eCommerce penetration testing

Manual and technical testing on checkout, accounts, APIs, CMS, servers and critical flows

An eCommerce doesn't just have to protect the website: it has to protect orders, customers, payments, the catalogue and the integrations.

A penetration test simulates realistic attacks to find out what a malicious actor could genuinely do within the agreed limits of the scope.
Typical areas
  • Login, registration, password recovery and the customer area.
  • Cart, coupons, checkout, orders and returns.
  • APIs, webhooks, feeds, ERP and carrier integrations.
  • CMS, plugins, modules, admin panels and user roles.
  • Servers, configurations, permissions, headers and sessions.
What we look for
  • Unauthorised access to orders or customer data.
  • Bypassing prices, discounts, coupons or checkout rules.
  • Insecure uploads, injection, XSS, CSRF and IDOR.
  • APIs without consistent authorisation checks.
  • Weak server or CMS configurations.
Output
  • A report with severity, impact and reproduction steps.
  • Proof of concept where safe and agreed.
  • Remediation priorities.
  • A technical walkthrough session.
  • Retesting after the fixes, where included.

When it makes sense

A pen test is useful before a significant go-live, after a migration, after new APIs are developed, or when the site handles volumes, data or processes that would make an incident expensive.

If you just need a first picture of the risk, a website vulnerability assessment may be enough. If you need to verify concrete scenarios on accounts, checkout and APIs, a penetration test is the better fit.

FAQ

Can the test take the eCommerce down?

The scope exists precisely to avoid unnecessary impact. We agree the environment, time windows, limits and permitted actions before starting.

Do you need the source code?

Not always. We can work black-box, grey-box or white-box. The choice depends on the goal of the test.

Is it useful for PrestaShop or WooCommerce too?

Yes, especially where there are modules, plugins, customisations, APIs and customer areas holding sensitive data.

Let's define the pen test scope