Skip to content
Magekwik Scanner home
critical

Magento 1 SUPEE gap

SUPEE SUPEE Magento 1.x

Magento 1 is end-of-life and only protected by cumulative SUPEE (or OpenMage LTS) patches; unpatched instances are actively exploited. Verify the applied SUPEE level.

Is my store affected?

A free passive scan tells you whether your store is on an affected line, along with everything else we can see from outside. It takes under a minute and needs no account.

How we detect this

We infer the platform and version line from signals the storefront serves publicly — the version endpoint when it is reachable, markup and cookie markers when it is not, and the fingerprints of static assets that changed between releases. If that line is one SUPEE affects, we say so.

We do not attempt to exploit it, and we never claim a store is vulnerable from a version string alone. A patched store and an unpatched one on the same release look identical from outside, so the finding is marked inferred and phrased as something to verify. It does not affect your grade.

How to fix it

Migrate off Magento 1, or apply the latest OpenMage LTS / SUPEE patches immediately.

  1. 1

    Preferred: migrate to Adobe Commerce / Magento 2.4.x, which is still receiving security patches. Magento 1 receives none from Adobe at all.

  2. 2

    Interim: move to the latest OpenMage LTS release, which bundles every SUPEE fix plus community patches issued since Magento 1 went end-of-life.

    # see https://github.com/OpenMage/magento-lts releases
  3. 3

    Check which SUPEE patches were ever applied to this installation. Absence of the file usually means none were.

    cat app/etc/applied.patches.list
Check it worked
grep -c SUPEE app/etc/applied.patches.list 2>/dev/null || echo 'no patch list found'

References

From intelligence vault 2026.09.6, released 2026-09-25. What changed