Security

Shopify Store Security & Vulnerability Patching

Shopify secures the platform, the hosting and the PCI scope around checkout. Everything else — staff access, app permissions, custom code and the third-party scripts somebody pasted into your theme two years ago — is yours. We audit and maintain that half, because that is the half that actually gets stores compromised.

Book a Free Technical Call
Shopify store security monitoring covering staff access, two-factor authentication, app permission audits and custom code review

Why it matters

Shopify is not the weak point. Your staff accounts and your app list usually are.

Security on Shopify is a shared responsibility, and merchants consistently misread the split. Shopify owns the infrastructure, the platform patching and PCI compliance for checkout — that part is genuinely well handled and it is not where incidents start. You own everything above it: who has admin access, what permissions they hold, which apps you installed and what data those apps asked for, the custom code in your theme, and every third-party script a marketer added without telling anyone. When a Shopify store is compromised, the cause is almost always a reused password on a staff account, an over-permissioned app, or code left behind by an app that was uninstalled months ago. None of those are platform vulnerabilities, and none of them get patched by Shopify on your behalf.

Sound familiar?

The honest warning signs, most of which are about people rather than code.

Security incidents on Shopify rarely announce themselves. They show up first as sloppy access habits nobody has had time to tidy up.

  • You believe Shopify handles security, so nothing on your side needs reviewing at all.
  • There are staff accounts in your admin you cannot confidently match to a current employee.
  • Your agency, freelancer and email tool all log in through the same shared account.
  • Nobody has looked at your installed app list, or what those apps can access, in over a year.
  • Scripts load on your storefront from vendors you can no longer name or account for.
  • A staff member left recently and nobody is certain their access was actually revoked.

What's included

What ongoing Shopify security actually involves

Not a scan and a certificate. The specific, unglamorous checks on the parts of the store you are responsible for.

Staff accounts and 2FA

Every human with admin access gets a named account with two-factor authentication enabled — no shared logins, no generic 'agency@' credential passed around Slack. We review the account list on a schedule, because staff lists drift far faster than anyone expects and a dormant admin account is a live risk.

Least-privilege permissions

Most people in your admin do not need full access, and giving it to them is how a phished marketing login becomes an emptied catalogue. We map each role to the permissions it genuinely requires, then trim the rest. It is tedious, it takes an afternoon, and it contains the blast radius of every future mistake.

App and data scope audits

Every installed app requested access to something — customer data, order data, the ability to write to your theme. Most merchants approved those requests without reading them. We list every app, what it can reach, whether it is still in use, and whether the access it holds is proportionate to the job it does.

Removing dead apps and their leftovers

Uninstalling an app does not always remove the code it injected. Orphaned snippets, script tags and asset files sit in your theme for years, still loading, still calling out to a vendor who may no longer maintain them. We remove the app, then remove what it left behind, and confirm nothing broke in the process.

Custom code and third-party scripts

Anything hand-written in the theme is unpatched by definition. We review custom Liquid and JavaScript, check what external scripts are loading and who owns them, and remove tags for tools you stopped paying for. Every third-party script is code you did not write, running on your storefront, with your customers in front of it.

Domain, DNS and email authentication

Your domain is the part of the stack Shopify does not hold. We check DNS records, watch domain and certificate expiry, and confirm SPF, DKIM and DMARC are configured so nobody can send convincing email as your brand. Domain-level failures look exactly like a hack to your customers, whatever the cause.

How it runs

How we secure the half of Shopify you own.

One to two weeks for the initial audit and clean-up, then ongoing reviews as part of the retainer — because access and app lists drift constantly.

  1. 01

    Audit access and apps

    Every staff account, every collaborator, every installed app and every data scope, listed in one place. This first pass almost always finds accounts and apps nobody remembers approving.

  2. 02

    Tighten and remove

    2FA enforced, shared logins replaced with named accounts, permissions trimmed to what each role needs, and unused apps removed along with the theme code they left behind.

  3. 03

    Review the code layer

    Custom Liquid and JavaScript reviewed, third-party scripts inventoried and attributed to an owner, dead tags removed, and DNS plus email authentication checked and corrected.

  4. 04

    Keep it from drifting

    Scheduled access reviews, app audits when anything new is installed, and offboarding as a standing step whenever staff or contractors leave. Security decays quietly without a routine.

2FA

On every staff account

Contractors and agencies included

0

Shared logins

Named accounts only, always

90 days

Access and app audit

Staff, permissions, data scopes

24 hrs

Offboarding window

Access revoked when someone leaves

Straight answer

We can reduce your risk. Nobody can honestly promise to eliminate it.

A good fit if…

  • Several staff, contractors or agencies hold admin access, and the list changes fairly often.
  • You have accumulated apps over years and cannot say what half of them still do.
  • Your theme carries custom code, or scripts added by people who no longer work there.
  • You handle enough customer data that a compromised account would be a reportable problem.

Probably not, if…

  • You want a guarantee you cannot be compromised. No agency and no platform can offer that.
  • You are looking for PCI compliance work on checkout — Shopify already owns that scope.
  • Nobody internally will enforce 2FA or offboarding, in which case our audit changes nothing.
  • You want a one-off scan and a badge. Security is a routine, not a certificate.

Frequently asked questions

  • Stores get compromised, but almost never through Shopify itself. In practice the entry point is a staff account with a reused password and no two-factor authentication, an app with far more access than its job requires, or malicious code added by someone who had legitimate admin access at the time. Shopify patches the platform and owns PCI scope for checkout. It cannot protect you from your own admin users, and that is where the incidents come from.

Not sure who can access your store?

Book a 30-minute call. We'll walk your staff accounts, app permissions and third-party scripts, and tell you what needs removing.

Book a free call