forumNew topic

Ran an online security audit on our site — serious vulnerabilities came up, should we believe them?

YYavuz D***Member
Job title
Field sales representative
Sector
Consulting
Organization type
family business
Joined
May 2025
Message
206
#1

We operate a small-scale e-commerce store in Moscow focused on wholesale apparel and textiles. We handle roughly 1,500 orders a year and run on an open-source e-commerce platform. Out of curiosity the other day, I typed our URL into a popular free automated security scanner I found online.

The report claimed we have two 'Critical' and four 'High' vulnerabilities. Scary things were listed particularly that our database could be directly breached and that critical server headers were missing. Seeing all those red warnings made me panic; it suddenly felt like all our customer records and order data were completely exposed.

When I reached out to an independent consultant they quoted 45,000 Rubles for a thorough manual audit. Can these free web scanner results actually be trusted, or are they just trying to scare people into buying services? Which warnings should I genuinely take seriously?

TTuğçe Y***Expert
Job title
Content Editor
Sector
E-commerce
Organization type
20-person company
Joined
Oct 2025
Message
215
Most Helpful#2

Short answer: You should not take reports from free automated scanners at face value, because these tools perform superficial signature matching without having any context of how your application actually works. A large portion of the findings are simply false alarms triggered by harmless configuration differences. However, rather than writing off alerts like database injection or open ports entirely, you should filter them through some basic sanity checks.

Automated scanners mostly just inspect the HTTP headers returned by your web server. For instance, if an anti-clickjacking header is missing or your server version is visible, the tool may instantly flag it as a critical threat. In reality, these omissions alone won't get your site hacked; they are merely tiny reconnaissance hints that might slightly lower the bar for an attacker. What is genuinely dangerous are exposed, unauthenticated admin panel directories, unpatched plugins, and form fields that allow arbitrary command execution or data extraction.

To verify what's going on, follow these steps: 1) Manually test input fields on your forms by inserting special characters like single quotes to see if the server spits out database errors, 2) Verify that your theme and plugins are on their latest versions and patch anything that's outdated, 3) Close any unused ports on your hosting server. As long as you aren't storing customer credit card details on-site and use a hosted payment gateway, take care of these basic hygiene steps yourself and run the scan again before paying 45,000 Rubles.

KKoray E***Expert
Job title
Software developer
Sector
Packaging
Organization type
chain store
Joined
Sep 2023
Message
25
#3

Scanners usually just read the Apache or Nginx version string from the server header and dump every known historic CVE for that release into your report. Meanwhile, your server might already have that vulnerability patched under the hood via OS package updates. If you hide the server version from public headers, half the warnings in those reports magically disappear.

NNuri E***Expert
Job title
General coordinator
Sector
Leather
Organization type
regional distributor
Joined
Feb 2023
Message
386
#4

Most free scanning sites are just marketing funnels. They flash red warning icons and terrifying risk scores, followed immediately by a big 'Clean up vulnerabilities with one click' button at the bottom. What you are seeing is not a genuine penetration test, it's just a scare tactic engineered to sell remediation services.

PPınar K***MemberCommunity member
Joined
Apr 2023
Message
95
#5

I've been managing e-commerce sites for years; whenever a panicked client brings me one of these reports, the vast majority of the flagged items don't pose any actual real-world risk. Automated tools can give you food for thought, but they cannot give you a proper roadmap. My advice: bump up your backup frequency and put two-factor authentication on your admin dashboard.

FFeyza S***Expert
Job title
Export manager
Sector
Cosmetics
Organization type
family business
Joined
Feb 2024
Message
99
#6

Don't go spending money just yet. First, move your admin panel URL away from the default path. Next, ensure a web application firewall (WAF) is active on the server level. Those two simple moves alone will render most automated external scans completely ineffective anyway.

EEmre K***Member
Job title
Courier coordinator
Sector
Law
Organization type
cooperative
Joined
Feb 2025
Message
1
#7

A similar tool flagged five critical vulnerabilities on our own site. When I had our developer look into it, four turned out to be false alarms, and only one was an outdated contact form plugin. Removing that plugin and installing an alternative took half an hour and didn't cost us a single Ruble.

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#8

automated tools usually just scan the headers like a robot and move on. I mean they don't actually test forms one by one to see if they can steal data. imo run another check with a free open-source scanner before panicking and throwing money at it.

HHasan U***MemberCommunity member
Joined
May 2024
Message
41
#9

How does the checkout step work on your site? Do you collect card details directly on your own form, or do you redirect the customer to an external bank page? If you use an external gateway, there’s no risk of card leaks anyway, only the customer address list would be exposed.

note: I wrote this based on my own experience, it might not apply to everyone.

FFeyza Y***MemberCommunity member
Joined
Jan 2024
Message
61
#10

To sum it up: Don't rush into spending 45.000 Ruble just because of red warnings on a report. Most vulnerabilities are just version disclosures and missing security headers. Update your software, turn on two-factor authentication, and if needed, only get an expert opinion for specific plugins.

GGizem A***MemberCommunity member
Joined
Oct 2025
Message
341
#11

You're right. Everyone rushing into website security audit gets stuck at the same point.

If I were you, I'd go this route.

MMurat T***MemberCommunity member
Joined
Apr 2025
Message
53
#12

Let me summarize the topic since several different answers were given. Security isn't absolute; it's about making attacks not worth the effort.

If you get three different answers on a topic the question was asked wrong. Proven by experience.

İİsmail E***Member
Job title
Logistics planning
Sector
Energy
Organization type
medium-sized business
Joined
Jun 2025
Message
144

Doki · E-commerce infrastructure · 2023

#13

i'd appreciate it if you shared the outcome.

OOsman E***MemberCommunity member
Joined
Jun 2024
Message
401
#14

Correct. If permission and scope aren't in writing, don't start that test.

This is my opinion, I'm not claiming it's absolute truth.

KKeremMember
Job title
Agency sales
Joined
Jul 2024
Message
94
#15

I felt relieved reading this answer, so it's not just me. Forgotten test environments are more often the entry point than live systems.

Forgotten test environments are more often the entry point than live systems. Of course, it varies if your situation is different.

NNeslihan C***Member
Job title
Operations director
Sector
Law
Organization type
regional distributor
Joined
May 2023
Message
4

Doki · Backup setup · 2023

#16

Noted, thanks.

HHakan C***Member
Job title
Country Manager
Sector
Furniture manufacturing
Organization type
workshop
Joined
Jan 2025
Message
417
#17

We got stuck at the same point for a while. If you scold false alarms nobody will report again.

Of course, it varies if your situation is different.

ZZerrin C***Member
Job title
Supply chain manager
Sector
Healthcare services
Organization type
workshop
Joined
Jan 2024
Message
10
#18

I went through the same thing. The harder it is to reverse a decision, the slower you should make it.

NNazlı K***MemberCommunity member
Joined
Apr 2024
Message
104
#19

I have a question. When you try to change everything at once nothing settles.

VVahide K***Member
Job title
Graphic Designer
Sector
Energy
Organization type
120-person company
Joined
Nov 2023
Message
411
#20

Let's separate the concepts, they're getting mixed up. Payment information changes are never verified through the channel they came from.

When you try to change everything at once, nothing settles. Hope this helps.

Reply