Ecommerce Security Audit: How to Review Your Store Before Professional Testing
How to run an internal ecommerce security review: scope, inventory, access, apps, scripts, payments, data, monitoring, prioritized findings and specialist testing.
Quick answer
An internal ecommerce security review checks that the basics are in place before professional testing. Define scope, build an inventory of domains, platforms, apps, scripts, integrations, accounts and data stores, then review controls: MFA and access, app permissions, scripts on payment-adjacent pages, payment setup, secrets, data handling, configuration, monitoring and incident readiness. Prioritize findings by likelihood and impact, fix them with owners and dates, and commission qualified specialists for testing. An internal review doesn't replace professional assessment.
What This Review Is and Isn't
This is a defensive review of your own store's controls, carried out by your team or partners. It checks configuration, access and processes. It doesn't involve attacking systems, and it doesn't prove the store is secure. Professional penetration testing and security assessments, carried out by qualified specialists with authorization, go further and should follow, especially for custom code, headless storefronts and integrations.
Doing the internal review first is still valuable: it fixes obvious gaps cheaply, gives testers an accurate inventory and scope, and makes their time count. For the underlying controls, see ecommerce security.
Step 1: Define Scope
List what's included: storefronts (theme or headless), admin, checkout configuration, apps and plugins, custom apps and code, integrations (ERP, CRM, marketing, fulfilment), domains and DNS, email, hosting, payment providers, analytics and marketing tags, and systems that hold customer data (warehouse, support desk, email platform). Note what's managed by third parties and what you control.
Step 2: Build the Inventory
| Inventory item | Record |
|---|---|
| Domains and DNS | Registrar, DNS provider, account owners, MFA status |
| Platforms and hosting | Platform, plan, hosting for headless or custom parts |
| Staff and collaborator accounts | Who, role, last login, MFA |
| Apps and plugins | Name, developer, access scopes, owner, still used? |
| Scripts and tags | Where loaded, purpose, owner, loaded on checkout-adjacent pages? |
| Integrations and API credentials | System, credential type, scopes, rotation date |
| Data stores | What customer data, where, who has access, retention |
| Third parties | Payment, fraud, support, email, analytics providers |
Step 3: Review Access
Access is where many incidents start. For every system in scope, confirm MFA is enforced, each person has their own account, permissions match roles, former staff and agencies are removed, and API credentials are scoped and owned. Pay special attention to email and domain accounts: control of them often means control of everything else through password resets.
- MFA enforced on all admin, email, domain, DNS, hosting, repository and payment accounts
- No shared accounts
- Admin rights limited to those who need them
- Leavers and past agencies removed
- API credentials scoped, owned and rotated
- Recovery methods for key accounts current and secure
Step 4: Review Apps, Scripts and Code
For each app or plugin, confirm it's still needed, comes from a reputable developer, requests only necessary access and is up to date. Remove unused ones. For scripts and tags, confirm each has an owner and purpose, is loaded only where needed, and is reviewed before being added to payment-adjacent pages. For custom code, check dependency updates, secrets management, code review practices and whether security testing has been done.
Need help preparing for a security assessment?
ZSpace helps ecommerce teams inventory systems, fix access and app issues and scope professional testing.
Step 5: Review Payments
Confirm how card data flows: hosted checkout, embedded payment fields or direct handling. Check which PCI DSS validation applies with your payment provider, and whether you meet current requirements, including script management on payment pages where relevant (PCI Security Standards Council). Review fraud tool settings, chargeback rates and who can issue refunds or change payout details.
Step 6: Review Data Handling
Map where customer data goes: platform, email and CRM tools, support desk, warehouse, spreadsheets, agencies. Check access, retention, encryption and deletion processes. Look for exports stored in shared drives or email. This overlaps with privacy work; see ecommerce privacy and customer data.
Step 7: Review Configuration, Monitoring and Readiness
Check HTTPS everywhere, security headers where you control them, secure configuration of storage and hosting, and email authentication (SPF, DKIM, DMARC) to reduce spoofing of your domain. Confirm alerts exist for admin changes, new apps, theme or script changes and unusual activity. Check backups and restores. Review the incident response plan and whether it's been practised.
| Area | Question |
|---|---|
| Transport | Is HTTPS enforced on every domain and subdomain? |
| Are SPF, DKIM and DMARC configured? | |
| Headers | Are security headers set where you control them? |
| Storage | Are buckets, databases and exports private? |
| Monitoring | Would you notice a new admin or app today? |
| Backups | When was a restore last tested? |
| Incidents | Is there a plan, and who knows it? |
Step 8: Prioritize Findings
Rate each finding by likelihood and impact, assign an owner and a date. Findings that could lead to takeover of admin, email or domain accounts, exposure of payment or large volumes of customer data, or unauthorized scripts on payment-adjacent pages are critical.
| Severity | Examples | Target |
|---|---|---|
| Critical | No MFA on admin or email; unknown scripts near checkout; exposed data export | Immediate |
| High | Over-permissioned apps; former agency access; unrotated keys | Within days |
| Medium | Missing monitoring; no tested backups | Within weeks |
| Low | Documentation gaps | Planned |
Step 9: Professional Testing
After fixing critical and high findings, commission professional testing where warranted: penetration testing of custom code, headless storefronts, APIs and integrations; reviews of cloud configuration; and assessments required by your payment or compliance obligations. Provide testers with your inventory and scope, confirm authorization (including from platform providers where their terms require it) and plan remediation time. Don't run intrusive tests against live systems or third-party platforms yourself.
Making Reviews Routine
Security reviews work best as routine: quarterly access and app reviews, an annual full review, and targeted reviews after major changes (replatforming, headless builds, new integrations, agency changes). Keep the inventory current and track findings to closure. See ecommerce replatforming.
Review Checklist Summary
- Scope written and agreed
- Inventory of domains, platforms, accounts, apps, scripts, integrations, data stores
- MFA and access reviewed on every system
- Apps reviewed for need, developer and scopes
- Scripts on payment-adjacent pages inventoried and approved
- Payment flow and PCI validation confirmed with provider
- Secrets located, scoped and rotated
- Customer data locations and exports reviewed
- Email authentication, HTTPS and headers checked
- Monitoring, backups and incident plan checked
- Findings prioritized with owners and dates
- Professional testing scoped
Working With Security Specialists
When engaging testers, agree scope, methods, timing and rules of engagement in writing, confirm authorization for every system tested (including checking platform provider terms), and provide a test environment where possible. Ask for a report with findings, severity, evidence and remediation guidance, and plan a re-test after fixes. Treat findings as confidential and share them only with those who need them.
| Agree | Details |
|---|---|
| Scope | Systems, URLs, APIs, apps in and out of scope |
| Authorization | Written approval; platform terms checked |
| Timing | Windows that avoid peak trading |
| Environment | Staging where possible |
| Reporting | Severity, evidence, remediation, re-test |
After the Review
Track findings to closure, re-check critical fixes, update the inventory and document decisions where risks are accepted, with a reason and an owner. Share a short summary with leadership so security investment decisions are informed. See ecommerce privacy and customer data for the data side.
Common Mistakes
- Treating an internal checklist as proof of security
- No inventory of apps, scripts and integrations
- Ignoring email and domain accounts
- Running intrusive tools against live or third-party systems without authorization
- Findings without owners or dates
- No re-review after major changes
Ready to review your store's security?
Talk to ZSpace about security-focused development reviews, Shopify access and app reviews and platform audits.
Conclusion
An internal security review inventories the store, checks access, apps, scripts, payments, data, configuration and readiness, prioritizes fixes and prepares for professional testing, which it doesn't replace. Related: website security checklist and ecommerce compliance.
Common questions
A structured review of a store's security controls: accounts and access, apps and integrations, scripts, payments, data handling, configuration, monitoring and incident readiness. This article covers an internal review, not a professional assessment.