Security & CSP
Content Security Policy hardening and safer security iterations for Magento 2.
-
Article
Magento 2 Incident Recovery: 6 Scenarios and a Runbook
Magento 2 incident recovery as a runbook, not a panic: six real scenarios with diagnosis flowcharts, timed recovery steps, and comms templates.
-
Article
Magento 2 Security Hardening: 9 Layers, Owned and Costed
Magento 2 security hardening as an owned, costed plan: SSO before 2FA, upload bypasses that still work, composer audit, and what breach tooling costs.
-
Article
Magento 2 Passkeys: The Mage-OS Module, Tested
Magento 2 passkeys for customers and admins, tested on 2.4.8-p5: what the Mage-OS module does well, three traps to check first, and why not to build your own.
-
Article
Magento Attack Surface: Don’t Ship Code You Don’t Need
StyleSmuggler (CVE-2026-75650) hit fully patched Magento 2 stores through GraphQL — a feature most of them never used. Patch, then stop shipping it.
-
Module
Magento 2 Config Data API Module: Redacted REST Access
A Magento config data API for reading core_config_data over REST, redacted by default — plus config.php/env.php override tracing and store scoping.
-
Article
Magento 2 Encrypted Config: The Key Rotation Trap
A Magento 2 encrypted config field without the obscure type leaks its value, and the next save can double-encrypt it for good — no key rotation needed.
-
Article
DataReporter WebCare Magento 2 Cookie Banner Guide
DataReporter WebCare Magento 2 developer guide: Loader Mode for CSP/SRI-safe integration, consent-gated scripts, multi-store redirects, and the consent API.
-
Article
Magento CSP header size: scope it, don’t just split it
A multi-website Magento 2 store can blow past the nginx header limit. Here is how to cut CSP header size at the root by scoping entries per store view.
-
Module
Magento 2 Scoped CSP Module: Per-Module CSP Whitelists
Per-module CSP whitelists for Magento 2, scoped to website or store view — one integration’s source change never forces a global policy relaxation.