Service
Ecommerce penetration testing for stores that take real orders
Ecommerce penetration testing focuses on the parts of a store that attackers target for money. So it covers checkout logic, customer accounts, admin access and integrations.
- Named tester before day one
- One retest within 30 days
- OWASP WSTG and NIST SP 800-115
Why ecommerce penetration testing needs its own focus
Online stores combine payments, personal data and promotions. Therefore business logic matters as much as technical flaws.
For example, a discount that stacks in an unintended way costs money without any classic vulnerability. Also, account takeover leads to fraud and support costs.
What ecommerce penetration testing examines
The test follows the money and the data. So it covers the full customer journey and the back office.
- Checkout and order logic, including discounts
- Customer account security
- Admin panel access and roles
- Payment page scripts and integrations
- Third-party plugins and apps
Ecommerce penetration testing readiness check
Tick what you can provide.
Your result appears here as you tick, so you can see what is still open.
Platforms and scope
Hosted platforms limit what you can test. However, your custom code, apps and configuration remain fair game with authorisation.
| Platform type | Typical scope |
|---|---|
| Hosted platform | Custom apps, theme code and configuration |
| Self-hosted store | Application, server and integrations |
| Headless storefront | Front end, APIs and checkout services |
Authorisation and compliance
Testing runs only under your written authorisation, and platform rules are checked first. Also, payment card requirements may ask for testing, so the report is written for assessors too.
Findings come with evidence and a fix. The OWASP Web Security Testing Guide frames the method.
Fees and timing
Stores are web applications, so most fall within our published web application range of $5,000 to $30,000. One retest within 30 days is included, and a named tester is confirmed before day one.
Also time the test well. Because stores often freeze changes before peak seasons, testing a few weeks earlier leaves room to fix findings. So book ahead of busy periods rather than during them. In addition, retest after major theme or app changes, because those often reopen closed issues.
Ecommerce penetration testing questions
Does ecommerce penetration testing cover the payment provider?
No. Your integration is tested, but the provider's platform is outside scope.
Can ecommerce penetration testing run on a hosted platform?
Yes, for your custom code and configuration, within the platform's rules.
What does ecommerce penetration testing cost?
Most stores fall within our web application range of $5,000 to $30,000.
Is a retest included?
Yes. One retest within 30 days is included.
Related guides
Scope your ecommerce penetration testing
Tell us about your platform, apps and checkout. We reply with a written estimate, usually within four working hours.
Get my estimate