Magecart · card skimmers

Free Magecart skimmer scanner

Scan your storefront for card-skimming indicators — free and passive.

No signup Passive & safe Results in seconds

Magecart is the umbrella name for digital card-skimming attacks that inject malicious JavaScript into checkout pages to steal customers’ payment-card data. MageArgus scans your store for free and flags skimmer indicators, suspicious external scripts and risky checkout behaviour — in seconds, with no signup.

What is Magecart?

Magecart refers to dozens of criminal groups that specialise in web skimming: planting hidden JavaScript on e-commerce sites that copies card numbers as customers type them at checkout, then exfiltrates the data to an attacker-controlled server. The customer completes a normal purchase and never knows. Stores often discover it only when their payment processor or a bank flags fraud weeks later.

Skimmers commonly arrive through an unpatched Magento CVE, a compromised admin account, or a hijacked third-party script. Magento’s checkout is a prime target because of its transaction volume.

What our skimmer scan looks for

The free scan is passive and external. For deeper, runtime-level detection on a store you own, verified scans can render the checkout in a real browser, and the MageArgus module scans your filesystem and database for injected code directly.

How to remove a Magecart skimmer

If a skimmer is found, treat it as an active breach:

  1. Take a forensic copy, then remove the injected script from templates, CMS content and any compromised third-party file.
  2. Find and close the entry point — patch the CVE or admin account that was abused, or the skimmer returns within days.
  3. Rotate all admin credentials and integration tokens.
  4. Notify your payment processor and follow PCI breach obligations.

Need hands-on help? See Magento malware removal.

Frequently asked questions

Can you detect a Magecart skimmer from outside my store?
Often, yes. Many skimmers run on the public storefront, so a passive external scan can flag suspicious scripts and known indicators. The most thorough detection comes from a verified browser-level scan or the on-store module, which inspect your files and database directly.
How did a skimmer get on my store?
Usually through an unpatched Magento vulnerability, a compromised admin account, or a hijacked third-party script. Our scan also reports the exposure that lets skimmers in, so you can close the door.
Will customers know their card was skimmed?
No — that’s what makes Magecart dangerous. The checkout works normally; the theft is invisible until fraud appears on customers’ statements. Regular scanning is the practical defence.

Scan your checkout for skimmers

Free, passive Magecart check — results in seconds.

Scan my store free