Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Ecommerce penetration testing for stores that take real orders

Ecommerce penetration testing focuses on the parts of a store that attackers target for money. So it covers checkout logic, customer accounts, admin access and integrations.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Ecommerce penetration testing: agree the scope, test the store and report and retest

Why ecommerce penetration testing needs its own focus

Online stores combine payments, personal data and promotions. Therefore business logic matters as much as technical flaws.

For example, a discount that stacks in an unintended way costs money without any classic vulnerability. Also, account takeover leads to fraud and support costs.

What ecommerce penetration testing examines

The test follows the money and the data. So it covers the full customer journey and the back office.

  • Checkout and order logic, including discounts
  • Customer account security
  • Admin panel access and roles
  • Payment page scripts and integrations
  • Third-party plugins and apps

Ecommerce penetration testing readiness check

Tick what you can provide.

Your result appears here as you tick, so you can see what is still open.

Platforms and scope

Hosted platforms limit what you can test. However, your custom code, apps and configuration remain fair game with authorisation.

Platform typeTypical scope
Hosted platformCustom apps, theme code and configuration
Self-hosted storeApplication, server and integrations
Headless storefrontFront end, APIs and checkout services

Authorisation and compliance

Testing runs only under your written authorisation, and platform rules are checked first. Also, payment card requirements may ask for testing, so the report is written for assessors too.

Findings come with evidence and a fix. The OWASP Web Security Testing Guide frames the method.

Fees and timing

Stores are web applications, so most fall within our published web application range of $5,000 to $30,000. One retest within 30 days is included, and a named tester is confirmed before day one.

Also time the test well. Because stores often freeze changes before peak seasons, testing a few weeks earlier leaves room to fix findings. So book ahead of busy periods rather than during them. In addition, retest after major theme or app changes, because those often reopen closed issues.

Ecommerce penetration testing questions

Does ecommerce penetration testing cover the payment provider?

No. Your integration is tested, but the provider's platform is outside scope.

Can ecommerce penetration testing run on a hosted platform?

Yes, for your custom code and configuration, within the platform's rules.

What does ecommerce penetration testing cost?

Most stores fall within our web application range of $5,000 to $30,000.

Is a retest included?

Yes. One retest within 30 days is included.

Related guides

Scope your ecommerce penetration testing

Tell us about your platform, apps and checkout. We reply with a written estimate, usually within four working hours.

Get my estimate