on any version.
- Does it test the admin panel?
- No. It only looks at public pages. It does not look for the admin URL or try to log in.
- Is this a full penetration test?
- No. It is an external check of configuration and known issues, with no attack payloads. It is a baseline you can keep monitoring, not a replacement for a pentest.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.