Overview
Engagements cover marketplaces and multi-vendor platforms, direct-to-consumer storefronts on Shopify, Magento and WooCommerce, subscription and loyalty products, and the fulfilment and logistics systems behind them.
Platform core is reviewed for known issues and configuration weaknesses, but the exploitable findings are almost always in the customisations: the theme, the apps, the custom checkout step, the integration written under deadline. Business logic is the dominant finding category here: nothing is malformed, every request is valid, and the platform still loses money on each one.
What drives testing in this sector
Buying triggers
- Direct revenue leakage
- Discount and refund abuse is continuous, quiet, and usually discovered by accounting rather than security.
- PCI DSS obligations
- Any platform touching card data inherits testing requirements, including client-side script integrity for payment pages.
- Client-side skimming
- Magecart-style attacks target the browser, not the server, which is why third-party script inventory belongs in scope.
Where the engagement concentrates
Checkout and pricing logic
Price, quantity, currency, tax and shipping tampering at every step, including values that are recalculated server-side only sometimes.
Coupon, loyalty and referral abuse
Stacking, reuse, race conditions on single-use codes, self-referral loops and points arbitrage.
Account takeover paths
Credential stuffing resistance, password reset lifecycle, guest-to-registered account merging, and order history exposure by identifier.
Payment integration
Callback and webhook verification, amount tampering between the order and the processor, and orders that complete on an unverified success signal.
Client-side integrity
Third-party scripts on payment pages, tag manager access, subresource integrity and content security policy enforcement.
Inventory and fulfilment logic
Overselling races, reservation abuse, address and delivery manipulation, and returns processed before goods are received.
Track record
E-commerce and marketplace engagements consistently produce business-logic findings as the highest-value category, the kind a scanner cannot express because nothing is technically malformed.
200+ projects delivered for 80+ organisations. Internal engagement log
Questions
Will testing create fake orders in our system?
Test orders are confined to accounts created for the engagement and tagged with an agreed marker, and a cleanup list is delivered with the report. Where a sandbox is available it is used in preference.
Do you test our Shopify, Magento or WooCommerce build?
Yes. Platform core is reviewed for known issues and configuration weaknesses, and the engagement then concentrates on your customisations, themes, apps and integrations, which is where the exploitable findings almost always are.
How do you test for skimming exposure?
Every third-party script on payment pages is inventoried, along with what it can reach, who can change it, and whether content security policy and subresource integrity would stop a modified script from executing.
How much does a penetration test cost for an e-commerce platform?
Cost follows scope: storefront, checkout, account area, APIs and any third-party integrations. Checkout and promotion logic usually carry the highest value per hour because that is where findings convert directly into money.
What do you find most often in e-commerce?
Promotion and pricing logic. Discount codes that stack when they should not, coupons that survive a cancelled order, and refund flows that credit before they verify. Nothing is malformed and nothing alerts; it simply shows up in the margin.
Do you test third-party scripts and tag managers?
Yes. Payment page skimming almost always arrives through a script you did not write, and the question is whether content security policy and subresource integrity would stop a modified script from executing. Usually the policy exists and would not.
Can you test during peak trading season?
We would rather not, and will say so. Testing is scheduled around your peak rather than into it, with windows agreed in writing. Where a deadline forces it, scope is narrowed to low-risk techniques and every request is logged for traceability.
Do you test mobile apps and marketplace integrations?
Yes, where they are in scope. Marketplace and fulfilment integrations carry credentials that reach order and customer data, and they are frequently outside the boundary anyone thought to test.