ShopGuard
Store security monitoring · by Evosec

The night watch
for your checkout.

ShopGuard checks your Shopify or WooCommerce store every night — certificates, leaked files, outdated plugins, card-skimming scripts, checkout uptime — and tells you what's wrong in plain English. One click and our engineers fix it.

No install · passive checks · results in ~20 seconds

nightly-scan · 03:00 UTC
$ shopguard scan northwind-coffee.example
→ resolving host … 104.21.32.7 (public ✓)
✓ tls valid · TLSv1.3 · 68 days left
✓ uptime / 412ms /cart 380ms /checkout 611ms
! headers no CSP · HSTS missing
! wordpress 6.4.2 (latest 6.8.3) · contact-form-7 outdated
✗ exposed /.env readable → DB_PASSWORD, STRIPE_SECRET_KEY
✗ scripts NEW host on /checkout: cdn-jquery-analytics.top
✓ email SPF ✓ DMARC p=quarantine DKIM google
grade F · 38/100 · 2 critical — Fix it for me?
TLSHSTS · CSPRDAP/checkout uptime.env · .gitWP pluginsMagecart driftSPF · DMARC · DKIM
// 01 — How it works

Three minutes to set up. Then we watch while you sleep.

01

Add your store

Paste your URL. Add one DNS record or meta tag to prove it's yours and unlock deep checks.

02

We scan every night

Eight families of checks run from the outside — the same view an attacker gets. Pro plans add hourly checkout probes.

03

Read it, or hand it off

Instant alerts when something breaks, a weekly report your non-technical self can read, and a Fix-it-for-me button.

// 02 — What we check

TLS certificate

Validity, expiry countdown, protocol version, legacy TLS still enabled.

Security headers

HSTS, CSP, clickjacking, nosniff, referrer & permissions policy, cookie flags.

Domain expiry

RDAP lookup so a lapsed domain never takes your store (and email) down.

Uptime & checkout

Home, cart and checkout reachability and latency — hourly on Pro.

Leaked files

.env, .git, wp-config backups, phpinfo, backup.zip, open directories.

Platform & plugins

WordPress/WooCommerce core and plugin versions vs. latest, user enumeration.

Card-skimmer drift

Every third-party script on checkout, baselined — new hosts trigger an alert.

Email spoofing

SPF, DMARC and DKIM so nobody can send fake order emails as you.

// 03 — The weekly report

Security, translated.

Every Monday you get one email: a grade per store, what changed, and what each problem means for your sales — not a wall of CVE numbers. Agencies get it white-labelled for their clients.

  • Grade A–F and a 0–100 score per store
  • Only new problems trigger alerts — no nightly nagging
  • Every finding has a one-line fix
  • “Fix it for me” sends it to Evosec engineers
ShopGuard // weekly report
1 store needs attention this week
Demo Merchants Co. · Sep 29 – Oct 6
A
Atelier Lune atelier-lune.example
No open issues. Nice.
96
B
Northwind Coffee northwind-coffee.example
Up 47 points since the .env leak was fixed.
82
F
Peak Outfitters peak-outfitters.example
Down 31 points
critical New script on your checkout page

A script from a domain we've never seen is running where customers type card numbers. That's how card skimmers work.

Fix it for me →
// 04 — Pricing

Cheaper than one hour of incident response.

Monthly, cancel anytime. All plans include every check.

Starter
$19/mo

One store, watched every night.

  • 1 store
  • Daily security scan
  • Plain-English weekly report
  • Email alerts
  • Card-skimmer script drift detection
Start with Starter
Most popular
Pro
$49/mo

For merchants who can't afford a bad Black Friday.

  • Up to 3 stores
  • Daily security scan
  • Hourly uptime & checkout checks
  • Slack + email alerts
  • Everything in Starter
Start with Pro
Agency
$99/mo

Monitor every client store from one console.

  • Up to 15 stores
  • White-label PDF/email reports
  • Client seats (read-only)
  • Hourly uptime & checkout checks
  • Everything in Pro
Start with Agency
// 05 — FAQ

Questions merchants ask us.

Is it safe to let you scan my store?+

Yes. Until you verify ownership we only do what a visitor's browser does: load public pages and read DNS. Deeper probes (like checking for a leaked .env) only run after you add a DNS record or meta tag — so nobody can point ShopGuard at a store they don't own. Our scanner also refuses to touch private or cloud-metadata IP addresses.

Do I need to install anything?+

No plugin, no app, no code. ShopGuard checks your store from the outside, exactly like an attacker would — which is the point.

I'm on Shopify. Isn't Shopify already secure?+

Shopify secures the platform. You still own the domain, email DNS, theme code and — most importantly — the third-party apps and scripts running on your checkout. That's where Magecart-style skimmers live, and that's what script-drift detection watches.

What happens when I click “Fix it for me”?+

The findings you selected go straight to Evosec Consulting's engineers. We reply with a fixed-price quote, usually within one business day. No obligation.

Do you store the secrets you find?+

Never. If your .env is exposed we record that it leaked and which variable names are in it — not the values. Then we tell you to rotate them.

Can I cancel anytime?+

Yes, monthly billing, cancel in one click. Your scan history stays exportable for 30 days.

Find out what an attacker sees.

Run a free passive scan now. It takes about twenty seconds and doesn't touch anything you wouldn't show a customer.

Scan my store