TECHNOLOGIES: MEDUSA

Medusa Penetration Testing

Medusa checks who calls a route, but each custom route needs its own authentication middleware or it inherits none. We test every custom route, module and workflow built on top of it. CREST-certified testers, fixed price from £2,760 for a 2-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Medusa Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Actors

Medusa’s authenticate middleware checks both the actor calling an API route, such as an admin user, a storefront customer or a custom type, and the method used, such as a session, a bearer token or an API key. We test whether every custom route your team added actually has it applied.

Why Medusa findings sit in your custom routes and modules, not the framework

Medusa protects a route with an authenticate middleware that must be wired up explicitly against a route matcher in your project’s middlewares.ts file, checking both the actor type, such as user or customer, and the authentication method, such as session, bearer or api-key, which the admin scope alone supports. Because this is added per route rather than inherited by default, a custom route created without it is not protected at all.

Medusa’s own documentation shows that a route can be built to accept anonymous requests, and that a request carrying an invalid or expired token is not automatically rejected. Its guidance for doing that correctly is to add a second middleware after authenticate that checks for the presence of credentials and returns a 401 if they failed verification. We test every custom route for exactly this gap: one that quietly falls back to an unauthenticated path when the credential presented was wrong rather than absent.

Inside a custom route, the authenticated actor’s ID is available through auth_context.actor_id, and it is the route’s own code that decides what to do with it, typically resolving the record through Medusa’s Query engine before acting on it. We test whether that resolution step actually filters by the requesting actor, or whether a query built without that filter can return or modify a record belonging to someone else.

SCOPE

What we pen test on a Medusa application

MD-01

Actor Type and Auth Method Enforcement

The authenticate middleware checks both the actor type and the authentication method allowed on a route. We test whether every route enforces the actor and method it is supposed to, not a wider set.

MD-02

Middleware Coverage on Custom Routes

Authentication is applied per route matcher in middlewares.ts rather than inherited by default. We test every custom route added on top of Medusa for one that was never given the middleware at all.

MD-03

Invalid Versus Missing Credential Handling

A route can allow anonymous requests, but Medusa’s own guidance says a request with a token that fails verification needs a separate check to be rejected. We test for a route that treats a bad token the same as no token.

MD-04

Admin and Customer Object-Level Authorisation

A custom route resolves the authenticated actor’s ID and then decides what record to return or change. We test whether that lookup is actually scoped to the requesting actor or can be pointed at someone else’s data.

MD-05

Query Results Scoped to the Requesting Actor

Custom routes commonly use Medusa’s Query engine to fetch data by filter. We test a query built inside a route for a missing filter that would otherwise return records beyond what the caller should see.

MD-06

Store API Session and Bearer Token Handling

The customer-facing Store API accepts session and bearer authentication separately from the Admin API. We test how a storefront session or token is issued, scoped and invalidated on logout.

MD-07

Module Isolation and Data Boundaries

Medusa organises commerce logic into isolated modules, each with its own service and data access. We test a custom or third-party module for a boundary it should not be able to reach into.

MD-08

Third-Party Provider Integrations

Payment, tax and fulfilment providers plug into Medusa as modules that your application calls out to and receives callbacks from. We test how those callbacks are authenticated and what they are trusted to change.

MD-09

Workflows and Server-Side Business Logic

Workflows run the multi-step server-side logic behind an order, refund or fulfilment action. We test whether a workflow can be triggered or resumed from a state it should not be reachable from.

MD-10

Deployment Secrets and Environment Configuration

A self-hosted Medusa deployment holds its own database credentials, API keys and environment configuration. We test how those secrets reach the running application and who or what can read them.

OUR PROCESS

Medusa Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree which custom routes, modules and workflows are in scope and get admin and customer test accounts for your deployment.

02

Deployment Testing

CREST-certified testers work through authentication middleware, module boundaries and workflow logic against the rows above.

03

Findings and Retest

Findings are written against the specific route, module or workflow involved, with a free retest once you have fixed them.

04

Report and Sign-off

You get a report ready to hand to an auditor or your own engineering team, plus a fixed retest window until every finding is closed.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Medusa pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Medusa Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,760–£4,180
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,520–£9,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Medusa Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Medusa application?

Admin and customer test accounts covering your different actor types, plus read access to the custom routes and modules your team built. We do not need production database credentials to complete most of the scope.

Does testing touch live customer or order data?

We work against a staging clone or test-mode data wherever your deployment allows it, and agree with you during scoping how to handle anything that can only be tested against a live environment.

Do you test Medusa’s open-source code or our deployment?

Your deployment: the custom routes, modules, workflows and configuration your team built on top of Medusa. Medusa’s own open-source framework code is not something we test.

What is out of scope?

The Medusa framework’s core code and your hosting provider’s underlying infrastructure, unless you specifically ask us to include infrastructure testing in the scope.

How long does a Medusa test take?

A single application with a typical set of custom routes and modules is usually a 2-day scope. Heavier custom module or workflow use may need more, which we confirm during scoping.

Does Medusa have a security or vulnerability disclosure policy?

Medusa publishes a security policy on GitHub with a dedicated contact for reporting vulnerabilities in its open-source code. For your own deployment, we confirm current hosting-provider terms with you during scoping.

Does it matter if we self-host or use a managed provider?

No, but we scope around it: a self-hosted deployment usually adds infrastructure and secrets-handling questions that a managed provider would otherwise answer for you.

Do you need our database credentials?

No. Admin and API-level access, plus read access to your custom code, is normally enough to test the logic that matters.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Medusa application

Medusa checks who calls a route, but each custom route needs its own authentication middleware or it inherits none. We test every custom route, module and workflow built on top of it. CREST-certified testers, fixed price from £2,760 for a 2-day single-application scope, quoted within 24 hours.