---
title: What is ShopSecurity?
description: ShopSecurity - Powerful security features for your cluster
---

[Skip to content](https://knowledge.maxcluster.de/en/what-is-shopsecurity#main-content)

- [English](https://knowledge.maxcluster.de/en/what-is-shopsecurity)
- [Deutsch](https://knowledge.maxcluster.de/was-ist-shopsecurity)

English

Show submenu for translations

[![maxcluster\_byteamblue\_logo\_main](https://knowledge.maxcluster.de/hubfs/maxcluster_byteamblue_logo_main.svg)](https://knowledge.maxcluster.de/en)

Open main navigation

Close main navigation

- - [English](https://knowledge.maxcluster.de/en/what-is-shopsecurity)
    - [Deutsch](https://knowledge.maxcluster.de/was-ist-shopsecurity)

  English
  
  Show submenu for translations
- [maxcluster.de/en](https://maxcluster.de/en)

[maxcluster.de/en](https://maxcluster.de/en)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Knowledge Base (en)](https://knowledge.maxcluster.de/en)
2. [Managed Center](https://knowledge.maxcluster.de/en/managed-center)
3. [ShopSecurity](https://knowledge.maxcluster.de/en/managed-center#shopsecurity)

September 4, 2026

# What is ShopSecurity?

## Powerful security features for your cluster

With the ShopSecurity function, we offer you a tool to check your store installations for known and potential security gaps. Following a scan, you receive detailed reports with concrete recommendations for action, so that any security gaps can be closed particularly quickly. In addition, you will receive recommendations for optimizing the security-relevant settings of your store and server. We provide this function to all our customers at no additional cost.

**Note:** ShopSecurity performs automated security checks. Please review the results regularly and implement any necessary measures in a timely manner to ensure the security of your system.

### **What is checked?**

We distinguish between domain and global malware scans. For each result, a classification is made into the urgency levels "critical", "important" and "recommended". This classification corresponds to our subjective assessment and is based on our many years of experience. In addition to a brief explanation, we also provide concrete instructions for remedying the security vulnerability as well as optional recommendations for action.

#### **Domain scan**

The domain scan analyzes a single domain and the store system installed there. It is available for installations of Magento 1, Magento 2, Shopware 5 and Shopware 6. This scan checks whether the store software used is installed in a current version and whether all available security patches have been applied.

Unprotected configuration files and directories of versioning software, through which secret access data and passwords can be publicly visible, are also detected by the scan. If a version of TLS for encrypting the communication between browser and server is available that is considered to be outdated, we will also point this out to you.

#### **Global malware scan**

The global malware scan checks the entire file system and database for suspicious patterns and known malware. Based on [eComscan's](https://web.archive.org/web/20230602190815/https://sansec.io/ecomscan/) extensive signature database, malware as well as Magento modules with known vulnerabilities are detected. In addition, all files are scanned for potentially dangerous and suspicious patterns, so that often even new malware can be detected.

#### **Ignore list for known false positives**

As part of the automated security checks, known false positives can occur, for example due to test files containing the EICAR signature. In the scan results, these findings are often classified as “critical” even though there is no real threat. Over time, this can lead to reduced sensitivity to genuine warnings.

To address this, ShopSecurity provides an ignore list that lets you define specific files which should no longer be reported by the scans.

**Note:** Entries on the ignore list are excluded from the malware scans and will no longer trigger alerts. Therefore, make sure that these are truly intended test or exception cases without any security risk before adding them to the ignore list.

Typical use cases for the ignore list include:

- Test files used to verify monitoring and security functionality (for example files with EICAR signatures)
- Intentionally stored files that are regularly flagged as suspicious but do not represent a security risk in your specific scenario

Once a file has been added to the ignore list, it will no longer appear as a finding in future ShopSecurity scans, helping to improve the clarity of the reports and keep the focus on real threats.

### **Why ShopSecurity?**

We know how important security is for the existence of an online store. Therefore, our goal is to offer you the most secure e-commerce hosting in Germany. For this reason we are continuously working on improving this product feature and adding more scans. If you have any feedback, suggestions or requests regarding this offer, please send us an email to [shopsecurity@maxcluster.de](https://web.archive.org/web/20230602190815/mailto:shopsecurity@maxcluster.de).

#### **Do you have questions about the results of a scan?**

In the report view of each scan you have the possibility to send questions about this scan to our service via the button "Contact Service". Of course, you can also reach us as usual by phone and e-mail if you have any questions.

If you require any further assistance, please contact our support team by phone at +49 5251/414130 or by email at [support@maxcluster.de](mailto:support@maxcluster.de) 

- [Managed Center](https://knowledge.maxcluster.de/en/managed-center#main-content)

    - [ShopPerformance](https://knowledge.maxcluster.de/en/managed-center#shopperformance)
    - [ShopSecurity](https://knowledge.maxcluster.de/en/managed-center#shopsecurity)
- [General information](https://knowledge.maxcluster.de/en/general-information)
- [Magento](https://knowledge.maxcluster.de/en/magento#main-content)

    - [Information](https://knowledge.maxcluster.de/en/magento#information)
- [Shopware](https://knowledge.maxcluster.de/en/shopware#main-content)

    - [Instructions](https://knowledge.maxcluster.de/en/shopware#instructions)

[![maxcluster-logo\_schwarz\_rot\_ohne\_claim\_cmyk](https://knowledge.maxcluster.de/hs-fs/hubfs/maxcluster-logo_schwarz_rot_ohne_claim_cmyk.png?width=200&height=31&name=maxcluster-logo_schwarz_rot_ohne_claim_cmyk.png "maxcluster-logo_schwarz_rot_ohne_claim_cmyk")](https://maxcluster.de/)

<https://www.xing.com/pages/maxclustergmbh> <https://www.linkedin.com/company/maxcluster-gmbh/> <https://www.facebook.com/> <https://www.youtube.com/@maxcluster>

Copyright © 2025, maxcluster GmbH