Beta version. Tell us what we got wrong: developers@houseofangular.io

E-commerce audit

shop.example.com

Magento Open Source 2.4.3Legacy · 29 September 2026, 14:32 · audit took 2 min 48 s

What we'd do first

  • Show guest checkout before the login step; asking for an account first is the biggest drop-off risk we found.
  • Cut the product page LCP from 4.8 s: serve the hero image as AVIF under 200 kB and delay the chat and review widgets.
  • Plan the move off Magento 2.4.3 and PHP 7.4; both stopped getting security fixes in 2022.

1

Is the store fast for customers?

Real mobile visitors wait too long.

58% of mobile visits show the main content within 2.5 s (Google's bar is 75%). 71% react to taps within 200 ms.

Chrome user data for this store, last 28 days. Retail sites convert about 8% better per 0.1 s faster mobile load (Deloitte, “Milliseconds Make Millions”, 2020).

PageMobile scoreDesktop scoreMain content (LCP)Tap response (INP)Layout shift (CLS)
Home/41784.1 s240 ms0.04
Category/women/dresses.html38744.4 s310 ms0.11
Product/linen-summer-dress.html35714.8 s280 ms0.02
Cart/checkout/cart/52833.1 s190 ms0.01

What slows it down

Hero and product images

1.8 MB JPEG on the product page on mobile; no AVIF or WebP, no size variants.

Third-party scripts

14 scripts load before the page is usable: chat, 3 ad pixels, reviews widget, 2 tag managers.

JavaScript bundle

2.3 MB of JavaScript on the category page (RequireJS modules, jQuery UI, Knockout).

Server response

Time to first byte 1.2 s on category pages; full-page cache misses for logged-out visitors.

2

What does the store run on?

PlatformLegacy
Magento Open Source 2.4.3Security patches for 2.4.3 ended in 2022.
BackendLegacy
PHP 7.4 (X-Powered-By)PHP 7.4 has had no security fixes since November 2022.
FrontendLegacy
Luma theme: Knockout, RequireJS, jQuery 3.4.1Knockout: framework from the jQuery era; few libraries and developers still support it.
CDN / hosting
Cloudflare
Payments seen
PayPal, card (Adyen)
Search
Magento native search

Worth adding

Express payments

Apple Pay and Google Pay on product and cart pages. They skip the address form for returning mobile shoppers.

Image CDN

AVIF and WebP in several sizes, generated on the fly. Usually the fastest win for mobile LCP.

Server-rendered storefront

Product and category pages rendered on the server and cached at the edge, while Magento keeps the catalogue and orders.

3

Where can shoppers drop off?

We opened a product, added it to the cart and went to the first checkout step on a phone. No order was placed.

  1. 1Product page4.8 s
  2. 2Add to cart1.4 sMini-cart opens, no page reload
  3. 3Cart3.1 s
  4. 4Checkout start6.2 sLogin form shown first
HighAccount step before shipping

The checkout opens on a login form. Guest checkout exists but sits below the fold on mobile.

Fix: Start the checkout with the email field and offer an account after the order.

HighCookie banner covers “Add to cart” on mobile

At 390 px width the banner hides the button until the visitor makes a choice.

Fix: Use a bottom bar lower than 25% of the screen, or move the button above it.

MediumNo express payments

No Apple Pay, Google Pay or PayPal Express on the product or cart page.

Fix: Enable express buttons in Adyen and show them next to “Add to cart”.

Medium17 fields on the first checkout step

Company name, VAT ID and a second phone field are required for every order.

Fix: Keep 6–8 required fields; show company fields only after “I need an invoice”.

LowFree-shipping threshold not shown in the cart

The threshold appears only in the site footer.

Fix: Show “€12 to free shipping” in the mini-cart and cart.

4

Is it safe to buy here?

CriticalMagento 2.4.3 has 9 known vulnerabilities
Magento 2.4.3 (generator meta + static paths)

Includes remote code execution fixed in later 2.4 releases.

Fix: Upgrade to a supported 2.4 release or plan the move to a supported platform.

HighSession cookie readable from JavaScript
PHPSESSID without HttpOnly

One XSS bug is enough to take over a logged-in customer's session.

Fix: Set HttpOnly and SameSite=Lax on the session cookie.

MediumNo Content Security Policy
No Content-Security-Policy header

Card-skimming scripts (Magecart) run unnoticed without a CSP on checkout pages.

Fix: Enforce a CSP on /checkout/ first; Magento 2.4 ships a CSP module you can switch to restrict mode.

7 other security checks passed. Same checks as our Security Check.

5

Is headless worth it?

VerdictConsider

Consider headless, in two steps

For

  • Mobile pages are slow on real devices even with Cloudflare in front.
  • The Luma frontend (Knockout, RequireJS) limits what your team can change quickly.
  • The platform version needs a major upgrade anyway.

Against

  • Checkout works and converts; rebuilding it first adds risk.
  • A headless storefront needs frontend developers you don't have in-house yet.

How we'd approach it

  1. 1

    Keep Magento for catalogue, prices and orders; expose them through its GraphQL API.

  2. 2

    Build product and category pages first with a server-rendered frontend (Angular SSR or Next.js) cached at the edge.

  3. 3

    Move the checkout in phase two, once the new pages prove the speed gain.

Moving off Magento 2.4.3, Knockout

We build new storefronts next to the old one and switch page types over one by one, while your team keeps selling.

Frontend Migration Guide

Let our team plan it with you

Go through the audit with our e-commerce team. In 30 minutes you'll know which fixes pay off first and whether headless fits your roadmap.

  • No cost
  • No NDA
  • No sales reps
Mateusz Stefańczyk
Mateusz StefańczykAngular Google Developer Expert (global title awarded by Google)