Sentinel security for
Magento 2 stores
Sentinel watches your store for the attacks aimed at Magento: admin password guessing, checkout skimmers, malware and bot floods. When it spots one, a UK Magento engineer deals with it, so you can keep trading.
What Sentinel does for your store
Sentinel is EveryHost's security monitoring, built around the way Magento stores are attacked. Here is what that means day to day.
Safer admin logins
Repeated password guessing and unusual admin sign-ins are spotted early, before anyone gets into your back office.
A watched checkout
Sentinel looks for the changes card skimmers make to checkout and payment files, so tampering is found and dealt with rather than left running.
Bots kept in check
Scrapers, fake searches and traffic floods are spotted and slowed before they use up the capacity your real customers need.
Malware and file checks
Your Magento files are scanned for malware and unexpected changes, the usual sign that someone has left a backdoor behind.
Tuned for Magento
Its rules are written for how Magento really works, so genuine shoppers, payment callbacks and your integrations are not blocked by mistake.
UK engineers on every alert
Alerts go to our UK Magento engineers, day or night. They look into it, act, and tell you what happened in plain English.
How it helps your store
1. It watches
Sentinel runs quietly on your server and checks visits to your store, and your Magento files, against the ways Magento stores are actually attacked. It does not sit in front of your pages, so shoppers see no delay.
2. It flags
Anything hostile raises an alert with our engineers.
3. We act
An engineer blocks the source at your server's firewall, deals with the cause and tells you what happened. If a Magento security patch is needed, we plan it with you.
What Sentinel does not do
Sentinel reduces risk and buys you time to patch. It does not replace Magento security updates. When Adobe fixes a flaw, such as the APSB26-92 account takeover or the APSB26-73 webhooks flaw (CVE-2026-48358), only the patch removes it. Sentinel watches for attempts to exploit it while the patch goes on. It does not replace your payment provider's fraud tools either: if bots are testing stolen cards at your checkout, see our guide to stopping card testing on Magento 2. Nor does it decide which AI crawlers may read your store: that is a robots.txt choice, covered in our guide to blocking AI crawlers on Magento 2.
Some attacks start from an account already on the server, below the layer any firewall can see, as with RefluXFS (CVE-2026-64600). Those are answered by running your store on single-tenant hardware, which is why we offer Magento dedicated hosting UK with no neighbouring stores on the machine. Sentinel guards the running store, while Bastion off-site backup, our add-on, guards the copy you would restore from.
Frequently Asked Questions
For technical teams: how Sentinel works
- A lightweight agent on each server reads the web server and SSH login logs. It is not in the request path, so it adds no latency to page loads.
- Requests are checked against Magento-specific patterns: admin and API probing, SQL injection, known scanning tools, request floods and SSH password guessing.
- Your installed Magento version is compared with Adobe's published security bulletins, so a missing patch is flagged.
- Magento files are scanned for malware and for unexpected changes.
- Sentinel can block abusive IPs at the server firewall automatically, and our engineers review every block.
- Findings go straight to our UK Magento engineers.
Security that is already included
Every EveryHost plan comes with Sentinel and with UK Magento engineers who act on what it finds. Choose a plan, or talk to us about your store first.