Manual testing — not a scanner

Shopify security audit by a human.

Shopify's platform is PCI-certified and locked down — but everything you add on top (apps, theme code, staff accounts) is on you. We audit that layer by hand and tell you exactly what to fix.

What does a Shopify security audit cost? A free passive critical-bug check (no login required), a $49 one-time full manual audit with a written report, or $299 for the audit plus fixes and 3 months of cover — the same transparent pricing as every Bug Circuit audit.

Shopify secures the platform. You're responsible for what runs on it.

Shopify is a PCI DSS Level 1 certified platform — hosting, checkout infrastructure and card data are locked down and Shopify’s responsibility, not yours. That’s genuinely strong, and it’s why we don’t test it: it’s already covered, and probing it would be against Shopify’s terms.

What Shopify’s certification does not cover is everything a merchant adds on top: installed apps (often with broad permissions to customer data and orders), custom theme code, staff account security, and any checkout customizations. That merchant-side layer is exactly where real incidents happen — and exactly what this audit tests.

What's already covered by Shopify vs. what your audit covers
Shopify (the platform)Your Shopify audit
Payment processing & PCICertified, Shopify’s responsibilityNot re-tested — already covered
Core hosting & infrastructureManaged and secured by ShopifyNot re-tested — already covered
Installed appsNot covered by ShopifyPermissions and exposure reviewed
Theme code (Liquid & JS)Not covered by ShopifyReviewed for exposed secrets & insecure logic
Staff accounts & 2FANot covered by ShopifyChecked, hardening recommended
DNS & email authenticationNot covered by ShopifySPF / DKIM / DMARC checked

What we actually test

  • Installed-app permissions — what data and functionality each app can access, and whether that scope matches what the app actually needs to do.
  • Theme code — Liquid templates and storefront JavaScript checked for exposed API keys or secrets, insecure client-side logic, and injected/unvetted third-party scripts.
  • Staff account security — who has access, whether 2FA is enforced, and whether permissions are scoped to what each person actually needs.
  • DNS & email authentication — SPF, DKIM and DMARC, so your domain can’t be easily spoofed for phishing.
  • Security headers — CSP, frame protection and cookie flags on your storefront.
  • Checkout customizations — for Shopify Plus stores using checkout extensibility, reviewed for the same class of logic flaws we check on any custom checkout flow.

Every finding is verified by hand before it goes in the report. Testing only begins after you verify store/domain ownership and we record an Authorization to Test — we never touch a store we haven’t been authorized to test.

Common questions

Is Shopify already PCI compliant, so why would I need an audit?
Shopify's platform is PCI DSS Level 1 certified, so payment processing and card data are Shopify's responsibility, not yours. What isn't automatically covered is everything you add on top of the platform: installed apps, custom theme code, staff accounts, and checkout customizations. That gap between what Shopify secures and what you're responsible for is exactly what this audit targets.
What exactly do you test on a Shopify store?
Your theme code (Liquid templates and storefront JavaScript) for exposed secrets and insecure client-side logic, installed-app permissions and exposed API scopes, staff account security and 2FA, DNS and email authentication (SPF, DKIM, DMARC), and security headers. We don't test Shopify's own infrastructure or payment processing — that's already covered by their PCI certification, and testing it would be against Shopify's terms.
Do you need my Shopify admin login?
Not for the core audit — we test what is publicly visible, the way a customer or attacker would. For a deeper look at installed apps and staff permissions, a limited collaborator or staff account (never full owner access) lets us check configuration without us ever holding the keys to your store.
Can a vulnerable app really put my store at risk?
Yes. Installed apps often request broad permissions — customer data, order history, discount codes, sometimes checkout access — and a compromised or poorly-secured app is a common way stores get hit, since the same app runs on many stores at once. We review what your installed apps can actually access and flag anything overpermissioned for what it does.
Is this different from your WordPress audit?
Yes — the platforms have different attack surfaces. WordPress exposes plugins, themes and a self-hosted admin panel; Shopify's core is hosted and PCI-certified, so the merchant-side risk shifts to installed apps, theme code and staff access instead. Same human-testing approach, same $49/$299 pricing, scoped to what actually matters on each platform.
What does it cost?
A yes/no critical-bug check is free. The full manual audit with a written report is $49 one-time. Audit plus fixes plus 3 months of monitoring is $299 — transparent pricing, no quote calls.

Keep reading

Start with the free check

Passive recon on your Shopify domain — no login, no charge, no impact on your store.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →