In-depth penetration testing for e-commerce stores that quietly lose money to checkout fraud.
Offensive security assessments built for e-commerce (VTEX, Magento, Shopify, custom platforms). Full coverage of checkout fraud, price and shipping manipulation, coupon and cashback abuse, bot defenses and card testing, inventory race conditions, order BOPLA and acquirer integration review. Retest included after the fix.
- Mutual NDA within 24h
- Retest included
- Direct contact with the researcher
Why e-commerce
E-commerce bugs don't take the store down — they slowly leak money
E-commerce penetration testing isn't about an attacker taking the site down. It's about hundreds of orders a month going out with modified prices, reused coupons, fraudulent free shipping and duplicate refunds. You won't see it in the application logs — you'll see it in reconciliation with your acquirer, three months later, when the books don't balance.
The most common patterns:
- Price manipulation — the attacker changes the amount between cart and payment, and the gateway accepts it
- Coupon reuse — a “single-use” campaign code that works 5 times
- Card testing — the checkout becomes a validator for stolen cards at scale
- Free-shipping fraud — bypassed by modifying the ZIP/postal code or region
- Cashback on cancellations — the customer cancels and keeps the cashback
Here, a pentest pays for itself in the first month — fraud documented and shut down.
Scope
What our e-commerce penetration testing covers
Checkout and purchase flow
- Price manipulation between cart, checkout and payment
- Order BOPLA (changing amount, status or shipping via a direct PATCH)
- Inventory race conditions (buying out-of-stock products)
- Order race conditions (creating 2 orders with 1 validated card)
- Tax ID (e.g., Brazil's CPF) / personal data validation bypass
- Currency manipulation in multi-currency stores
- Bypass of combo / product bundle rules
Coupons, vouchers and cashback
- Reuse of single-use coupons (race condition)
- Combining mutually exclusive coupons
- Eligibility rule bypass (tax ID, first order, minimum order value)
- Discount percentage manipulation via payload
- Fraudulent cashback on cancellations
- Loyalty program cashback stacking
Shipping and delivery
- Shipping cost manipulation (changing the amount after the order is placed)
- ZIP/postal code or region validation bypass for free shipping
- Bypass of rules for products that don't ship to a region
- BOLA on order tracking (accessing another customer's delivery)
- Delivery status manipulation
- SSRF via the carrier integration
Bot defenses, anti-fraud and card testing
- Card testing — approval rate as a signal for the attacker
- Checkout rate limiting by IP / device / BIN / ZIP code
- CAPTCHA bypass (token reuse, headless detection)
- Fingerprint forgery (User-Agent, Accept-Language, screen)
- Abuse of sign-up/login flows to evade anti-fraud controls
- Risk score bypass through payload modification
- Mastercard SDP / Visa CPP — high-risk merchant compliance
Catalog and search
- Product BOPLA (changing another seller's price on a marketplace)
- Mass assignment on product updates
- SQL injection / NoSQL injection in search
- SSRF via product import from a URL
- Stored XSS in product descriptions
- Path traversal in image uploads
Customer accounts
- BOLA on orders, addresses and saved cards
- Account takeover (ATO) via OAuth (Google, Apple, Facebook login)
- Recovery tokens — entropy, replay, expiration
- BOLA on wishlists
- PII leakage on public endpoints
Acquirer and ERP integrations
- Webhook tampering — replay, signature bypass
- Reconciliation race conditions (an order marked as paid without payment)
- SSRF via ERP integrations (Bling, Tiny, Linx)
- Sub-acquirer payload manipulation
- 3DS validation bypass
Platform-specific
- VTEX IO — custom apps, Master Data, Checkout UI customization
- Shopify — Shopify apps, Liquid templates, Storefront API
- Magento 2 — extensions, ACL, customer data leaks
- Tray, Loja Integrada, Nuvemshop, custom platforms
Pricing
E-commerce penetration testing pricing
| Scenario | Price range | Coverage |
|---|---|---|
| Small online store (up to 50K orders/month) | Sprint (25h): US$ 3,750 to US$ 6,250 | Checkout + coupons + auth + acquirer integration |
| Mid-sized online store (50K–500K orders/month) | Deep Dive (50h): US$ 7,500 to US$ 12,500 | + bot defenses + shipping + ERP + customizations |
| Enterprise e-commerce (custom platform) | Full Scope (100h+): from US$ 15,000 | White box + mobile + cloud + ML anti-fraud |
| Recurring, sprint-aligned | PTaaS: on request | Continuous pentesting + fraud monitoring |
Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
FAQ
Frequently asked questions
What bugs come up in e-commerce penetration testing?
The most common are: price manipulation at checkout (changing the amount between cart and payment), coupon abuse (reuse, forbidden combinations), free-shipping bypass, inventory race conditions (buying out-of-stock products), tax ID validation bypass (such as Brazil's CPF), cashback manipulation on cancellations, order BOPLA (changing status or amount) and BOLA on other customers' orders.
VTEX, Magento, custom Shopify — do you cover them?
Yes. Coverage includes SaaS platforms (VTEX, Shopify, Tray, Loja Integrada, Nuvemshop) and self-hosted ones (Magento 2, Shopware, custom builds). On SaaS platforms, we focus on theme/checkout customizations, integrations and the public API. On self-hosted platforms, we focus on known vulnerabilities + customizations.
How much does e-commerce penetration testing cost?
Small online store (up to 50K orders/month): Sprint (25h), US$ 3,750 to US$ 6,250. Mid-sized online store (50K–500K orders/month): Deep Dive (50h), US$ 7,500 to US$ 12,500. Enterprise e-commerce (500K+ orders/month, custom platform): Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.
Do you cover bot defenses and card testing?
Yes. Card testing is one of the most common vectors in e-commerce — attackers use the checkout to validate stolen cards at scale. Coverage includes rate limiting by IP/device/BIN, bot detection (fingerprinting, behavioral), CAPTCHA bypass, abuse of sign-up/login flows to evade controls, and alignment with Mastercard SDP / Visa CPP for high-risk merchants.
Next step
Request a proposal for your e-commerce business.
Mutual NDA within 24h. Once it's signed, a technical call to map your platform, checkout flows and integrations. Formal proposal within 3 business days.
Talk to a researcher