Service — beyond Shopify

Ecommerce security audit for stores beyond Shopify

WooCommerce, Magento, and custom-built carts each hand you plugins, extensions, and a self-hosted admin panel to secure yourself. A human engineer tests your checkout, cart, and order logic by hand and tells you exactly what to fix.

A dedicated ecommerce security audit costs $49 for a one-time manual test at Bug Circuit — a human engineer checks checkout tampering, cart and order IDOR (one customer viewing another’s orders), coupon abuse, admin panel exposure, and plugin/extension vulnerabilities on WooCommerce, Magento, or a custom-built cart, then hands you a written report with severity, evidence, and exact fix steps. Agency-run ecommerce security audits commonly run from $8,000 to well over $60,000, usually with a quote call and a multi-week wait. Bug Circuit skips both.

Shopify locks down the platform. Self-hosted ecommerce doesn’t.

The line between “handled for you” and “handled by you” moves

On Shopify, the core platform is PCI DSS Level 1 certified and hosted, so a huge chunk of the risk surface — infrastructure, payment processing, the base checkout — is already Shopify’s problem. WooCommerce, Magento, and a custom-built cart don’t come with that floor. The server, the admin panel, every plugin or extension you install, and the checkout logic you wrote or configured are all yours to secure, because there’s no platform underneath absorbing that responsibility.

That’s not a reason to avoid self-hosted ecommerce — it’s why so many stores run on it, for the control and customization it gives you. It does mean the audit has to cover more ground: the admin panel, the plugins, and the checkout and order logic end to end.

Why this matters more at checkout than almost anywhere else on your site

A broken contact form is embarrassing. A broken checkout is a direct path to money and customer data — which is exactly why checkout and order flows get disproportionate attention from anyone trying to break in, and why they deserve disproportionate attention from testing, too. A logic flaw in a checkout doesn’t need malware or a stolen password to matter; it just needs someone to notice the flaw and use it.

What we actually test on a self-hosted store

Every item below is tested by hand, not flagged by a scanner matching known signatures. Findings go into a written report with severity, evidence, and the exact fix — the same format shown on our sample report.

  • Checkout and payment flow tampering — whether price, quantity, shipping cost, or item totals can be manipulated client-side before the order is submitted.
  • Cart and order IDOR. Can one logged-in customer see or edit another customer’s order by changing an ID in the URL or an API call — one of the most common, most serious ecommerce findings.
  • Coupon and discount abuse — codes that stack when they shouldn’t, negative percentages, client-side-only discount checks that can be skipped entirely.
  • Admin panel exposure — WooCommerce/WordPress admin, Magento’s admin path, or a custom backend login, checked for default paths, weak protection and predictable credentials.
  • Plugin and extension vulnerabilities — known CVEs, outdated versions, and permissions broader than what a plugin actually needs.

Bug Circuit doesn’t claim to be a PCI auditor and this isn’t a PCI-DSS assessment — but the logic flaws we test for sit right next to PCI’s concerns without being covered by them, which is why a manual audit is a reasonable, complementary step alongside whatever PCI compliance work your payment processor already requires.

What this costs, compared to what it usually costs

Agency-run ecommerce security audits commonly run from $8,000 to well over $60,000, typically starting with a scoping call, a proposal, and a multi-week wait before testing even begins. That pricing isn’t unreasonable for a large, custom enterprise engagement — but it puts a real audit out of reach for most small and mid-sized store owners, who end up either skipping it or settling for an automated scan that misses exactly the logic flaws above.

Start with a free passive check — no login, no card, no impact on your live store. The full manual audit, checkout to admin panel, is $49 one-time with a written report. If you’d rather have the team fix the high and critical issues with you, re-test, and watch the store for 3 months, that’s Signal at $299 — currently discounted roughly 55% as a launch offer. No quote calls, no scoping proposals.

Common questions

Do I need this if I’m already PCI-DSS compliant?
PCI-DSS compliance and a security audit answer different questions. PCI-DSS is mostly about how you handle and store card data — it doesn’t test whether a logged-in customer can pull up someone else’s order by changing a number in the URL, or whether your coupon logic can be abused for free stock. A manual audit is a reasonable complementary step alongside PCI work, not a replacement for it, and Bug Circuit doesn’t claim to be a PCI auditor or issue PCI attestations.
What’s the actual difference between this and your Shopify audit?
Shopify’s core platform is PCI DSS Level 1 certified and hosted, so a Shopify audit focuses on what merchants add on top — apps, theme code, staff access. WooCommerce, Magento, and custom carts are self-hosted, which means the platform itself, the server, the admin panel, and every plugin or extension are all in scope and are the merchant’s responsibility. This page covers that broader, self-hosted attack surface; see the Shopify audit if Shopify is your platform.
Can someone really see another customer’s orders on my store?
Yes — this is one of the most common findings we see on ecommerce sites, and it’s the exact issue shown in our sample report: an order API that returns whatever order ID is requested, without checking it belongs to the logged-in user. Incrementing a number in the address bar or an API call exposes every other customer’s name, address, and order contents. It’s a severe, GDPR-relevant bug and it’s trivial to test for by hand.
Do you test my payment processor or card data storage?
No. If you’re using Stripe, PayPal, Braintree, or a similar processor, the card-handling infrastructure is their responsibility and typically already PCI-certified — testing it isn’t useful and may be against their terms. What we do test is everything around it: whether your checkout logic can be tampered with, whether discount codes can be abused, and whether the order flow leaks other customers’ data.
How is a manual audit different from running an automated scanner on my store?
A scanner checks for known signatures and misconfigurations — it won’t notice that swapping an order ID in a URL returns someone else’s address, or that a coupon field accepts a negative percentage. Those are logic flaws, and finding them takes a person actually using your checkout the way a real attacker would, not a tool matching patterns. Every Bug Circuit audit is done by hand by a security engineer, then written up with evidence and exact fix steps.
What does it cost and how long does it take?
The passive check is free and takes seconds — no login, no card, no impact on your store. The full manual audit is $49 one-time with a written report typically back within a few business days. Signal, at $299 (currently discounted from launch pricing), adds the team fixing high/critical issues with you, a re-test, and 3 months of monitoring. Agency-run ecommerce audits elsewhere commonly run $8,000 to well over $60,000, usually behind a sales call — Bug Circuit’s pricing is posted and fixed.
Do you need admin access to my store to run the audit?
Not for the core audit — we test the storefront and checkout the way a customer or attacker would, without needing your keys. For a deeper look at plugin configuration, admin-panel hardening, or account permissions, a limited staff/collaborator login (never full owner access) lets us check further. Either way, testing only starts after you verify domain ownership and sign a recorded Authorization to Test.
Which platforms does this cover — WooCommerce, Magento, something custom?
This audit is scoped to WooCommerce, Magento, and custom-built carts and checkout flows — anything self-hosted where plugins, extensions, and the admin panel are your responsibility rather than a hosted platform’s. If your store runs on Shopify specifically, the merchant-side risk profile is different, so see the Shopify security audit for that.

Keep reading

Start with the free check

Passive recon on your store’s domain — no login, no charge, no impact on live orders.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →