Sansec eComscan integration
What is Sansec eComscan?
eComscan is a tool from Sansec that scans your Magento or Adobe Commerce codebase to detect vulnerabilities and malware.
How do I get eComscan?
It is included as standard if the website you are scanning is subscribed to AuditIQ Essential and Premium Edition.
How does eComscan integrate with AuditIQ?
After installing the Magento Agent, the Sansec Ecomscan tool must be installed on the live server.
Step 1 — Download Ecomscan
After installation, the binary is usually located at:
~/bin/ecomscan
Example absolute path:
/root/bin/ecomscan
Step 2 — Send Required Information
To complete the integration, please send the following information to the AuditIQ team:
- Ecomscan binary path
Example: /root/bin/ecomscan
- Sansec license key
The key used when running Ecomscan manually.
This allows the auditing system to automatically enable Sansec scanning whenever a user activates an audit.
Example Sansec Run Command
For reference, Sansec Ecomscan is typically executed like:
/root/bin/ecomscan --key=YOUR_SANSEC_KEY
Result
After completing the steps above:
-
Sansec Ecomscan will be available on the server.
-
Security audits can automatically trigger malware scanning.
Installing the Magento Agent via (Option 1) is recommended for better version control and reproducible deployments.
Configuration of eComscan for use with AuditIQ?
If you use the installation script then configuration is automatic. Alternatively, it is possible to manually configure the Audit Agent to use eComscan. In both cases, you will need your eComscan license key, which is provided by On Tap if you have purchased AuditIQ Professional Edition, or can be obtained by purchasing a license directly from Sansec.