Skip to content
Magekwik Scanner home

The crawler

MagekwikScanner

The crawler behind Magekwik, a passive security and PCI-exposure audit for Magento 2 and Adobe Commerce storefronts. Operated by 4KTechnologies Ltd (company no. 14234800, trading as Magekwik).

User-agent
MagekwikScanner/1.0 (+https://scan.magekwik.com; passive security audit)
Calls from
2.28.34.250/32
Reverse DNS
egress.magekwik.com
Published list
/ipranges.json
Contact
support@magekwik.com

Telling a real request from a borrowed name

Anyone can put MagekwikScanner in a header. The address is the part that cannot be copied. It reverse-resolves to egress.magekwik.com, and that name resolves forward to the same address, so the loop closes in both directions:

Confirming the address in both directions
dig +short -x 2.28.34.250
dig +short A egress.magekwik.com

The same addresses are published at /ipranges.json in the format Googlebot uses, which is the shape Cloudflare's verified-bot IP validation fetches. If a request carries our user-agent from any other address, it did not come from us, and we would like to know about it.

What a scan does

Nothing runs on a schedule and nothing follows links across the web. A scan happens when a person submits a store URL at scan.magekwik.com, and it reads a fixed list of publicly reachable paths on that one store. Requests are read-only GET and HEAD, spaced at least 0.75 seconds apart per host, and the whole run is bounded by a 90-second budget. Every check it performs is named at the Vault.

Monitoring subscribers can have a store re-scanned on a schedule. That runs the same read-only checks at the same pace, and it begins only after the subscriber confirms the request from the email address they gave.

What it never does

  • It never authenticates, and never submits a form or any other write request.
  • It never attempts exploitation and never brute-forces anything.
  • It never requests private, internal, or loopback addresses; those are refused before a scan starts.
  • It never conceals itself. The user-agent above names us and links back to this site on every request it makes.

robots.txt

Because a scan is initiated by a person for one named store, the scanner does not crawl, and it does not read robots.txt as a crawl directive. It does fetch the file as one of the checks: a Disallow list naming admin, backup, or staging paths advertises exactly what an attacker should try, which is worth telling a merchant about.

Refusing it

Blocking by user-agent is enough to stop every request we make, since we do not disguise them. Blocking the addresses above is the stricter version of the same thing. Either is fine by us: a refused request is never retried under a different identity.

If our traffic caused you a problem, or you want a store excluded from scanning altogether, write to support@magekwik.com and we will deal with it.