The practical checklist

Magento 2 security checklist

Scan your store free to see which items you already pass.

No signup Passive & safe Results in seconds

This Magento 2 security checklist covers the controls that actually stop real attacks: staying patched against known CVEs, hardening the admin, setting security headers, locking down file permissions, and monitoring for change. Run the free scan to see which items your store already passes and which need attention.

The checklist

1. Patching & versions

2. Admin hardening

3. Transport & headers

4. Files & secrets

5. Monitoring

Check your store against it automatically

You don’t have to audit all of this by hand. The free MageArgus scan covers the externally-visible items — version & CVE exposure, TLS and headers, leaked files and skimmer indicators — and returns a 0–100 score so you can see your gaps at a glance. The on-store MageArgus module covers the internal items: on-disk patch confirmation, file/database malware, permissions and rogue-admin detection.

Frequently asked questions

How often should I run through this checklist?
Review it quarterly and any time a new Magento security patch is released. Because new CVEs are weaponised within days, the patching and scanning items in particular should be continuous, not annual.
What’s the single most important item?
Staying patched. The large Magento compromises of recent years (CosmicSting, SessionReaper) all exploited known, already-patched vulnerabilities on stores that simply hadn’t updated yet.
Can MageArgus check the whole checklist for me?
The free scan covers everything visible from outside the store. The internal items — on-disk patch confirmation, file and database malware, permissions, rogue admins — are covered by the MageArgus Magento module.

See how your store scores

Free scan against the externally-visible checklist items — 0–100 score in seconds.

Scan my store free