TECHNOLOGIES: OPEN EDX

Open edX Penetration Testing

Open edX splits access across course roles, Studio and a platform-wide course-creator setting, so one gap widens who reaches it. We test each role, cohort and content-group boundary against your intended structure. CREST-certified testers, fixed price from £2,290 for a 2-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Open edX Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Roles

Course access in Open edX runs through named course roles, Content Groups and a platform-wide course-creator setting rather than one switch. Get any one of those layers wrong and it changes who can reach your content or your learner data.

Why Open edX access is split across roles, cohorts and one platform-wide switch

Open edX assigns course-level access through named roles rather than a single admin flag. Open edX’s own course team documentation sets out Staff, Limited Staff, Admin and Course Data Researcher as separate roles, with Limited Staff carrying no access to Studio at all and only Admin able to add or remove other team members. We test whether a role granted for one task, marking grades or downloading anonymised learner data, quietly carries more reach than the task needed.

A course can also gate specific units and components by Enrollment Track or by Content Group, and Content Groups are what Open edX’s own cohort documentation uses to give different cohorts of learners different course experiences. A component inherits its parent unit’s restrictions, and Open edX’s own guidance warns against giving a group access to a component when that group cannot reach the unit around it, exactly the contradiction we test for once a course has grown past its original structure.

Some settings sit above any single course. Whether a signed-in user can create a course at all depends on a site-wide course-creator setting that, left disabled, lets anyone with an account start one, and every REST API endpoint declares its own authentication method rather than inheriting one platform-wide default. Where an organisation also runs Moodle, which groups learners into cohorts the same way, our Moodle LMS penetration testing tests that platform on its own terms. We test the course-creator gate, the authentication method on each API endpoint in scope, and any custom XBlock or plugin running with the same privileges as the platform’s own code.

SCOPE

What we pen test on an Open edX instance

OE-01

Course Team Role Boundaries

Studio and the LMS instructor dashboard use four separate course roles, Staff, Limited Staff, Admin and Course Data Researcher, each with a different set of tasks rather than one shared permission. We test whether a Staff or Limited Staff account can reach a task the role guide reserves for Admin, such as resetting grade attempts for every learner in the course or adding another team member to the Admin role.

OE-02

Course Data Researcher Access

The Course Data Researcher role opens the Data Download tab on the instructor dashboard, including anonymised learner IDs and certificate data, without granting the content or grading permissions Staff and Admin hold. We test whether that role stays scoped to the Data Download tab alone, and whether its exports carry anything beyond the anonymised identifiers it is meant to expose.

OE-03

Roles and Permissions Console

A newer Roles and Permissions console lets a Course Admin or global site admin assign and audit Course Admin and Course Staff roles across every course and library they can see, and Open edX’s own documentation notes the feature is disabled by default until a site administrator turns it on. We test whether the console is actually restricted to Course Admins and site admins, and whether a course still on the older role model disagrees with one using the console about who holds access.

OE-04

Course Creator Group and Platform Access

Whether any signed-in user can create a new course at all depends on a single platform-wide setting, the course creator group, and Open edX’s own documentation confirms that leaving it off lets any signed-in user create a course while turning it on routes requests through an approval queue only a site administrator with staff or superuser rights can act on. We test which state that setting is actually in, and whether the approval queue holds once an account is registered.

OE-05

Content Group and Enrollment Track Restrictions

Studio can restrict a unit or component to specific Enrollment Track Groups or Content Groups, and a component automatically inherits whatever restriction is set on its parent unit. We test for the exact contradiction Open edX’s own guidance warns against, a component left open to a group that the unit around it does not actually admit.

OE-06

Cohort Assignment and Cross-Cohort Boundaries

Every learner in an Open edX course sits in exactly one cohort, assigned either manually or at random, and cohorts are what divide discussion topics and gate specific content once Content Groups are associated with them. We test whether a learner’s cohort assignment, and any discussion or content gated to it, actually matches the group they were meant to join, the same cohort-based access question our Moodle LMS penetration testing covers on that platform.

OE-07

XBlock and Custom Component Security

Every course component, whether a built-in problem type or a custom one, is built as an XBlock, a Python class exposing its own fields, handlers and views inside the Studio and LMS runtimes. We test what a custom or third-party XBlock installed on your instance actually does with the data and handler calls it receives, rather than assuming its listing description is accurate.

OE-08

Proctored Exam Provider Configuration

Proctoring is switched on per course through a Proctoring Provider setting in Studio, and Open edX’s own guidance warns that changing provider once proctored exams already exist in the course is not supported. We test how that setting, the verified-track requirement it depends on, and the exam review workflow behave together, rather than testing the proctoring vendor’s own infrastructure.

OE-09

Third-Party Authentication and SSO

Open edX can hand sign-in off to an external identity provider over SAML or OAuth through its third-party authentication framework, configuring your site as a SAML service provider or an OAuth client rather than checking every credential itself. We test how that handoff is configured and what an account provisioned through it can actually reach, the same identity boundary our Okta penetration testing covers on the provider side.

OE-10

REST API and JWT Authentication

Open edX’s REST endpoints are built on Django REST Framework and default to JWT authentication ahead of session cookies, with each endpoint declaring its own authentication classes rather than inheriting one platform-wide rule. We test every API endpoint in scope for a JWT check that is missing, misapplied, or quietly falls back to session authentication where it should not.

OUR PROCESS

Open edX Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree which courses, cohorts and environments are in scope, and set up accounts across Staff, Admin and Course Data Researcher, plus a site administrator account where the Roles and Permissions console or the course-creator setting is in scope.

02

Role and Content-Group Mapping

We map course team roles, cohorts, Content Groups and Enrollment Track Groups against how your organisation actually intends access to work.

03

Manual Testing

A CREST-certified tester manually tests role boundaries, cohort and content-group gating, the authentication configured on each API endpoint, and any custom XBlock in scope, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Open edX pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Open edX Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,290–£3,480
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,640–£8,270
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Open edX Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Open edX instance?

We need at least one account for each course role you use, typically Staff, Admin and, if you use it, Course Data Researcher, plus a learner account in more than one cohort if cohorts gate any content. Where the Roles and Permissions console or the course-creator setting is in scope, we also need a site administrator account to test that layer.

Will testing touch our live learner data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as live proctoring sessions and outbound notification emails, and we do not run destructive tests against real learner records without that agreement in writing.

How long does an Open edX penetration test take?

A single Open edX instance sits in our 2-day single-platform scope, with a report typically landing around 5 working days after kickoff. An instance with several courses using different role or cohort configurations, custom XBlocks, or third-party authentication in scope moves into a wider scope with more testing days.

Is Open edX self-hosted, and does that change how you test it?

Open edX is open-source software that an organisation deploys and runs itself, commonly using Tutor, rather than a vendor-hosted SaaS product. We test the instance and the access you give us, and the accounts we need depend on how your deployment is configured rather than on any single hosting model.

What is out of scope for a single-platform Open edX test?

Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope and covered by our cloud penetration testing service instead. A proctoring vendor’s own infrastructure, and a separate identity provider handling third-party authentication, are also out of scope and quoted separately if either needs its own test.

Do you need our source code?

No. Testing is black-box against the running instance by default. A grey-box option, where we review the configuration behind your Content Groups, cohorts and any custom XBlocks alongside testing, is available if you want faster or deeper coverage of specific findings.

Does the Open edX project have a security or vulnerability disclosure policy we should know about?

The Open edX project’s own security policy asks anyone who finds a vulnerability in the platform code base to report it to security@openedx.org rather than disclose it publicly, and states plainly that no bug bounty is offered for those reports. That policy covers the shared code base itself, and since a self-hosted instance is yours to authorise, we confirm your current testing terms with you during scoping.

Are your testers CREST certified?

Yes. Every Open edX engagement is carried out by UK-based, CREST-certified testers, and your report and attestation letter are recognised by auditors and insurers accordingly.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Open edX instance

Open edX splits access across course roles, Studio and a platform-wide course-creator setting, so one gap widens who reaches it. We test each role, cohort and content-group boundary against your intended structure. CREST-certified testers, fixed price from £2,290 for a 2-day single-platform scope, quoted within 24 hours.