Run a free security scan against any Magento store you have SSH access to - no signup, no account, just one curl command. Same detection engine we run nightly across our own fleet, now available to everyone.
If you run a Magento store with us, you already know WhizzyScan - our free, in-house malware and vulnerability scanner that checks your store every night regardless of your Sansec license status. Today we're extending it to any Magento store, on any host - not just servers we manage directly.
curl https://shopwhizzy.com/gowiz/external/agent | sh
You'll get a private report link at the end. That's it.
Why we built this
Most free scanners either require you to install something permanently, sign up for an account before you can even test it, or lock the real detections behind a paywall. We wanted something closer to how the security community actually works: point it at a store, get a straight answer, no strings attached.
This is also useful if you're evaluating us for hosting or Magento support and want a second opinion on your current store's security posture before moving anything - run it against your existing server, see exactly what it finds, and use the report as a real conversation starter with your current host or developer.
How it works
SSH into the Magento install you want to check (yours, a client's, anything on cPanel, Plesk, or a bare server - it doesn't need to be one of our managed servers), then run:
curl https://shopwhizzy.com/gowiz/external/agent | sh
The script will:
- Auto-detect your Magento root (checks the current directory, then common locations like
public_html,httpdocs,www). - Ask you to confirm the detected path (press Enter to accept it), and optionally ask for an email address for future reports.
- Scan your files and database for known malware signatures, webshells, skimmer code, and a growing list of specific Magento CVEs - the exact same rule engine we run nightly across our own fleet.
- Print a private report link when it's done.
What gets checked
The scan mirrors the same categories you'd expect from a proper security report:
- Core eCommerce platform components - your Magento version against Adobe's security bulletins, plus specific high-risk CVEs verified directly against your code (so a manually patched or spoofed version number can't hide an unpatched vulnerability).
- Database integrity - CMS blocks/pages, configuration values, and order address data checked for known malicious patterns, plus a full list of your admin accounts so you can spot one that shouldn't be there.
- File system scan - PHP and JavaScript files checked for malware signatures, webshells, and payment-skimmer patterns.
- Exposed archives or backups - leftover .zip/.tar/.sql files sitting in your public document root.
- Suspicious custom options uploads - unexpected executable files in the custom options upload directory, a known sign of a successful PolyShell-style attack.
Your report, your link
Once the scan finishes, you get a private URL in this form:
https://shopwhizzy.com/gowiz/external/report/token/<your-token>/
No login required to view it - but treat the link itself as a secret, the same way you'd treat a Stripe or GitHub webhook URL. Anyone with the exact link can see the report, so don't post it anywhere public.
Re-running the scan on the same server later updates the same report, rather than creating a new one each time (capped at 3 scans per 24 hours per install, so it can't be abused as a load generator).
Already a ShopWhizzy client? Your servers are already covered automatically every night - this is for anything outside our managed fleet: a second store, a client's server, or a store you're thinking about migrating to us.
Try it now
Pick any Magento store you have SSH access to and run:
curl https://shopwhizzy.com/gowiz/external/agent | sh
If anything comes back critical and you'd like help fixing it, open a ticket and we'll take a look.

