TECHNOLOGIES: SYLIUS

Sylius Penetration Testing

Sylius plugins install as Composer packages into the same application, not a sandbox, so a plugin can reach whatever the application can. We test every plugin, resource and channel your team added. CREST-certified testers, fixed price from £2,760 for a 2-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Sylius Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Plugins

A Sylius plugin is installed as a regular Composer package inside the same application rather than an isolated add-on, sharing its configuration, services and database. We test what a plugin can reach beyond the feature it was installed to add.

Why Sylius findings sit in your plugins and channel configuration, not the framework

Sylius describes itself as a headless, open-source eCommerce framework built on Symfony, with a REST and GraphQL API built on API Platform. That means the application inherits Symfony’s security layer wholesale: firewalls for authentication boundaries, access_control rules matched by URL pattern, and Voter classes for the object-level checks a URL pattern cannot express. We test all three, and whether an API operation enforces the same rule as the admin screen or storefront page built on the same resource.

A Sylius plugin is installed with a standard Composer command and runs inside the same application rather than a sandboxed environment, with access to the same services, configuration and database connection unless a plugin was deliberately built to avoid that. We test what a plugin actually reaches beyond the feature it adds, and who in your organisation can install or update one, since doing so is effectively a code-deployment action.

Sylius supports multiple channels, currencies and storefronts managed from a single admin installation. We test whether pricing, promotions, payment methods and customer data configured for one channel stay confined to it, or whether a gap in channel scoping lets one leak into another.

SCOPE

What we pen test on a Sylius application

SY-01

Firewall and access_control Coverage

Sylius inherits Symfony’s firewall and access_control configuration for authentication boundaries and URL-pattern access rules. We test for a route that falls outside every pattern configured, the same class of gap we test on any Symfony application.

SY-02

Voter Coverage on Custom Resources

Object-level checks, such as whether a user can edit a specific order or product, are enforced through Voter classes rather than the firewall. We test every custom resource and admin action that should call one, not only the ones that already do.

SY-03

REST and GraphQL API via API Platform

Sylius exposes its resources through a REST and GraphQL API built on API Platform, alongside the admin panel and storefront. We test whether an API operation enforces the same access rule as its equivalent screen.

SY-04

Plugin Installation and Admin Restriction

A plugin is installed as a Composer package into the same application, not a sandbox, making installation effectively a code-deployment action. We test who can install or update a plugin and what review happens before one reaches production.

SY-05

Plugin Reach Beyond Its Declared Feature

A plugin shares the application’s services, configuration and, unless deliberately isolated, its database connection. We test what an installed plugin can actually read or change outside the feature it was added for.

SY-06

Admin Panel Role and Permission Configuration

Sylius administrators are assigned roles inside the admin panel that gate which sections and actions they can reach. We test for a role that reaches further than the job it was created for requires.

SY-07

Channel and Multi-Store Isolation

A single Sylius installation can manage multiple channels, currencies and storefronts from one admin. We test whether pricing, promotions or customer data set for one channel can be reached or changed through another.

SY-08

Payment Method Gateway Configuration

Each payment method is configured with its own gateway and credentials, scoped to a channel. We test how those credentials are stored and whether a payment method meant for one channel is reachable from another.

SY-09

Shipping Method and Fulfilment Integration

Shipping methods and any connected fulfilment integration are configured per channel alongside payment methods. We test the same integration boundary for shipping that we test for payment: credential handling and channel scope.

SY-10

Environment Configuration and Secrets

As a Symfony application, Sylius relies on APP_ENV and APP_SECRET to control debug tooling and session and CSRF token generation. We test what your production environment actually reports and how APP_SECRET reaches it.

OUR PROCESS

Sylius Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree which plugins, custom resources and channels are in scope and get admin test accounts across your roles.

02

Application Testing

CREST-certified testers work through the Symfony security layer, plugin reach and channel isolation against the rows above.

03

Findings and Retest

Findings are written against the specific resource, plugin or channel involved, with a free retest once you have fixed them.

04

Report and Sign-off

You get a report ready to hand to an auditor or your own engineering team, plus a fixed retest window until every finding is closed.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Sylius pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Sylius Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,760–£4,180
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,520–£9,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Sylius Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Sylius application?

Admin test accounts covering your different roles, plus read access to any custom plugins or resources your team built. We do not need production database credentials to complete most of the scope.

Does testing touch live customer or order data?

We work against a staging clone or test channel wherever your setup allows it, and agree with you during scoping how to handle anything that can only be verified against live data.

Do you test Sylius’s open-source code or our application?

Your application: the plugins, custom resources and channel configuration your team built on top of Sylius. Sylius’s own open-source framework code is not something we test.

What is out of scope?

The Sylius and Symfony framework code itself, and your hosting provider’s underlying infrastructure, unless you specifically ask us to include infrastructure testing.

How long does a Sylius test take?

A single application with a typical number of plugins and channels is usually a 2-day scope. Heavy plugin use or many channels may need more, which we confirm during scoping.

Does Sylius have a security or disclosure policy?

Sylius asks that security issues be reported privately to security@sylius.com rather than through its public issue tracker. For your own deployment, we confirm current hosting-provider terms with you during scoping.

Can you test a specific plugin we built or installed?

Yes. A plugin you built, or a third-party one you installed, is tested for what it can reach beyond the feature it adds, alongside the rest of your application.

Do you need our database credentials?

No. Admin and API-level access, plus read access to your custom plugins and resources, is normally enough to test the logic that matters.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Sylius application

Sylius plugins install as Composer packages into the same application, not a sandbox, so a plugin can reach whatever the application can. We test every plugin, resource and channel your team added. CREST-certified testers, fixed price from £2,760 for a 2-day single-application scope, quoted within 24 hours.