Shopify Store Security & Vulnerability Patching
Shopify secures the platform, the hosting and the PCI scope around checkout. Everything else — staff access, app permissions, custom code and the third-party scripts somebody pasted into your theme two years ago — is yours. We audit and maintain that half, because that is the half that actually gets stores compromised.
Book a Free Technical Call
Why it matters
Shopify is not the weak point. Your staff accounts and your app list usually are.
Security on Shopify is a shared responsibility, and merchants consistently misread the split. Shopify owns the infrastructure, the platform patching and PCI compliance for checkout — that part is genuinely well handled and it is not where incidents start. You own everything above it: who has admin access, what permissions they hold, which apps you installed and what data those apps asked for, the custom code in your theme, and every third-party script a marketer added without telling anyone. When a Shopify store is compromised, the cause is almost always a reused password on a staff account, an over-permissioned app, or code left behind by an app that was uninstalled months ago. None of those are platform vulnerabilities, and none of them get patched by Shopify on your behalf.
Sound familiar?
The honest warning signs, most of which are about people rather than code.
Security incidents on Shopify rarely announce themselves. They show up first as sloppy access habits nobody has had time to tidy up.
- You believe Shopify handles security, so nothing on your side needs reviewing at all.
- There are staff accounts in your admin you cannot confidently match to a current employee.
- Your agency, freelancer and email tool all log in through the same shared account.
- Nobody has looked at your installed app list, or what those apps can access, in over a year.
- Scripts load on your storefront from vendors you can no longer name or account for.
- A staff member left recently and nobody is certain their access was actually revoked.
What's included
What ongoing Shopify security actually involves
Not a scan and a certificate. The specific, unglamorous checks on the parts of the store you are responsible for.
Staff accounts and 2FA
Every human with admin access gets a named account with two-factor authentication enabled — no shared logins, no generic 'agency@' credential passed around Slack. We review the account list on a schedule, because staff lists drift far faster than anyone expects and a dormant admin account is a live risk.
Least-privilege permissions
Most people in your admin do not need full access, and giving it to them is how a phished marketing login becomes an emptied catalogue. We map each role to the permissions it genuinely requires, then trim the rest. It is tedious, it takes an afternoon, and it contains the blast radius of every future mistake.
App and data scope audits
Every installed app requested access to something — customer data, order data, the ability to write to your theme. Most merchants approved those requests without reading them. We list every app, what it can reach, whether it is still in use, and whether the access it holds is proportionate to the job it does.
Removing dead apps and their leftovers
Uninstalling an app does not always remove the code it injected. Orphaned snippets, script tags and asset files sit in your theme for years, still loading, still calling out to a vendor who may no longer maintain them. We remove the app, then remove what it left behind, and confirm nothing broke in the process.
Custom code and third-party scripts
Anything hand-written in the theme is unpatched by definition. We review custom Liquid and JavaScript, check what external scripts are loading and who owns them, and remove tags for tools you stopped paying for. Every third-party script is code you did not write, running on your storefront, with your customers in front of it.
Domain, DNS and email authentication
Your domain is the part of the stack Shopify does not hold. We check DNS records, watch domain and certificate expiry, and confirm SPF, DKIM and DMARC are configured so nobody can send convincing email as your brand. Domain-level failures look exactly like a hack to your customers, whatever the cause.
How it runs
How we secure the half of Shopify you own.
One to two weeks for the initial audit and clean-up, then ongoing reviews as part of the retainer — because access and app lists drift constantly.
- 01
Audit access and apps
Every staff account, every collaborator, every installed app and every data scope, listed in one place. This first pass almost always finds accounts and apps nobody remembers approving.
- 02
Tighten and remove
2FA enforced, shared logins replaced with named accounts, permissions trimmed to what each role needs, and unused apps removed along with the theme code they left behind.
- 03
Review the code layer
Custom Liquid and JavaScript reviewed, third-party scripts inventoried and attributed to an owner, dead tags removed, and DNS plus email authentication checked and corrected.
- 04
Keep it from drifting
Scheduled access reviews, app audits when anything new is installed, and offboarding as a standing step whenever staff or contractors leave. Security decays quietly without a routine.
2FA
On every staff account
Contractors and agencies included
0
Shared logins
Named accounts only, always
90 days
Access and app audit
Staff, permissions, data scopes
24 hrs
Offboarding window
Access revoked when someone leaves
Straight answer
We can reduce your risk. Nobody can honestly promise to eliminate it.
A good fit if…
- Several staff, contractors or agencies hold admin access, and the list changes fairly often.
- You have accumulated apps over years and cannot say what half of them still do.
- Your theme carries custom code, or scripts added by people who no longer work there.
- You handle enough customer data that a compromised account would be a reportable problem.
Probably not, if…
- You want a guarantee you cannot be compromised. No agency and no platform can offer that.
- You are looking for PCI compliance work on checkout — Shopify already owns that scope.
- Nobody internally will enforce 2FA or offboarding, in which case our audit changes nothing.
- You want a one-off scan and a badge. Security is a routine, not a certificate.
Keep exploring
More on Shopify maintenance
Security & Vulnerability Patching is one part of what an ongoing Shopify retainer covers. Here's the rest of the picture.
Shopify Maintenance & Support
The complete retainer — monitoring, patching, fixes and the reporting behind them.
View the serviceClosely relatedBackups & Disaster Recovery
Shopify does not back your store up for you. What to back up, and how to prove it restores.
Read the guideClosely relatedUptime Monitoring & Incident Response
What actually breaks is DNS, apps and deploys. Monitoring the checkout path, not the homepage.
Read the guideAll guides in this series
- App & Theme UpdatesUpdates tested on a duplicate first, because the live store is not a staging site.
- Bug Fixes & Quick WinsThe small broken things nobody owns — and the queue they never leave.
- Content & Copy UpdatesCampaign pages, banners and seasonal swaps, without a developer bottleneck.
- Analytics & Monthly ReportingA report that names what changed and what it did, not a dashboard screenshot.
- Quarterly Strategy ReviewsDeciding what to build next quarter, and what to stop paying for.
Beyond this service
Other things we do
Most stores need two or three of these working together. Book a call and we'll tell you which ones actually move your numbers.
- Shopify Theme DevelopmentCustom themes built from Figma to production Liquid on Online Store 2.0 — fast and merchant-editable.
- Shopify App DevelopmentCustom and public apps, Checkout UI Extensions and Shopify Functions built with React and Polaris.
- Shopify MigrationMove from WooCommerce, Magento or BigCommerce with a full 301 redirect map and zero downtime.
- Shopify SEOTechnical audits, Core Web Vitals, structured data and collection content built around buyer intent.
- Shopify Performance OptimizationFaster load times and green Core Web Vitals — theme refactors, image pipelines and app cleanup.
- Shopify A/B TestingHypothesis-led experiments on product pages and checkout, shipped as native theme code.
- Shopify Email Marketing & KlaviyoFlows, segmentation and campaigns — welcome, abandoned cart, winback and SMS, built and monitored.
- Shopify CRO & FunnelsValue-ladder, tripwire, quiz and post-purchase upsell funnels built to lift conversion and AOV.
- Shopify Maintenance & SupportRetainers covering uptime monitoring, security patching, bug fixes and proactive improvements.
Frequently asked questions
- Stores get compromised, but almost never through Shopify itself. In practice the entry point is a staff account with a reused password and no two-factor authentication, an app with far more access than its job requires, or malicious code added by someone who had legitimate admin access at the time. Shopify patches the platform and owns PCI scope for checkout. It cannot protect you from your own admin users, and that is where the incidents come from.
Not sure who can access your store?
Book a 30-minute call. We'll walk your staff accounts, app permissions and third-party scripts, and tell you what needs removing.
Book a free call