Fixed-price audit · Adobe Commerce & Magento Open Source
Magento Audit: Know Where Your Store Stands
Patch level, end-of-life risks, extensions, custom code, signs of compromise and performance, reviewed by a senior Magento engineer. You get a written report with what to fix first and what it will take, and a call to go through it.
$990 fixed price · report within 5 business days
Credited in full against the Magento Upgrade Plan if you subscribe within 60 days · +1 866 571 7005
What the Audit Covers
01
Version & Patches
Exact version and patch level against Adobe’s security bulletins, every patch your build applies, and whether it actually applied.
02
End-of-Life Exposure
Support dates for your Magento line, PHP, the database and search engine, and what the next upgrade will require.
03
Extensions & Custom Code
Third-party modules and their versions, abandoned or risky packages, and custom code that will block the next upgrade.
04
Signs of Compromise
Unexpected files in writable directories, unknown admin users, stale integrations and tokens, injected scripts in configuration and content.
05
Performance & Caching
Full-page cache hit rate, slow pages and queries, cron and indexer health, and the frontend weight of key templates.
06
Infrastructure & Releases
Hosting or Adobe Commerce Cloud setup, environments, backups, and how code gets from a branch to production.
What You Get
A Report You Can Act On
- Executive summary: where the store stands, in one page
- Findings ranked by risk, each with the evidence behind it
- Quick wins you can ship within a week
- Upgrade roadmap with effort estimates
- List of missing security patches for your exact version
- A one-hour call to walk through the report
The audit does not change your store. Fixes are quoted separately, or covered by the Magento Upgrade Plan, where the $990 is credited against the first year if you subscribe within 60 days.
How It Works
01
Request
Send the form below. We confirm scope and send the invoice within one business day.
02
Access
Read access to your Git repository, a staging copy or database dump without customer data, and hosting details.
03
Review
Two days of hands-on review of code, configuration, environments and logs.
04
Report
Written report within 5 business days of access, followed by the review call.
Emergency
Store Compromised? Emergency Patch & Cleanup
If you think someone got into your store, do not wait for a scheduled audit. We aim to start within one business day: apply the emergency patch for your version, find and remove what the attacker left behind, close the entry point and rotate the credentials that could have leaked.
Billed hourly at a rate we agree on the first call. Work can start before the invoice is paid.
Call us now if you see
- Unfamiliar PHP files in pub/media, pub/static or var
- Admin users nobody on your team created
- Unknown scripts on checkout pages or in CMS blocks
- Customers reporting card fraud after buying from you
- An actively exploited Adobe bulletin your store is not patched for
Questions
What access do you need?
Read access to your Git repository, a staging environment or a database dump without customer data, read-only admin access, and details of your hosting or Adobe Commerce Cloud project. We do not need production write access.
Does the audit include fixes?
No. The audit tells you what to fix and what it takes, with an estimate for each item. You can do the work in-house, have us quote it, or cover patches and updates with the Magento Upgrade Plan.
Will the audit tell me if my store was hacked?
It checks the common signs: unexpected files, unknown admin users and integrations, injected scripts. If we find any, we tell you the same day and recommend an emergency cleanup rather than waiting for the report.
Which versions do you audit?
Magento Open Source and Adobe Commerce 2.3 and 2.4, self-hosted or on Adobe Commerce Cloud, with Luma or Hyvä themes.
How is the audit credited against the Upgrade Plan?
If you subscribe to any Magento Upgrade Plan within 60 days of receiving the report, the $990 is deducted from the first year. The plan's onboarding audit is then already done.
Who issues the invoice?
Paxento operates within Fundacja Firma Dla Każdego in Warsaw, which issues a VAT invoice for every payment. Business customers in the EU with a valid VAT number are invoiced under the reverse charge. Details are in our Terms of Service.
Request the Audit
Tell us about your store. We confirm the scope and send the invoice within one business day.
Direct Contact
Typical response within 24 hours
$990, fixed. Report within 5 business days of access, then a one-hour review call. Credited against the Magento Upgrade Plan if you subscribe within 60 days.
