← Back to all services
Service · Patch installation

Security patches, installed properly.

Magento releases security patches multiple times a year. Each one closes vulnerabilities that attackers are actively exploiting on stores like yours. Magento Patches installs them on staging first, tests against your real customer journeys, then deploys to production with rollback ready.

Who this is for

  • Magento 1 store still in production and behind on community patches
  • Magento 2 store with patches pending for more than 30 days
  • MageReport showing red against your URL
  • Failed a PCI scan or QSA assessment on patch hygiene
  • Just want patches handled by someone who's done it 200+ times

What we'll do

The actual sequence, not a vague promise.

  1. 01
    Audit your current state

    Identify Magento version, list installed extensions, check which patches are already applied. You get a clear picture before the quote is confirmed.

  2. 02
    Quote and schedule

    Fixed quote, agreed maintenance window (usually outside business hours), and a written rollback plan.

  3. 03
    Backup and stage

    Database snapshot, codebase tagged in Git, patch applied on a staging environment matching production.

  4. 04
    Regression test

    Top customer journeys walked manually: browse, search, add to cart, checkout, payment, admin order management.

  5. 05
    Production deploy

    Most patches deploy in 5–20 minutes of actual downtime. You can watch live or come back to a confirmation email.

  6. 06
    Verify and document

    MageReport rescan, headers check, written report of what changed and what to watch over the next 14 days.

What you get

Full pre-patch database backup, retained 30 days
Codebase tagged in Git for instant rollback
Patch applied and verified on staging before production
Regression test report covering checkout and admin
Post-patch MageReport scan showing the fix
Written report sent within 24 hours
Headers and PCI hardening review (no extra charge)
14-day regression support window
Pricing
£99
per patch · same-day urgent patch £199
Get a fixed quote →

Every engagement starts with a fixed quote. The price doesn't move once we've agreed it — if scope changes mid-project, we agree the variation before any work happens.

Common questions

Which patches do I actually need?+

Depends on your current version. Magento Patches audits before quoting and confirms which patches are critical, which are recommended, and which can safely wait. No upselling — if you only need one patch, you only pay for one patch.

How much downtime will my store have?+

Most patches deploy with 5–20 minutes of actual downtime, scheduled outside business hours. For zero-downtime deployment on managed hosting (Cloudways, Adobe Commerce Cloud), the cutover can be under 60 seconds.

What if a patch breaks an extension?+

It happens — usually with older third-party modules. Compatibility is checked on staging first, so any conflict surfaces there, not in production. Resolution is included in the quote unless the extension needs a paid upgrade from the vendor.

Can you do this remotely?+

Always. Work is handled remotely via SSH and deployment tools. Physical access and hosting owner credentials are not normally required.

Ready when you are.

Free 30-minute call, no obligation.