← All articles

Checklist · 2026-07-18

Ecommerce Website Security Checklist (2026)

Every online store — Magento, WooCommerce, Shopify or custom — shares the same core risks: an attacker wants your customers' cards and your admin access. This platform-agnostic ecommerce security checklist covers the controls that protect any store, so you can secure the fundamentals regardless of the tech underneath.

Start with a free baseline: run a free MageArgus scan to check patching, TLS, headers, exposed files and skimmer signals.

By the numbers
  • Checkout skimmers target every ecommerce platform, not just oneSansec
  • PCI DSS 4.0 now requires payment-page script management and change detectionPCI SSC

Patch & update

Lock down access

Protect the checkout

Transport & headers

See security headers explained.

Detect & recover

Platform-specific deep dives: Magento hardening and WooCommerce security.

Frequently asked questions

Which platform is most secure?

Security depends far more on how a store is maintained than on the platform. A patched, hardened, monitored store is safe on any platform; an out-of-date one is at risk on all of them. See our Magento vs WordPress security comparison.

Do small stores really get targeted?

Yes. Most attacks are automated and indiscriminate — bots scan the whole web for vulnerable versions. A small store running an unpatched platform is just as likely to be hit as a large one.

Related reading

Scan your store free →