Somebody told you to "get a security scan" and you have no way to judge what you were quoted. Here is what a real one covers on a WordPress, Shopify or custom store — and what the piece of paper at the end actually says.
Get a quote for your storeSee a sample reportRarely the payment processor. Almost always the layer you or your agency built around it.
The processor is fine. The problem is the code around it — price and quantity accepted from the browser, discount codes that stack, or an order that can be marked paid by replaying a webhook nobody verifies the signature on.
On WordPress this is where most compromises begin: a plugin abandoned by its author two years ago, still installed, still running with database access. We inventory what you run and flag what has known issues or no maintainer.
Order history readable by changing a number in a URL, password reset with no rate limit, and staff accounts that were never removed when someone left. Boring, common, and the source of most real-world card fraud.
The forgotten blog on a subdomain, the old landing page builder, the staging copy of the store with real customer data in it. Attackers go around the shop, not through it.
A penetration test is one input to PCI DSS, not a certificate of compliance. We give you a dated report, a named tester, a scope statement and a re-test record — the artifacts an acquirer or an insurer asks for. We will not sell you a badge for your footer.
Earthshaker SecurityWe find the cracks before they do. Automated and human-verified security testing for web applications.
earthshakersecurity.com · contact@earthshakersecurity.com
Earthshaker Security