A Full Shopify Store Security Audit Checklist
When did you last check who has admin access, which apps can read your orders, or whether your fraud rules still fit your volume? This end-to-end audit checklist covers access, apps, fraud rules, content, and compliance.

Most stores never get audited until something goes wrong. Then everyone scrambles to remember who has access, which app can touch customer data, and whether the fraud rules were ever configured at all. A security audit is how you find those gaps on a calm Tuesday instead of during a breach.
This is an end-to-end checklist you can run quarterly. It is organized into five areas: access, apps, fraud rules, content, and compliance. Work through it top to bottom, check each box, and note anything you cannot immediately confirm. The items you hesitate on are exactly the ones worth fixing.
1. Access and accounts
Your admin is the keys to the kingdom. Most breaches are not clever hacks, they are stolen or stale credentials.
- Review every staff account. Confirm each active account belongs to a current person who still needs access. Remove ex-employees and contractors immediately.
- Enforce two-factor authentication (2FA) on every account, no exceptions, including the owner.
- Right-size permissions. Give each user the minimum access their role needs. A social media manager does not need financial or app-installation rights.
- Check the store owner email is a secure, monitored address with strong 2FA, since it can reset almost anything.
- Review third-party collaborator access. Agencies and freelancers often retain access long after a project ends. Revoke what is no longer needed.
- Confirm strong, unique passwords via a password manager. No shared logins.
- Audit the login history for unfamiliar locations or devices.
2. Apps and integrations
Every installed app is a door into your data. Each one you no longer use is a door you forgot to lock.
- List every installed app and confirm you still actively use it. Uninstall anything dormant.
- Review each app's permissions. Note which apps can read customer data, orders, or payment information. Question anything with more access than its function requires.
- Check app developer reputation. Prefer apps from established developers with clear privacy policies and active support.
- Review API keys and private apps you created. Rotate or revoke any keys that are old, unused, or were shared insecurely.
- Confirm webhooks and integrations point only to endpoints you control and trust.
- Read the data-handling terms of any app touching customer personal data, especially relevant for GDPR if you sell into the EU.
3. Fraud rules and order protection
This is the section most stores skip, and the one that costs the most when skipped. Your storefront can be perfectly secure and still lose thousands to fraudulent orders.
- Confirm fraud filtering is active, not installed-and-forgotten.
- Review velocity rules. Are there caps on how many orders a single email, card, IP, or device can place in a short window? Do the thresholds match your current normal volume?
- Check geography rules. Are you blocking or flagging orders from countries you do not ship to?
- Verify disposable-email blocking. Throwaway and clearly fake email domains should be denied at checkout.
- Confirm IP blocking capability. Can you quickly block an abusive IP or range during an attack?
- Test bot friction. Confirm reCAPTCHA or checkout verification is enabled and functioning.
- Review your manual-review process for high-value or borderline orders. Who owns it, and is there a hold before auto-fulfillment?
- Confirm you have an incident runbook for a live attack, and that your team knows where it lives.
If several of these are gaps, a dedicated filter closes them in one place. Shieldy — Fraud Filter handles velocity, geography, email, and IP rules together, so instead of stitching protections across settings you configure them once and let the filter enforce them on every checkout.
4. Content and storefront integrity
An audit is not only about attackers. It is also about the quiet errors that erode trust and conversions.
- Check checkout over HTTPS and confirm no mixed-content warnings.
- Review theme and custom code for outdated scripts or anything you did not add yourself. Injected code is a real risk.
- Confirm your storefront has no broken or malicious redirects.
- Verify contact and support information is accurate and reachable, a trust signal and, in some regions, a legal requirement.
- Test the full checkout flow as a customer, including on mobile, to confirm it behaves and shows correct pricing.
- Review pricing and discount displays for accuracy, especially sale prices (relevant to EU pricing rules if you sell there).
- Back up your theme before making changes so you can roll back cleanly.
5. Compliance and legal
Compliance is security's quieter twin. The failures are slower but the fines are real, especially for cross-border sales.
- Confirm your privacy policy is present, current, and reflects the apps and data you actually use.
- Verify cookie consent is properly implemented if you serve EU or UK visitors.
- Check your terms and conditions are clear and up to date.
- Confirm your business-identity page (imprint) is complete if you sell into markets that require it.
- Review your refund and return policy for accuracy and legal compliance in your markets.
- For EU sales, verify right-of-withdrawal handling: a compliant withdrawal form, the correct cooling-off period, and proper refund timelines.
That last item is easy to get subtly wrong. If you sell into the EU, Blockly — Right of Withdrawal helps you present the correct withdrawal form and manage the cooling-off window and refunds, turning a fiddly legal duty into a standard, repeatable flow.
Running the audit
A few habits make the audit stick:
- Schedule it quarterly and put it on the calendar so it actually happens.
- Assign an owner for each of the five sections.
- Track findings, not just checkmarks. The value is in the items you could not confirm.
- Turn gaps into dated action items, the same way you would after an incident.
Security is not a project you finish, it is a rhythm you keep. Run this checklist four times a year and you will catch the stale account, the over-permissioned app, and the never-configured fraud rule long before any of them becomes a story you have to explain. When you are ready to close the fraud-rule gaps in one place, Shieldy is a fast first step.
Protect your Shopify store today
Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.
Install on Shopify — Free


