>< Lynx Auditoría Web · Security audit service

Security audit for PrestaShop, WordPress and WooCommerce stores and websites

6
areas reviewed: surface, patches, configuration, access, backups and traffic
0
changes to your store during the audit: read-only
1
report with findings ranked by risk and effort
You
decide whether to fix it yourself or hand it to us

Where they really get in

What we see when analysing compromised stores keeps repeating. None of it takes a brilliant attacker.

The third-party module from four years ago

Installed for a campaign, never updated, with a public vulnerability. It is the most common origin of compromise in e-commerce.

The backup in the public folder

A backup.zip, a .sql dump or a .git folder reachable by URL. Anyone can download the whole store, credentials included.

Admins who no longer work here

Accounts from the previous provider, from an intern, from "testing". Weak password, no second factor, on a panel reachable from anywhere.

The backup nobody has ever restored

It exists, it runs every night and nobody has checked it can be recovered. A backup that has never been tested is not a backup.

What Lynx Auditoría Web reviews

Six areas, all checked on the real installation and its server, not on a questionnaire.

Exposed surface

Inventory of core, theme and module or plugin versions, identifying abandoned or unsupported ones. Files that should not be public: backups, installers, dumps, logs, version-control directories and reachable test environments.

Vulnerabilities and patches

Installed versions checked against known public vulnerabilities. Review of third-party modules, the usual origin of compromise in e-commerce. List of pending patches ordered by criticality.

Configuration

File and directory permissions, PHP version and extensions, debug mode, error handling, session cookie attributes, security headers and content security policy.

Access control

Admin accounts and their permissions, password policy, second factor, exposure of the admin panel and of webservice or API endpoints, and credentials stored in code or configuration files.

Backups

Checking that they exist, where they are stored and, above all, that they can be restored.

Traffic

Analysis of server logs to detect scrapers, brute-force attempts, user enumeration and automation that degrades performance.

Deliverable: a report with findings ranked by risk and impact, the specific fix for each one and an effort estimate. You can carry it out yourself, with your current provider, or hand it to us.

How it works

Nothing installed on your store and no changes to production. Read-only.

01

Scope and access

We agree what is audited (one store, several, the whole server) and which read-only access we need: SSH/FTP, a read-only profile in the store back office and access to the web server logs.

  • Scope
  • Read-only
  • Logs
02

External review

What anyone can see from outside: detectable versions, exposed files, headers, reachable panels, certificate and DNS.

  • Surface
  • Headers
  • Exposed panels
03

Internal review

On the installation and the server: modules, permissions, PHP and application configuration, accounts, credentials in code, backups and analysis of access logs.

  • Modules
  • Permissions
  • Accounts
  • Backups
04

Report and plan

Findings ordered by risk and effort, a specific fix for each one and a session to go through it with you or with whoever will carry it out.

  • Prioritisation
  • Remediation plan
  • Review session

Who it is for

Stores that sell and don't want to learn about their holes from an incident.

  • Stores inheriting an installation

    Change of agency, hosting provider or internal owner. Before taking on maintenance it pays to know what you are inheriting.

  • Before a campaign or a migration

    Black Friday, sales, migration to PrestaShop 8 or 9. Traffic peaks and big changes are the worst time to discover a vulnerable module.

  • A requirement from a client, insurer or supplier

    More and more cyber-risk insurers and B2B clients ask for evidence that security is reviewed. The report is that evidence.

After the audit

The audit tells you what is there. These services fix it, protect it or watch it.

PrestaShop maintenance

We carry out the remediation plan and keep the store updated and patched, with Lynx Monitor watching versions and new admin accounts.

See maintenance

Lynx Perímetro

For what cannot be fixed immediately in the application, the managed firewall on Cloudflare blocks the way from the edge.

See the managed WAF

General web audit

If you are after performance, technical SEO and user experience as well as security, the general audit covers those areas.

See the general audit

Frequently asked questions

Is this a pentest?
What do you need from me?
How long does it take?
What if you find something serious?
How is it different from your general web audit?

Better to know now

Tell us which platform you use and how many stores you have and we will propose a scope.

Contact us, don't be afraid.
Chat on WhatsApp