The night watch
for your checkout.
ShopGuard checks your Shopify or WooCommerce store every night — certificates, leaked files, outdated plugins, card-skimming scripts, checkout uptime — and tells you what's wrong in plain English. One click and our engineers fix it.
No install · passive checks · results in ~20 seconds
Three minutes to set up. Then we watch while you sleep.
Add your store
Paste your URL. Add one DNS record or meta tag to prove it's yours and unlock deep checks.
We scan every night
Eight families of checks run from the outside — the same view an attacker gets. Pro plans add hourly checkout probes.
Read it, or hand it off
Instant alerts when something breaks, a weekly report your non-technical self can read, and a Fix-it-for-me button.
TLS certificate
Validity, expiry countdown, protocol version, legacy TLS still enabled.
Security headers
HSTS, CSP, clickjacking, nosniff, referrer & permissions policy, cookie flags.
Domain expiry
RDAP lookup so a lapsed domain never takes your store (and email) down.
Uptime & checkout
Home, cart and checkout reachability and latency — hourly on Pro.
Leaked files
.env, .git, wp-config backups, phpinfo, backup.zip, open directories.
Platform & plugins
WordPress/WooCommerce core and plugin versions vs. latest, user enumeration.
Card-skimmer drift
Every third-party script on checkout, baselined — new hosts trigger an alert.
Email spoofing
SPF, DMARC and DKIM so nobody can send fake order emails as you.
Security, translated.
Every Monday you get one email: a grade per store, what changed, and what each problem means for your sales — not a wall of CVE numbers. Agencies get it white-labelled for their clients.
- Grade A–F and a 0–100 score per store
- Only new problems trigger alerts — no nightly nagging
- Every finding has a one-line fix
- “Fix it for me” sends it to Evosec engineers
A script from a domain we've never seen is running where customers type card numbers. That's how card skimmers work.
Cheaper than one hour of incident response.
Monthly, cancel anytime. All plans include every check.
One store, watched every night.
- 1 store
- Daily security scan
- Plain-English weekly report
- Email alerts
- Card-skimmer script drift detection
For merchants who can't afford a bad Black Friday.
- Up to 3 stores
- Daily security scan
- Hourly uptime & checkout checks
- Slack + email alerts
- Everything in Starter
Monitor every client store from one console.
- Up to 15 stores
- White-label PDF/email reports
- Client seats (read-only)
- Hourly uptime & checkout checks
- Everything in Pro
Questions merchants ask us.
Is it safe to let you scan my store?+
Yes. Until you verify ownership we only do what a visitor's browser does: load public pages and read DNS. Deeper probes (like checking for a leaked .env) only run after you add a DNS record or meta tag — so nobody can point ShopGuard at a store they don't own. Our scanner also refuses to touch private or cloud-metadata IP addresses.
Do I need to install anything?+
No plugin, no app, no code. ShopGuard checks your store from the outside, exactly like an attacker would — which is the point.
I'm on Shopify. Isn't Shopify already secure?+
Shopify secures the platform. You still own the domain, email DNS, theme code and — most importantly — the third-party apps and scripts running on your checkout. That's where Magecart-style skimmers live, and that's what script-drift detection watches.
What happens when I click “Fix it for me”?+
The findings you selected go straight to Evosec Consulting's engineers. We reply with a fixed-price quote, usually within one business day. No obligation.
Do you store the secrets you find?+
Never. If your .env is exposed we record that it leaked and which variable names are in it — not the values. Then we tell you to rotate them.
Can I cancel anytime?+
Yes, monthly billing, cancel in one click. Your scan history stays exportable for 30 days.
Find out what an attacker sees.
Run a free passive scan now. It takes about twenty seconds and doesn't touch anything you wouldn't show a customer.
Scan my store