The crawler
MagekwikScanner
The crawler behind Magekwik, a passive security and PCI-exposure audit for Magento 2 and Adobe Commerce storefronts. Operated by 4KTechnologies Ltd (company no. 14234800, trading as Magekwik).
- User-agent
- MagekwikScanner/1.0 (+https://scan.magekwik.com; passive security audit)
- Calls from
- 2.28.34.250/32
- Reverse DNS
- egress.magekwik.com
- Published list
- /ipranges.json
- Contact
- support@magekwik.com
Telling a real request from a borrowed name
Anyone can put MagekwikScanner in a header. The address is the part that
cannot be copied. It reverse-resolves to egress.magekwik.com, and that name
resolves forward to the same address, so the loop closes in both directions:
dig +short -x 2.28.34.250
dig +short A egress.magekwik.com
The same addresses are published at /ipranges.json in the format Googlebot uses, which is the shape Cloudflare's verified-bot IP validation fetches. If a request carries our user-agent from any other address, it did not come from us, and we would like to know about it.
What a scan does
Nothing runs on a schedule and nothing follows links across the web. A scan happens when a
person submits a store URL at scan.magekwik.com, and it reads a fixed list of
publicly reachable paths on that one store. Requests are read-only GET and
HEAD, spaced at least 0.75 seconds apart per host, and the
whole run is bounded by a 90-second budget. Every check it performs is
named at the Vault.
Monitoring subscribers can have a store re-scanned on a schedule. That runs the same read-only checks at the same pace, and it begins only after the subscriber confirms the request from the email address they gave.
What it never does
- It never authenticates, and never submits a form or any other write request.
- It never attempts exploitation and never brute-forces anything.
- It never requests private, internal, or loopback addresses; those are refused before a scan starts.
- It never conceals itself. The user-agent above names us and links back to this site on every request it makes.
robots.txt
Because a scan is initiated by a person for one named store, the scanner does not crawl,
and it does not read robots.txt as a crawl directive. It does fetch the file
as one of the checks: a Disallow list naming admin, backup, or staging paths
advertises exactly what an attacker should try, which is worth telling a merchant about.
Refusing it
Blocking by user-agent is enough to stop every request we make, since we do not disguise them. Blocking the addresses above is the stricter version of the same thing. Either is fine by us: a refused request is never retried under a different identity.
If our traffic caused you a problem, or you want a store excluded from scanning altogether, write to support@magekwik.com and we will deal with it.