Start with the business and technical reality
Web security failures frequently cross boundaries. An outdated extension can provide the entry point, weak server permissions can increase impact, and poor monitoring can allow compromise to remain undetected. Cleaning one malicious file without understanding the path of entry leaves the original risk in place.
Our work considers application code, dependencies, admin access, deployment, hosting, logs, backups and third-party services. For Magento, patch status, extension quality, admin exposure and filesystem integrity are particularly important alongside the wider server environment.
Where an incident has already occurred, containment and evidence preservation come before cosmetic cleanup. The recovery plan then needs to reduce the chance of immediate reinfection.
When clients bring us in
- A site has been compromised or modified unexpectedly
- Magento or plugin patching has fallen behind
- The business wants an independent security review
- Admin accounts or permissions have grown without governance
- Hosting was migrated and hardening was never reviewed
- A development supplier has left and access needs to be audited
What good delivery should leave behind
A successful engagement should improve more than the immediate feature or incident. It should make the system easier to understand, safer to change and more visible to the people responsible for operating it.
- Clear technical ownership and responsibilities
- Maintainable code and configuration
- Visible failures rather than silent data loss
- Controlled release and recovery paths
- Documentation for future developers and operators
- A sensible next-step roadmap rather than permanent firefighting
Technical depth across the parts that matter
The exact scope depends on the existing environment and commercial priorities. We focus on the areas that materially affect reliability, maintainability and delivery rather than adding process for its own sake.
Application review
Assess code, extensions, dependencies and exposed functionality for practical risk.
Patch & dependency posture
Identify outdated components and plan updates with regression risk in mind.
Access
Review admin users, SSH, API credentials, service accounts and least-privilege expectations.
Infrastructure
Assess file permissions, web server, PHP, database exposure, firewall/CDN controls and backups.
Detection
Use logs, integrity checks and monitoring to identify suspicious changes or behaviour.
Incident recovery
Contain, investigate, clean, patch and validate before returning systems to normal operation.
Common failure patterns that create unnecessary cost
Many technical problems are recurring patterns rather than isolated defects. Identifying them early helps avoid repeatedly paying to treat the visible symptom.
- Removing malware without finding persistence
- Old admin or supplier accounts left active
- Shared credentials with no audit trail
- Backups that have never been tested for recovery
- Security tools generating alerts nobody reviews
- Patches postponed because deployment confidence is low
A controlled route from uncertainty to production
We prefer visible, reviewable delivery. The exact sequence changes with the project, but the principle is to reduce uncertainty early and keep each production change understandable.
Technology is part of the answer, not the starting question
No web platform can be made risk-free. The goal is layered defence, reduced exposure, useful detection and a practical recovery route. Security work should also respect availability: a rushed production patch that breaks checkout is not a good security outcome.
Where specialist capability comes from our wider engineering team, we are transparent about the proposed delivery model and match the person or team to the actual requirement rather than presenting a long list of technologies as if every project needs all of them.
Use the level of ownership that fits your team
Defined project
Midoriweb owns an agreed scope with clear milestones, acceptance criteria and release responsibilities.
Specialist workstream
Bring us into one technically difficult area while your existing team or agency owns the wider programme.
Team augmentation
Add developers to your existing process for a fixed period or an ongoing roadmap.
Ongoing technical partner
Combine support, maintenance, monitoring and planned improvement under continuing technical ownership.
Questions worth answering before work starts
Can you clean a hacked Magento site?
We can assist with investigation and remediation subject to access and scope, including identifying persistence, vulnerable components and required hardening.
Do you provide penetration testing?
We can perform technical security review and coordinate specialist testing where a formal penetration-test scope or certification is required.
Can you review third-party extensions?
Yes. Extension quality, update status and unnecessary attack surface are important parts of platform review.
Do you manage patching?
Yes. Patch management can be part of ongoing maintenance and support.
Can you help after an incident if another provider manages hosting?
Yes. We can coordinate with the host and other suppliers while focusing on application and technical evidence.
Should security be ongoing?
Yes. Dependencies, access and threats change, so periodic review and monitoring are more effective than one annual exercise.
Continue exploring
Have a requirement in this area?
Send the current situation, desired outcome, platform or systems involved and any important deadline. We can review the detail first or discuss it in a short consultation.