Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Pen testing · Commerce & industry

Penetration Testing for E-commerce & DTC Brands

A penetration test shows how your storefront holds up against the two attacks that actually hit Canadian online retail: skimming code slipped into the checkout and credential stuffing against customer accounts. Brands book us when the acquirer reclassifies them to SAQ A-EP, when an insurer wants testing evidence, or simply because the summer window before the code freeze is the only safe time to probe and fix a revenue-critical site.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The attack surface of a modern storefront

A commerce stack exposes more than a website. Testing has to reach every path an attacker could take to card data, customer accounts or the admin itself.

Checkout and the scripts around it

Third-party JavaScript, GTM containers and checkout customizations are where skimmers live, and where the new PCI script scrutiny is aimed.

Customer accounts and loyalty endpoints

Login, password reset and points-redemption flows attract credential-stuffing crews because a stolen account pays out in stored addresses and rewards.

Custom apps, webhooks and headless APIs

Bespoke Shopify apps, Hydrogen storefront APIs and the webhooks feeding your systems often skip the security review the theme got.

Admin and collaborator access paths

Staff logins, agency collaborator accounts and session handling around the admin decide whether one phished password becomes a full compromise.

Fulfilment and wholesale integrations

Connections to the 3PL, ShipStation-class tools and EDI links for retail partners move customer data outside the storefront's protections.

Regulatory map

Why the acquirer's letter now mentions testing

The compliance reasons to test an online store sharpened considerably when the card brands turned their attention to merchant-side scripts.

PCI's script requirements, 6.4.3 and 11.6.1

Merchants in SAQ A-EP must manage and justify payment-page scripts and detect tampering, while even SAQ A eligibility now hinges on confirming resistance to script attacks. Testing demonstrates whether those controls stand up.

Primary source →

PIPEDA's safeguard principle

Federal law expects protection matched to the sensitivity of the customer data you hold, and periodic testing is one of the clearest ways a merchant can show its safeguards were checked rather than assumed.

Read our guide →

Law 25 and overhauled systems

Replatforming, going headless or rebuilding checkout counts as a new or overhauled information system for Quebec purposes, and security testing pairs naturally with the privacy assessment the change requires.

Primary source →

The platform boundary

Shopify secures and tests its own infrastructure under its PCI certification, so merchant-side testing properly targets what you built: customizations, apps, APIs and integrations.

Primary source →

What goes wrong

What a storefront pen test is built to catch

Every finding category below corresponds to an incident Canadian retailers have already lived through or a fraud line brands fight daily.

  • Skimming footholds on the payment page

    The Kritec campaign hid a skimmer behind a convincing Google Tag Manager disguise on the LCBO's store. Testing hunts for the injection points and weak script controls that let that happen.

    Source →

  • Account takeover at scale

    The PC Optimum points thefts showed how reused passwords empty loyalty balances. We test rate limiting, credential-stuffing resilience and recovery flows before someone else does.

    Source →

  • Business-logic abuse

    Stacked discount codes, manipulated points redemptions, subscription tampering and refund-flow weaknesses cost real margin even though no system is ever "hacked" in the traditional sense.

  • Over-trusted apps and webhooks

    Webhooks that accept unsigned calls, apps holding broader scopes than their function needs, and API keys sitting in theme code all shorten an attacker's path to order data.

Our pen testing for e-commerce & dtc brands

What we examine on a Shopify or headless build

Deliverables follow our standard testing service, aimed at the pieces of a commerce stack a merchant controls.

Business performance checklist, Businessman using laptop online survey filling out check digital form task, business performance monitoring and evaluation. online survey question f
  1. Payment-page script reconnaissance

    An inventory of every script loading on checkout with an assessment of its origin, justification and integrity controls, in the exact shape acquirers ask about.

  2. Storefront and theme vulnerability exploration

    Controlled probing of the customer-facing site and its customizations for the weaknesses that matter, prioritized by exploitability.

  3. Authentication and API testing

    Account portal, loyalty, subscription and headless API endpoints exercised for takeover resistance, authorization gaps and abuse-friendly logic.

  4. Custom app and integration review

    Your bespoke apps, webhooks and 3PL or EDI connections tested for authentication weaknesses and data exposure between systems.

  5. Findings, debrief and retest

    A report your developers and agency can act on, framed for acquirers and insurers, with a retest to confirm fixes landed before peak season.

How the engagement runs

Testing an active store without touching revenue

Method and timing are designed around a site that cannot afford downtime or a broken conversion funnel.

  1. Step 1

    Scope the estate

    We map storefronts, headless components, mobile surfaces, custom apps and integrations, and agree what is in and out of bounds.

  2. Step 2

    Set rules of engagement

    Test accounts, low-traffic windows, platform terms and 3PL coordination are settled up front so nothing surprises operations or support.

  3. Step 3

    Test in the summer window

    Active work runs well before the late-October freeze, leaving room for remediation while the theme can still change.

  4. Step 4

    Debrief the people who fix things

    Findings are walked through with your developer or agency in plain terms, ranked by real-world risk rather than scanner severity.

  5. Step 5

    Retest and close

    Confirmed fixes are verified and the final report updated, giving you a clean artifact for the acquirer, insurer or diligence file.

What it costs

What drives the price of a storefront test

Scope is the whole story: one storefront or several brands, whether a headless build and mobile app join the web target, how many custom apps and webhooks exist, the depth of API and loyalty testing, and whether a retest is included. A theme-only engagement sits at one end; a Plus store with subscriptions, custom checkout and a headless frontend sits at the other.

Timing can matter too, since compressed pre-freeze schedules constrain how work is sequenced. Share your platform, integrations and deadline and we will return a fixed, tailored quote.

E-commerce & DTC Brands: Pen testing questions, answered

Yes. Merchant-side testing works within the platform's boundaries: we use test accounts and agreed windows, avoid destructive techniques against production checkout, and lean on preview themes or staging environments where changes are involved. The point is to observe how your customizations, apps and APIs behave under attack conditions, not to disrupt ordering. Brands typically see no customer-facing impact during an engagement.

It supplies evidence, not the attestation itself. The SAQ remains a self-assessment your CFO signs for the acquirer, but A-EP's expectations around managed, justified payment-page scripts and tamper detection are exactly what a test can validate in practice. Our report shows which controls held, which failed and what changed after remediation, which is the substance behind the boxes the questionnaire asks you to tick.

That is often the most valuable part of the engagement. We simulate credential-stuffing conditions against login and password-reset flows, check rate limiting and lockout behaviour, and probe loyalty and subscription endpoints for authorization gaps that let one customer read or spend another's balance. Stored addresses, points and saved payment methods make these accounts genuinely worth stealing, so they deserve dedicated attention.

All in scope if you want them to be. Custom apps frequently hold wide API scopes, webhooks sometimes accept traffic without verifying its source, and 3PL or EDI connections carry order and address data outside the storefront entirely. We test authentication, signing and data handling across those links, because attackers treat the seams between systems as the front door.

Work backwards from late October. A test in June through September leaves time to remediate and retest while your theme and checkout can still be modified; anything later risks findings you cannot act on until the new year. Brands that miss the window sometimes test read-only surfaces during Q4 and schedule the intrusive portion for January, but the summer slot remains the efficient path.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.