EcomScan is a host-resident Go scanner plus a tenant-isolated API and dashboard. It evaluates ecommerce files, optional platform databases, component vulnerabilities, file changes, and supported host evidence — then uploads the structured result for investigation.
Each surface below maps to code and API records in the current product. Remediation remains operator-controlled.
Content signatures, MD5/SHA-256 hashes, IOC matches, heuristics, delta evidence, and optional YARA evaluate PHP, JavaScript, HTML, and related files.
Explicit database scans inspect WordPress/WooCommerce and Magento data using credentials parsed from the local platform configuration.
Supported hosts add exposed-service, persistence, and active-process observations to the scan result without claiming automatic containment.
Platform inventory and vulnerability data identify affected components, known CVEs, CVSS context, and exploit-in-the-wild signals where available.
The API publishes versioned bundles of active hashes and signatures. Agents verify Ed25519 signatures and can fall back to a previously verified cache.
The dashboard exposes stores, scans, findings, alerts, incidents, shared threats, runbook checklists, compliance checks, and exportable API data.
Monitor mode watches the configured path and logs filesystem events locally, reports agent health, and uploads periodic scan results on the configured interval. It must be started explicitly by the operator or a service manager.
The dashboard can store provider configuration, validate credentials, and send manual test payloads for Slack, PagerDuty, Jira, Splunk, Datadog, Elastic, Microsoft Teams, and generic webhooks. Cloudflare credentials can be validated. Automatic event dispatch and firewall blocking are not enabled yet.
EcomScan does not currently instrument checkout form fields, observe browser network egress, apply CSP, or block exfiltration at the edge. Those capabilities require a separate browser collection and privacy design before they can be represented as product features.
The generated key response includes the install, scan, and monitor commands for that store.