Email confirmed
Checking shop.example.com
You can close this tab. The report will open under the link from your email.
- Opening the store
- Finding a category, a product and the cart
- Recognising the platform and its version
- Checking the path to checkout (a phone adds a product to the cart)
- Running security checks
- Measuring speed on mobile and desktop (the longest step)
- Writing the verdict
E-commerce audit
shop.example.com
What we'd do first
- Show guest checkout before the login step; asking for an account first is the biggest drop-off risk we found.
- Cut the product page LCP from 4.8 s: serve the hero image as AVIF under 200 kB and delay the chat and review widgets.
- Plan the move off Magento 2.4.3 and PHP 7.4; both stopped getting security fixes in 2022.
1
Is the store fast for customers?
Real mobile visitors wait too long.
58% of mobile visits show the main content within 2.5 s (Google's bar is 75%). 71% react to taps within 200 ms.
Chrome user data for this store, last 28 days. Retail sites convert about 8% better per 0.1 s faster mobile load (Deloitte, “Milliseconds Make Millions”, 2020).
| Page | Mobile score | Desktop score | Main content (LCP) | Tap response (INP) | Layout shift (CLS) |
|---|---|---|---|---|---|
| Home/ | 41 | 78 | 4.1 s | 240 ms | 0.04 |
| Category/women/dresses.html | 38 | 74 | 4.4 s | 310 ms | 0.11 |
| Product/linen-summer-dress.html | 35 | 71 | 4.8 s | 280 ms | 0.02 |
| Cart/checkout/cart/ | 52 | 83 | 3.1 s | 190 ms | 0.01 |
What slows it down
Hero and product images
1.8 MB JPEG on the product page on mobile; no AVIF or WebP, no size variants.
Third-party scripts
14 scripts load before the page is usable: chat, 3 ad pixels, reviews widget, 2 tag managers.
JavaScript bundle
2.3 MB of JavaScript on the category page (RequireJS modules, jQuery UI, Knockout).
Server response
Time to first byte 1.2 s on category pages; full-page cache misses for logged-out visitors.
2
What does the store run on?
- PlatformLegacy
- Magento Open Source 2.4.3Security patches for 2.4.3 ended in 2022.
- BackendLegacy
- PHP 7.4 (X-Powered-By)PHP 7.4 has had no security fixes since November 2022.
- FrontendLegacy
- Luma theme: Knockout, RequireJS, jQuery 3.4.1Knockout: framework from the jQuery era; few libraries and developers still support it.
- CDN / hosting
- Cloudflare
- Payments seen
- PayPal, card (Adyen)
- Search
- Magento native search
Worth adding
Express payments
Apple Pay and Google Pay on product and cart pages. They skip the address form for returning mobile shoppers.
Image CDN
AVIF and WebP in several sizes, generated on the fly. Usually the fastest win for mobile LCP.
Server-rendered storefront
Product and category pages rendered on the server and cached at the edge, while Magento keeps the catalogue and orders.
3
Where can shoppers drop off?
We opened a product, added it to the cart and went to the first checkout step on a phone. No order was placed.
- 1Product page4.8 s
- 2Add to cart1.4 sMini-cart opens, no page reload
- 3Cart3.1 s
- 4Checkout start6.2 sLogin form shown first
HighAccount step before shipping
The checkout opens on a login form. Guest checkout exists but sits below the fold on mobile.
Fix: Start the checkout with the email field and offer an account after the order.
HighCookie banner covers “Add to cart” on mobile
At 390 px width the banner hides the button until the visitor makes a choice.
Fix: Use a bottom bar lower than 25% of the screen, or move the button above it.
MediumNo express payments
No Apple Pay, Google Pay or PayPal Express on the product or cart page.
Fix: Enable express buttons in Adyen and show them next to “Add to cart”.
Medium17 fields on the first checkout step
Company name, VAT ID and a second phone field are required for every order.
Fix: Keep 6–8 required fields; show company fields only after “I need an invoice”.
LowFree-shipping threshold not shown in the cart
The threshold appears only in the site footer.
Fix: Show “€12 to free shipping” in the mini-cart and cart.
4
Is it safe to buy here?
CriticalMagento 2.4.3 has 9 known vulnerabilities
Magento 2.4.3 (generator meta + static paths)Includes remote code execution fixed in later 2.4 releases.
Fix: Upgrade to a supported 2.4 release or plan the move to a supported platform.
HighSession cookie readable from JavaScript
PHPSESSID without HttpOnlyOne XSS bug is enough to take over a logged-in customer's session.
Fix: Set HttpOnly and SameSite=Lax on the session cookie.
MediumNo Content Security Policy
No Content-Security-Policy headerCard-skimming scripts (Magecart) run unnoticed without a CSP on checkout pages.
Fix: Enforce a CSP on /checkout/ first; Magento 2.4 ships a CSP module you can switch to restrict mode.
7 other security checks passed. Same checks as our Security Check.
5
Is headless worth it?
Consider headless, in two steps
For
- Mobile pages are slow on real devices even with Cloudflare in front.
- The Luma frontend (Knockout, RequireJS) limits what your team can change quickly.
- The platform version needs a major upgrade anyway.
Against
- Checkout works and converts; rebuilding it first adds risk.
- A headless storefront needs frontend developers you don't have in-house yet.
How we'd approach it
- 1
Keep Magento for catalogue, prices and orders; expose them through its GraphQL API.
- 2
Build product and category pages first with a server-rendered frontend (Angular SSR or Next.js) cached at the edge.
- 3
Move the checkout in phase two, once the new pages prove the speed gain.
Moving off Magento 2.4.3, Knockout
We build new storefronts next to the old one and switch page types over one by one, while your team keeps selling.
Let our team plan it with you
Go through the audit with our e-commerce team. In 30 minutes you'll know which fixes pay off first and whether headless fits your roadmap.
- No cost
- No NDA
- No sales reps
