Skip to main content

Sansec eComscan integration

What is Sansec eComscan?

eComscan is a tool from Sansec that scans your Magento or Adobe Commerce codebase to detect vulnerabilities and malware.

How do I get eComscan?

It is included as standard if the website you are scanning is subscribed to AuditIQ Essential and Premium Edition.

How does eComscan integrate with AuditIQ?

After installing the Magento Agent, the Sansec Ecomscan tool must be installed on the live server.

Step 1 — Download Ecomscan

After installation, the binary is usually located at:

~/bin/ecomscan

Example absolute path:

/root/bin/ecomscan

Step 2 — Send Required Information

To complete the integration, please send the following information to the AuditIQ team:

  1. Ecomscan binary path

Example: /root/bin/ecomscan

  1. Sansec license key

The key used when running Ecomscan manually.

This allows the auditing system to automatically enable Sansec scanning whenever a user activates an audit.

Example Sansec Run Command

For reference, Sansec Ecomscan is typically executed like:

/root/bin/ecomscan --key=YOUR_SANSEC_KEY

Result

After completing the steps above:

  • Sansec Ecomscan will be available on the server.

  • Security audits can automatically trigger malware scanning.

note

Installing the Magento Agent via (Option 1) is recommended for better version control and reproducible deployments.

Configuration of eComscan for use with AuditIQ?

If you use the installation script then configuration is automatic. Alternatively, it is possible to manually configure the Audit Agent to use eComscan. In both cases, you will need your eComscan license key, which is provided by On Tap if you have purchased AuditIQ Professional Edition, or can be obtained by purchasing a license directly from Sansec.