Magento security, upgrades and emergency response

Find the risk.
Fix the store.
Keep it moving.

A UK Magento support team for patches, failed PCI scans, Magento 1 rescue work, Magento 2 upgrades and urgent production fixes.

15+ years in ecommerce
Emergency triage in hours
Staged, tested deploys
magentopatches.scan
Magento risk scan

Passive checks only: no login attempts, no payloads, no intrusive probing. Same public-surface logic merchants already trust from MageReport-style checks.

Established Magento support team
Security patches · upgrades · emergency response · managed support
Magento 2 retailers·4x4AT·Majorelle Interiors·Plants Express·Field & Fawcett
Support desk
2.4.8 upgrade queuedok
PCI patch verifiedok
Cloudways migration plannedok
Incident response activelive
Magento Patches
UK Magento support team
02 · Why Magento Patches

A proper support team.
Not a ticket queue.

Magento Patches is built for merchants who need calm, technical help when the store is behind on patches, stuck on an old version, failing a PCI scan or starting to creak under real traffic.

The service is deliberately focused: Magento security, version upgrades, emergency stabilisation, hosting migrations and managed maintenance. That narrow scope keeps response fast and recommendations practical.

You get senior technical judgement, written plans, rollback routes and clear reporting. No vague handovers, no mystery retainers, and no production changes without a tested path back.

15+
Years on Magento
£5M
Portfolio managed
200+
Patches installed
03 · What you actually get

A typical patch engagement, end to end.

Not vague promises. The actual sequence followed whenever a patch lands on your store.

  1. 01
    Audit & scope

    Pull your current Magento version, list installed extensions, identify customisations that touch core. Spot the patches you actually need versus the ones safe to skip.

  2. 02
    Backup & rollback plan

    Full database snapshot, codebase tagged in Git, documented rollback procedure. If anything goes sideways, we're back in production in under 15 minutes.

  3. 03
    Apply to staging

    Patch goes onto an environment that matches production. Composer dependencies resolved, extensions tested, no surprises.

  4. 04
    Regression test

    Top 5 user journeys walked manually: homepage → category → product → checkout → confirmation. Plus admin → catalogue, admin → orders.

  5. 05
    Production deploy

    Pre-agreed maintenance window. Most patches deploy in 5–20 minutes of actual downtime. You can watch live if you want.

  6. 06
    Verify & report

    MageReport rescan, headers check, written summary of what changed and what to watch for over the next 14 days.

05 · Pricing

Transparent pricing,
no surprises.

Every engagement starts with a fixed quote. These are typical starting points — your final price depends on the state of your store, not on what we think you'll pay.

Starting at
£99
per patch, installed
Single patch install
  • Pre-patch backup & rollback plan
  • Patch applied on staging first
  • Regression test against your top 5 user journeys
  • Post-patch MageReport verification
  • Written report, 24-hour turnaround
  • 14-day regression support
Starting at
£499
clean M2 minor upgrade
Version upgrade
  • Compatibility audit of all extensions
  • Test environment matching production
  • Database upgrade with rollback safety
  • Composer dependency resolution
  • Performance regression check
  • Cutover plan with downtime window
Starting at
£99
/ month · Bronze tier
Managed Magento
  • Magento patch monitoring
  • Monthly security and performance report
  • Uptime monitoring with alerts
  • Priority booking for patch work
  • Discounted planned work rates
  • Emergency access when needed
06 · FAQ

Things people
always ask.

Not in here? Email the team and you'll get a proper answer.

hello@magentopatches.com
How do I know if my Magento is actually secure?+

Run the scan at the top of this page — it checks public signals similar to the checks merchants already use through MageReport-style tooling.

For a deeper view, an authenticated audit reviews things the public surface cannot see: extension versions, admin users, database integrity, file permissions, hosting configuration and deployment history.

How long does a patch install actually take?+

Two to four hours of engineering time per patch is typical. Most of that is testing, not the patch command itself. A clean Magento 2 store can be quick; a heavily customised store with 40+ extensions can take a full day if compatibility issues surface.

Fixed quotes are agreed before work starts, so the price is clear before production is touched.

Can you still work on Magento 1?+

Yes. Magento 1 went end-of-life in June 2020, but plenty of stores are still trading on it. Magento Patches can handle community-maintained patches, PCI review work and migration planning.

The recommendation will be practical: stabilise where needed, migrate when the risk and commercial case justify it.

Do you offer fixed prices or hourly?+

Fixed quotes are used for defined work such as patches, audits and planned upgrades. Hourly billing is reserved for emergency support or open-ended retainer work where the cause is unknown at the start.

If scope changes mid-project, the change is agreed before extra work starts.

What happens if something breaks after the patch?+

Every patch install includes a 14-day regression support window. If something that worked before the patch stops working because of the patch, it is handled inside that window.

Pre-existing bugs, unrelated hosting issues or changes made elsewhere are scoped separately.

Do you work with my hosting provider?+

Almost certainly. Recent work covers Nexcess, Cloudways, Adobe Commerce Cloud, Redis, Elasticsearch/OpenSearch, Cloudflare and common LEMP stacks.

SSH or deployment access is usually enough; owner-level hosting passwords are not normally required.

How quickly can you start in a genuine emergency?+

Emergency requests are triaged as quickly as possible, with a 2-hour response target during UK business hours. Active compromise, checkout failure and revenue-impacting outages are prioritised first.

Do I need to give you full admin access to my store?+

For most patch work, the team needs SSH or deployment access, database read access and a Magento admin account with developer-level permissions.

You will get a clear access request listing what is needed and why.

What's your process for a major version upgrade?+

Three phases. (1) Compatibility audit — every extension, every customisation, every theme override gets checked against the target version. You get a written report on what'll work, what needs replacing, and what'll break. (2) Staged upgrade — build the new version in parallel, migrate data, run regression tests. (3) Cutover — pre-agreed window, usually 1–2 hours of downtime, with rollback ready.

A typical M2 minor upgrade (e.g. 2.4.6 → 2.4.8) takes 5–10 working days. A major M1 → M2 migration is 6–12 weeks depending on data complexity.

Are you Adobe-certified?+

Magento Patches is positioned around practical production experience: patching, upgrades, emergency recovery, hosting migrations and support operations.

If Adobe certification is a procurement requirement, mention it during the call and the team will confirm the best route before scope is agreed.

Two ways to start.
Both free.

Either run a scan and see what comes back, or book a half-hour call and we'll talk through it together.