Home/Services/E-commerce & Retail Penetration Testing
security service

E-commerce & Retail Penetration Testing

E-commerce penetration testing across Europe: checkout, payment and Magecart risks tested by hand, mapped to PCI DSS 11.4. Fixed price, free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

E-commerce penetration testing is where security meets your revenue line: a broken checkout, a skimmer in your payment page, or a coupon that stacks to 100% off all hit the balance sheet directly. We test your storefront, checkout and payment paths by hand, the way a fraudster and a card-skimming crew actually work, and give you fixes that survive your next PCI review.

What e-commerce penetration testing actually covers

An online store is a chain of trust from the product page to the payment processor, and attackers go after the weakest link in that chain rather than the front door. Sometimes that is a classic web flaw. More often it is business logic: prices set from the client, discounts that stack, orders confirmed before payment clears, or a third-party script on the checkout page quietly reading card fields. The card data you never store can still be stolen in the browser.

Checkout and payment flow: price tampering, currency abuse and payment-bypass logic
Magecart and client-side skimming: third-party script integrity on payment pages
Coupon, voucher and loyalty logic: discount stacking, reuse and gift-card abuse
Account and order security: takeover, order enumeration and address or PII exposure
Platform and plugin review: Magento, WooCommerce, Shopify apps and custom extensions
Admin and fulfilment back office: privilege escalation and order-manipulation paths
APIs and headless storefronts: authorization on cart, order and customer endpoints

How we test an online store

Every engagement is manual, run by an OSCP or OSWE certified engineer who has tested storefronts and payment integrations before. Scanners are useful for mapping and for catching known-CVE plugin versions, but they cannot tell you that a shopper can change a €900 price to €9 in a request, or that a script on your checkout is sending card data to a domain you have never heard of. That judgement is the work.

Reconnaissance and mapping

We map the storefront, the checkout, the customer and admin areas, any headless or mobile API, and the full set of third-party scripts loaded on payment pages. Using Burp Suite, nmap and ffuf we enumerate endpoints and identify the platform and its extensions, flagging outdated Magento, WooCommerce or plugin versions with known vulnerabilities early.

Business-logic and checkout testing

Here we attack the buying flow as a fraudster would. We try to set prices and quantities from the client, apply and re-apply discount codes, stack vouchers with gift cards, change currency to gain a rounding advantage, and complete an order without a successful payment or after a cancelled one. We also test refund and store-credit paths, which are a favourite for turning a small flaw into real money out the door.

Payment-page and Magecart testing

Because client-side skimming is now the dominant way card data is stolen from retailers, we look hard at what runs on your checkout. We review every third-party script for integrity, test whether an attacker could inject or swap a script through a compromised tag manager or a vulnerable dependency, and check whether Subresource Integrity and a Content Security Policy are actually enforcing what loads. PCI DSS 4.0 now requires exactly this attention to payment-page scripts.

Exploitation, reporting and retest

When we find a way to buy for less than we should, take over an account, or exfiltrate card fields, we prove it with a working request set using test cards and test accounts only. You get the report within days, a live walkthrough, and a free retest after remediation.

48h
typical time to first critical findings
100%
manual verification, no raw scanner dumps
Free
retest after you remediate

Vulnerabilities we routinely find on e-commerce sites

Retail platforms tend to share the same weak spots, whether they run on Magento, WooCommerce, a Shopify app, or a custom headless build.

Price and cart manipulation

Prices, quantities, shipping costs and totals that are trusted from the client instead of recalculated on the server let a shopper decide what to pay. We test every field in the cart and checkout request for tampering, including negative quantities and rounding tricks that turn a large order into a small charge.

Magecart-style client-side skimming

A single malicious line of JavaScript on your checkout can copy every card number entered and ship it to an attacker, without ever touching your server or your logs, and it often sits in a script you did not write and do not monitor. We assess third-party script exposure, tag-manager access, dependency risk and CSP coverage, because this is the breach most likely to end in a PCI forensic investigation and card-brand fines.

Coupon, gift-card and refund abuse

Discount logic is deceptively hard to get right. We test whether codes can be reused, stacked, brute-forced, or applied to already-discounted items, whether gift-card balances can be checked or drained by enumeration, and whether refunds and store credit can be issued beyond what was paid.

Account takeover and order enumeration

Weak password resets, guessable order references, and endpoints that return another customer’s order by changing an ID expose personal data and shipping details at scale. We test authentication, session handling and object-level authorization across the customer account and order-history features.

Platform and plugin vulnerabilities

In most compromised stores we look at, the entry point was an out-of-date extension, not a novel exploit. We identify vulnerable plugins and themes, insecure custom code, and misconfigured admin panels, and we test the admin and fulfilment back office for privilege escalation and order manipulation.

API and headless storefront flaws

Headless and mobile commerce move the logic into APIs, where broken object-level authorization on cart, order and customer endpoints becomes the main risk. We test those endpoints for the same price, discount and data-exposure issues as the web checkout, plus mass assignment and over-shared responses.

Automated fraud and abuse exposure

Beyond individual bugs, we look at how well the store resists automation: credential stuffing against the login, card-testing against the payment endpoint, and bots that hoard limited stock at drop time. Missing rate limits, weak bot defences and unthrottled gift-card checks turn an ordinary flaw into a scalable loss, so we flag where a single request becomes ten thousand.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Compliance, PCI DSS and e-commerce security best practices

If you take card payments, security is not optional, and a penetration test is often a written requirement rather than a nice-to-have. We align the work to the standards your acquiring bank and your customers expect.

PCI DSS 4.0

PCI DSS requirement 11.4 calls for regular penetration testing of the systems in and connected to your cardholder data environment, and the 4.0 revision adds specific requirements around managing and monitoring the scripts on your payment pages, aimed squarely at Magecart. Our report and attestation letter are written to support your PCI assessment and to give your QSA the evidence they need.

Data protection and secure baselines

Customer names, addresses and order histories are personal data, so we test with GDPR in mind, and we measure the application against OWASP ASVS and the OWASP Top 10. For mobile shopping apps we use OWASP MASVS. Beyond the test, we give you practical e-commerce security best practices your team can adopt: enforce server-side pricing, lock down payment-page scripts with SRI and CSP, patch extensions on a schedule, and separate admin access from the public store.

What you get from the engagement

A report your QSA accepts and your developers can act on immediately.

  • An executive summary for leadership, your bank and your compliance owner
  • A technical report with each finding scored by CVSS, ranked by revenue and data impact, and paired with exact reproduction steps
  • Specific remediation guidance mapped to your platform, whether Magento, WooCommerce, Shopify or custom
  • An attestation letter to support PCI DSS 11.4 and customer or partner reviews
  • A live results walkthrough with your engineering and operations teams
  • A free retest once you have remediated, confirming the fixes hold

Everything is delivered under NDA, and any data we touch is handled securely and destroyed on request.

Why manual testing beats a scanner here

A scanner can tell you a plugin is out of date. It cannot buy a product for a euro, cannot notice that a script on your checkout is exfiltrating card fields, and cannot reason about whether three valid coupons should combine into a free order. Those are the flaws that actually cost retailers money and trigger PCI investigations, and every one of them needs a person who understands how a store makes money and how a fraudster unmakes it. We shop your site the way an attacker does, chain a client-side price change into a completed order, and hand you the exact request and the server-side fix that ends it. On a store, that difference is measured directly in euros kept rather than lost.

Pricing

Pricing depends on scope: catalogue and checkout complexity, how many payment and shipping integrations, and whether the admin, API and mobile app are in scope. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Essential Single storefront and checkout, one payment provider, customer account, checkout logic and payment-page script review, full report and free retest 4–6 working days from €2,500
Standard Store plus admin back office, multiple payment and shipping integrations, coupon and refund logic, and the customer or order API 7–10 working days €4,500–€9,000
Advanced Multi-store or headless commerce, complex promotions, marketplace or multi-vendor logic, and attack-chaining across web, API and admin 10–15 working days €9,000–€20,000
Compliance add-on Mapping and attestation for PCI DSS 11.4, GDPR or ISO 27001, aligned to your QSA with any tier from €800
Custom / large estate Several brands or storefronts, or a full retail estate, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call — no hourly surprises, and a retest is included. Get a fixed quote

FAQ

How much does e-commerce penetration testing cost?
E-commerce penetration testing cost starts from €2,500 for a single storefront and checkout, and scales with the number of integrations, the admin back office, and any API or mobile app in scope. You get a fixed price after a free scoping call.
How long does an e-commerce penetration test take?
A focused storefront test runs about 4–6 working days plus the report, while a larger multi-store or headless build is usually 7–15 days. If we find a payment-bypass or skimming issue, you hear about it the same day.
Do you test for Magecart and payment-page skimming?
Yes. We review every third-party script on your checkout, test whether one could be injected or swapped through your tag manager or a vulnerable dependency, and check that Subresource Integrity and a Content Security Policy actually enforce what loads, which is exactly what PCI DSS 4.0 now requires.
Will this satisfy PCI DSS requirements?
Yes. PCI DSS 11.4 calls for regular penetration testing of your cardholder data environment, and our report and attestation letter are written to give your QSA the evidence they need, including the new payment-page script requirements.
Can you test on Magento, WooCommerce or Shopify?
All of them, plus custom and headless builds. We identify vulnerable extensions and themes, test custom code and admin configuration, and check the checkout and API logic regardless of the underlying platform.
Will the test disrupt live sales?
No. We prefer a staging copy with test payment credentials, agree any noisy checks in advance, and can run intrusive steps out of peak trading hours. Your storefront availability is never the price of finding a flaw.
What e-commerce security best practices will you recommend?
Alongside the findings you get practical guidance: enforce all pricing and discounts server-side, lock down payment-page scripts with SRI and CSP, patch platform and plugins on a schedule, restrict and monitor admin access, and rate-limit account and order endpoints.
Is everything kept confidential?
Every engagement runs under NDA. Test data and findings are handled securely, shared only with the people you name, and destroyed on request.

Related services

Who needs this

Online retailers, marketplaces and DTC brands taking card payments, preparing for a PCI DSS assessment, replatforming, or worried about checkout skimming and discount fraud eating into margin.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "E-commerce & Retail Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.