Online Marketplace Penetration Testing
CREST-accredited penetration testing for two-sided platforms, multi-vendor marketplaces and gig marketplaces: seller portals, buyer apps, listing platforms and marketplace payouts. We test whether seller A can reach seller B’s data, whether a buyer can act as a seller, and whether fees, refunds and payouts can be redirected or tampered with. Fixed quote in 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
trust boundaries sit at the centre of every marketplace test: seller versus seller, buyer versus seller, and staff versus partner. Each one needs its own test cases.
The Trust Boundaries Your Marketplace Actually Has to Hold
Five parties, one platform. A marketplace test starts by naming who can act: buyers who purchase, sellers who list and fulfil (or arrange fulfilment through a partner), your own marketplace staff who moderate and support, the payment processor that moves money between them, and any fulfilment or logistics partner that reads order and address data. Every role gets its own test account and its own list of things it should never be able to reach.
Trust boundaries. Seller A should never read, edit or export seller B’s listings, orders, messages or payout details. A buyer account should never gain seller capabilities by changing a role flag or replaying a signup request. Your own staff and any fulfilment or logistics partner should each see only the fields their job requires, not the whole order record.
Money, payouts and webhooks. We test whether commission and fee calculations can be manipulated client-side, whether a refund can land on an account that never paid, whether a dispute can be closed in a seller’s favour without buyer input, and whether the payout recipient on a seller’s account can be changed without re-verification. Order-state and payment-callback webhooks from your Stripe or Adyen integration are tested for signature verification, replay resistance and correct state transitions, alongside the checkout and payment flow itself. Platforms built on connected-account models push payouts and onboarding checks onto each seller’s own account, but the platform still decides who can trigger a payout and what a support agent can override. Stripe Connect documentation.
Who we test for. Two-sided platforms, multi-vendor marketplaces and gig marketplaces selling physical goods, digital goods or services. See our retail and e-commerce page for the wider commerce picture, and our guide to marketplaces and the NIS Regulations for the regulatory background.
SCOPE
What We Test in an Online Marketplace
Seller-to-Seller Isolation
Swapping listing, order and message IDs between seller accounts. Can seller A view seller B’s buyers, payout details, or edit a live listing that isn’t theirs?
Buyer Accounts & Orders
Order history, saved addresses, saved payment methods and messaging threads tested across every buyer account, plus privilege escalation from buyer to seller.
Payouts, Fees & Refunds
Commission and fee calculation tampering, refund-to-unrelated-account abuse, payout recipient changes, and dispute or chargeback workflows that bypass review.
Staff & Support Access
Marketplace staff impersonation of buyers and sellers, moderator override powers, dispute-resolution actions, and whether every override is logged.
Listings, Reviews & Search
Listing price and stock tampering, review and rating manipulation, category and search-ranking abuse, and bulk listing import endpoints.
Marketplace & Partner APIs
Broken object-level authorisation, webhook signature and replay checks for order-state and payment callbacks, and API keys scoped to one seller or partner.
Fulfilment & Logistics
Integrations with fulfilment and logistics partners: shipping-label generation, tracking-data exposure, and address or order data reaching the wrong partner.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute call covering sellers, roles, payment model and fulfilment partners in scope. Fixed-price quote within 24 hours.
Test Accounts
You provide staging accounts for at least two sellers and two buyers, plus a marketplace-staff account, and confirm which transactions we’re permitted to run.
Active Testing
3-15 days of hands-on testing by UK-based CREST-certified pen testers, crossing every buyer, seller and staff boundary. Live findings in your client portal.
Report & Retest
CVSS-scored report with a role matrix, walkthrough call, free retest and a letter of attestation for partners and auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST online marketplace pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.
PCI DSS
Requirement 11.4.2 and 11.4.3: internal and external testing at least every 12 months and after significant change, where your platform sits in the cardholder-data environment.
UK GDPR
Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures.
Amazon SP-API DPP
Contract, not law: apps accessing seller PII must scan every 30 days and complete a penetration test every 365 days under the Data Protection Policy.
OWASP API Top 10
Broken object-level authorisation and related API findings mapped by category across buyer, seller and partner endpoints.
ISO 27001
Annex A 8.8 technical vulnerability management, once you declare that control applicable.
Marketplace Questionnaires
An independent report you can attach to payment processor, fulfilment partner and enterprise seller security questionnaires.
PRICING
Transparent Online Marketplace Penetration Testing Pricing
Pricing depends on the number of seller and buyer roles, payment and payout integrations, and fulfilment-partner APIs in scope. The day count flexes; the included deliverables stay the same across all engagements.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From Online Marketplace Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What is online marketplace penetration testing?
Testing whether a buyer, seller or member of marketplace staff can reach data or actions that belong to someone else: another seller’s listings and payouts, another buyer’s orders, or a dispute and refund outcome they shouldn’t control. We test through the interface, the API and the webhooks your payment processor and fulfilment partners rely on.
What do you need from us to scope a marketplace test?
The URLs or apps in scope, API documentation if you have it, the roles in your platform (buyer, seller, staff, and any partner roles), how many sellers we’re testing across, your payment model and processor, staging accounts for each role, and a note of which transactions we’re permitted to run, for example real refunds versus simulated ones.
Do you test Stripe Connect and Adyen marketplace payouts?
Yes. We test how your platform creates and manages connected seller accounts, how payout recipients and schedules can be changed, and whether webhook events are verified and cannot be replayed. See our Stripe and Adyen pages.
Do you test Amazon Selling Partner API (SP-API) integrations?
Yes, where your marketplace or its sellers integrate with Amazon SP-API. Amazon’s Data Protection Policy requires solution providers that access seller PII to run vulnerability scans every 30 days, complete a penetration test every 365 days, scan code before every release, and remediate critical findings within 7 days and high findings within 30 days. It’s a contractual requirement from Amazon, not a legal one, and we scope testing to match it. Amazon SP-API vulnerability management guide.
How do you handle our payment processor and fulfilment partners during testing?
We test the boundary your platform controls: how you call the processor or partner API, how you verify their responses and webhooks, and what you do with the data they send back. We do not attack the processor’s or partner’s own infrastructure, and any test transactions are agreed in advance and run through sandbox or staging credentials wherever they exist.
Can you test whether a refund or payout can reach the wrong recipient?
Yes. Refund and payout testing covers whether the recipient, amount, timing or approval state of a refund or payout can be changed by a user who shouldn’t control it, including sequences that combine a legitimate refund with an unrelated payout change.
Can you test our multi-vendor marketplace’s checkout before a PCI DSS assessment?
Yes. We test the checkout and payment flow alongside the wider marketplace, and where your platform sits in the cardholder-data environment we scope to PCI DSS Requirement 11.4.2 and 11.4.3 so the report is ready for your QSA or acquirer.
What does a marketplace role matrix look like?
A typical scope: buyer browses, purchases and messages sellers about their own orders only; seller manages their own listings, orders and payout details, and nothing belonging to another seller; marketplace staff moderate listings and mediate disputes, with every override logged; payment processor integration holds tokens and webhook secrets, never raw card data on your servers; fulfilment partner reads shipping address and order contents only, never payment credentials. We confirm each boundary holds through the interface and the API.
What abuse cases do you test for?
Illustrative examples of the technique, not findings from a client engagement. Can a seller edit an order that belongs to another seller by swapping the order ID in an API call? Can a buyer trigger a refund and cancel the linked payout adjustment before it applies, keeping the goods and the money? Can a seller account change its own payout bank details and cash out before your fraud checks or manual review catch the change?
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my online marketplace pen test scope
Tell us how many sellers, buyers and payment or fulfilment integrations you run. A CREST-certified pen tester will contact you within one business day with a fixed price.



