Pen testing · Commerce & industry
Penetration Testing for E-commerce & DTC Brands
A penetration test shows how your storefront holds up against the two attacks that actually hit Canadian online retail: skimming code slipped into the checkout and credential stuffing against customer accounts. Brands book us when the acquirer reclassifies them to SAQ A-EP, when an insurer wants testing evidence, or simply because the summer window before the code freeze is the only safe time to probe and fix a revenue-critical site.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The attack surface of a modern storefront
A commerce stack exposes more than a website. Testing has to reach every path an attacker could take to card data, customer accounts or the admin itself.
Checkout and the scripts around it
Third-party JavaScript, GTM containers and checkout customizations are where skimmers live, and where the new PCI script scrutiny is aimed.
Customer accounts and loyalty endpoints
Login, password reset and points-redemption flows attract credential-stuffing crews because a stolen account pays out in stored addresses and rewards.
Custom apps, webhooks and headless APIs
Bespoke Shopify apps, Hydrogen storefront APIs and the webhooks feeding your systems often skip the security review the theme got.
Admin and collaborator access paths
Staff logins, agency collaborator accounts and session handling around the admin decide whether one phished password becomes a full compromise.
Fulfilment and wholesale integrations
Connections to the 3PL, ShipStation-class tools and EDI links for retail partners move customer data outside the storefront's protections.
Regulatory map
Why the acquirer's letter now mentions testing
The compliance reasons to test an online store sharpened considerably when the card brands turned their attention to merchant-side scripts.
PCI's script requirements, 6.4.3 and 11.6.1
Merchants in SAQ A-EP must manage and justify payment-page scripts and detect tampering, while even SAQ A eligibility now hinges on confirming resistance to script attacks. Testing demonstrates whether those controls stand up.
PIPEDA's safeguard principle
Federal law expects protection matched to the sensitivity of the customer data you hold, and periodic testing is one of the clearest ways a merchant can show its safeguards were checked rather than assumed.
Law 25 and overhauled systems
Replatforming, going headless or rebuilding checkout counts as a new or overhauled information system for Quebec purposes, and security testing pairs naturally with the privacy assessment the change requires.
The platform boundary
Shopify secures and tests its own infrastructure under its PCI certification, so merchant-side testing properly targets what you built: customizations, apps, APIs and integrations.
What goes wrong
What a storefront pen test is built to catch
Every finding category below corresponds to an incident Canadian retailers have already lived through or a fraud line brands fight daily.
Skimming footholds on the payment page
The Kritec campaign hid a skimmer behind a convincing Google Tag Manager disguise on the LCBO's store. Testing hunts for the injection points and weak script controls that let that happen.
Account takeover at scale
The PC Optimum points thefts showed how reused passwords empty loyalty balances. We test rate limiting, credential-stuffing resilience and recovery flows before someone else does.
Business-logic abuse
Stacked discount codes, manipulated points redemptions, subscription tampering and refund-flow weaknesses cost real margin even though no system is ever "hacked" in the traditional sense.
Over-trusted apps and webhooks
Webhooks that accept unsigned calls, apps holding broader scopes than their function needs, and API keys sitting in theme code all shorten an attacker's path to order data.
Our pen testing for e-commerce & dtc brands
What we examine on a Shopify or headless build
Deliverables follow our standard testing service, aimed at the pieces of a commerce stack a merchant controls.

Payment-page script reconnaissance
An inventory of every script loading on checkout with an assessment of its origin, justification and integrity controls, in the exact shape acquirers ask about.
Storefront and theme vulnerability exploration
Controlled probing of the customer-facing site and its customizations for the weaknesses that matter, prioritized by exploitability.
Authentication and API testing
Account portal, loyalty, subscription and headless API endpoints exercised for takeover resistance, authorization gaps and abuse-friendly logic.
Custom app and integration review
Your bespoke apps, webhooks and 3PL or EDI connections tested for authentication weaknesses and data exposure between systems.
Findings, debrief and retest
A report your developers and agency can act on, framed for acquirers and insurers, with a retest to confirm fixes landed before peak season.
How the engagement runs
Testing an active store without touching revenue
Method and timing are designed around a site that cannot afford downtime or a broken conversion funnel.
Step 1
Scope the estate
We map storefronts, headless components, mobile surfaces, custom apps and integrations, and agree what is in and out of bounds.
Step 2
Set rules of engagement
Test accounts, low-traffic windows, platform terms and 3PL coordination are settled up front so nothing surprises operations or support.
Step 3
Test in the summer window
Active work runs well before the late-October freeze, leaving room for remediation while the theme can still change.
Step 4
Debrief the people who fix things
Findings are walked through with your developer or agency in plain terms, ranked by real-world risk rather than scanner severity.
Step 5
Retest and close
Confirmed fixes are verified and the final report updated, giving you a clean artifact for the acquirer, insurer or diligence file.
What it costs
What drives the price of a storefront test
Scope is the whole story: one storefront or several brands, whether a headless build and mobile app join the web target, how many custom apps and webhooks exist, the depth of API and loyalty testing, and whether a retest is included. A theme-only engagement sits at one end; a Plus store with subscriptions, custom checkout and a headless frontend sits at the other.
Timing can matter too, since compressed pre-freeze schedules constrain how work is sequenced. Share your platform, integrations and deadline and we will return a fixed, tailored quote.
E-commerce & DTC Brands: Pen testing questions, answered
Yes. Merchant-side testing works within the platform's boundaries: we use test accounts and agreed windows, avoid destructive techniques against production checkout, and lean on preview themes or staging environments where changes are involved. The point is to observe how your customizations, apps and APIs behave under attack conditions, not to disrupt ordering. Brands typically see no customer-facing impact during an engagement.
It supplies evidence, not the attestation itself. The SAQ remains a self-assessment your CFO signs for the acquirer, but A-EP's expectations around managed, justified payment-page scripts and tamper detection are exactly what a test can validate in practice. Our report shows which controls held, which failed and what changed after remediation, which is the substance behind the boxes the questionnaire asks you to tick.
That is often the most valuable part of the engagement. We simulate credential-stuffing conditions against login and password-reset flows, check rate limiting and lockout behaviour, and probe loyalty and subscription endpoints for authorization gaps that let one customer read or spend another's balance. Stored addresses, points and saved payment methods make these accounts genuinely worth stealing, so they deserve dedicated attention.
All in scope if you want them to be. Custom apps frequently hold wide API scopes, webhooks sometimes accept traffic without verifying its source, and 3PL or EDI connections carry order and address data outside the storefront entirely. We test authentication, signing and data handling across those links, because attackers treat the seams between systems as the front door.
Work backwards from late October. A test in June through September leaves time to remediate and retest while your theme and checkout can still be modified; anything later risks findings you cannot act on until the new year. Brands that miss the window sometimes test read-only surfaces during Q4 and schedule the intrusive portion for January, but the summer slot remains the efficient path.
More for e-commerce & dtc brands
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.