Ecommerce security audit for stores beyond Shopify
WooCommerce, Magento, and custom-built carts each hand you plugins, extensions, and a self-hosted admin panel to secure yourself. A human engineer tests your checkout, cart, and order logic by hand and tells you exactly what to fix.
Shopify locks down the platform. Self-hosted ecommerce doesn’t.
The line between “handled for you” and “handled by you” moves
On Shopify, the core platform is PCI DSS Level 1 certified and hosted, so a huge chunk of the risk surface — infrastructure, payment processing, the base checkout — is already Shopify’s problem. WooCommerce, Magento, and a custom-built cart don’t come with that floor. The server, the admin panel, every plugin or extension you install, and the checkout logic you wrote or configured are all yours to secure, because there’s no platform underneath absorbing that responsibility.
That’s not a reason to avoid self-hosted ecommerce — it’s why so many stores run on it, for the control and customization it gives you. It does mean the audit has to cover more ground: the admin panel, the plugins, and the checkout and order logic end to end.
Why this matters more at checkout than almost anywhere else on your site
A broken contact form is embarrassing. A broken checkout is a direct path to money and customer data — which is exactly why checkout and order flows get disproportionate attention from anyone trying to break in, and why they deserve disproportionate attention from testing, too. A logic flaw in a checkout doesn’t need malware or a stolen password to matter; it just needs someone to notice the flaw and use it.
What we actually test on a self-hosted store
Every item below is tested by hand, not flagged by a scanner matching known signatures. Findings go into a written report with severity, evidence, and the exact fix — the same format shown on our sample report.
- Checkout and payment flow tampering — whether price, quantity, shipping cost, or item totals can be manipulated client-side before the order is submitted.
- Cart and order IDOR. Can one logged-in customer see or edit another customer’s order by changing an ID in the URL or an API call — one of the most common, most serious ecommerce findings.
- Coupon and discount abuse — codes that stack when they shouldn’t, negative percentages, client-side-only discount checks that can be skipped entirely.
- Admin panel exposure — WooCommerce/WordPress admin, Magento’s admin path, or a custom backend login, checked for default paths, weak protection and predictable credentials.
- Plugin and extension vulnerabilities — known CVEs, outdated versions, and permissions broader than what a plugin actually needs.
Bug Circuit doesn’t claim to be a PCI auditor and this isn’t a PCI-DSS assessment — but the logic flaws we test for sit right next to PCI’s concerns without being covered by them, which is why a manual audit is a reasonable, complementary step alongside whatever PCI compliance work your payment processor already requires.
What this costs, compared to what it usually costs
Agency-run ecommerce security audits commonly run from $8,000 to well over $60,000, typically starting with a scoping call, a proposal, and a multi-week wait before testing even begins. That pricing isn’t unreasonable for a large, custom enterprise engagement — but it puts a real audit out of reach for most small and mid-sized store owners, who end up either skipping it or settling for an automated scan that misses exactly the logic flaws above.
Start with a free passive check — no login, no card, no impact on your live store. The full manual audit, checkout to admin panel, is $49 one-time with a written report. If you’d rather have the team fix the high and critical issues with you, re-test, and watch the store for 3 months, that’s Signal at $299 — currently discounted roughly 55% as a launch offer. No quote calls, no scoping proposals.
Common questions
Do I need this if I’m already PCI-DSS compliant?
What’s the actual difference between this and your Shopify audit?
Can someone really see another customer’s orders on my store?
Do you test my payment processor or card data storage?
How is a manual audit different from running an automated scanner on my store?
What does it cost and how long does it take?
Do you need admin access to my store to run the audit?
Which platforms does this cover — WooCommerce, Magento, something custom?
Keep reading
Start with the free check
Passive recon on your store’s domain — no login, no charge, no impact on live orders.