Magebean Documentation
Manage Magento application security from baseline to monitoring.
Learn how to register Magento applications and instances, assign required security baselines, run automated and human verification, manage findings and risk decisions, verify remediation, and monitor the approved security state over time.
Recommended path
From application inventory to monitoring
Begin with the Magento Application and its deployable Instances, then configure the required Baseline, complete an independent Assessment, verify every Item, treat Findings, and continue in Monitoring.
-
1
Application
Create or select a Company, register the Magento Application, and add its production, staging, or development Instance.
-
2
Baseline
Configure a required Baseline from a system Profile and assign it to the Application.
-
3
Assessment
Create an independent Assessment for the selected Instance and Baseline snapshot.
-
4
Verification
Pair Magebean CLI Agent with the Instance and process automated and human-required Items.
-
5
Findings
Treat Findings, submit fixes, and independently verify remediation before resolution.
-
6
Monitoring
Complete the initial Assessment, continue Monitoring, and export immutable Report snapshots when required.
Documentation library
Find guidance for the task in front of you
Start with the available guides and references below. Planned documentation is clearly marked and does not link to unfinished pages.
Getting Started
Set up your Company, register a Magento application and instance, assign a required baseline, and begin the first assessment.
Assessments requiring attention
Prioritized by missing actions and deadlines.
| Finding ↕ | Issue ↕ | Severity ↕ | Status ↕ | Action ↕ |
|---|---|---|---|---|
| F-104 | World-writable sensitive file detected | ● Critical | ● Open | No action |
| F-103 | Admin session lifetime exceeds policy | ● High | ● Ticketed | T-238 · Maya |
| F-102 | Content Security Policy allows unsafe-inline | ● High | ● Deferred | Until Oct 1 |
Coming soon
- Product Overview — Coming soon
- Create or Join a Company — Coming soon
- Add Your First Application — Coming soon
- Add a Magento Instance — Coming soon
- Assign a Required Baseline — Coming soon
- Create Your First Assessment — Coming soon
- Connect Magebean CLI Agent — Coming soon
Applications and Instances
Organize Magento systems by business application, deployable instance, ownership, risk classification, environment, and expected scan frequency.
Instances
Manage Magento instances across your organization.
| Instance ↕ | Environment ↕ | Version ↕ | Findings ↕ | Last Scan ↕ | Status ↕ |
|---|---|---|---|---|---|
| Acme Store — Production | Production | 2.4.7-p3 | 14 | 12 min ago | ● Attention Required |
| Acme Store — Staging | Staging | 2.4.7-p3 | 4 | 2 hours ago | ● Healthy |
Coming soon
- Applications vs Instances — Coming soon
- Application Owners — Coming soon
- Business Criticality — Coming soon
- Data Classification — Coming soon
- Internet Exposure — Coming soon
- Application Lifecycle — Coming soon
- Production, Staging and Development Instances — Coming soon
- Hosting Type and Expected Scan Frequency — Coming soon
- Deployment Revisions — Coming soon
Profiles and Baselines
Start from a system Profile, configure the applicable Rules as a Company Baseline, and assign that Baseline to the Applications that require it.
Baselines
Manage security baselines across your organization.
| Baseline ↕ | Source Profile ↕ | Rules ↕ | Automated / Human ↕ | Status ↕ |
|---|---|---|---|---|
| Production ASVS Level 2 | OWASP ASVS Level 2 | 286 | 151 / 135 | ● Active |
| Magento Production Baseline | Magento Security Best Practices | 198 | 126 / 72 | ● Active |
| PCI Checkout Baseline | PCI DSS 4.0.1 | 144 | 88 / 56 | ● Active |
- Selecting a Security Profile
- Browse the Security Baseline
- Magento Security Best Practices Profile
- OWASP ASVS Profiles
- PCI DSS Profile
Coming soon
- Profiles and Rules — Coming soon
- Create a Baseline from a Profile — Coming soon
- Configure Baseline Rules — Coming soon
- Assign Required Baselines — Coming soon
- Assessment Frequency — Coming soon
- Baseline Changes and Existing Assessments — Coming soon
Assessments and Verification
Create an independent assessment, process its automated and human-required Items, review Evidence, and satisfy the completion rules.
Missing to complete
Resolve these blockers before Monitoring.
| Finding ↕ | Issue ↕ | Severity ↕ | Status ↕ | Action ↕ |
|---|---|---|---|---|
| F-104 | World-writable sensitive file detected | ● Critical | ● Open | No action |
| F-103 | Admin session lifetime exceeds policy | ● High | ● Ticketed | T-238 · Maya |
| F-102 | Content Security Policy allows unsafe-inline | ● High | ● Deferred | Until Oct 1 |
| F-099 | Outdated payment module dependency | Medium | ● Risk Accepted | Reviewed quarterly |
Coming soon
- Create an Assessment — Coming soon
- Assessment Types — Coming soon
- Scope, Owner, Reviewer and Due Dates — Coming soon
- Assessment Item Snapshots — Coming soon
- Automated Verification — Coming soon
- Human-Required Verification — Coming soon
- Submit Evidence — Coming soon
- Review Evidence — Coming soon
- Verification Attempts — Coming soon
- Verification Expiry — Coming soon
- Assessment Progress — Coming soon
- Assessment Completion Rules — Coming soon
Magebean CLI and Agent
Pair Magebean CLI Agent with a Magento Instance, submit idempotent scan results, associate results with deployment revisions, and monitor Agent health.
Magebean CLI Agent
Paired with this Instance
Instance-scoped token · Rotatable · Raw value shown once
Coming soon
- Install Magebean CLI — Coming soon
- Pair an Agent with an Instance — Coming soon
- Create and Rotate Agent Tokens — Coming soon
- Submit a Scan — Coming soon
- Scan Runs and Scan Results — Coming soon
- Idempotent Scan Submission — Coming soon
- Full and Partial Scans — Coming soon
- Agent Health States — Coming soon
- Deployment Revisions — Coming soon
- Stale Results After Deployment — Coming soon
- Run Magebean in CI/CD — Coming soon
- CLI Troubleshooting — Coming soon
Findings and Remediation
Assign Findings, track remediation against severity-based due dates, submit fixes, and independently verify that controls now pass.
Finding disposition
Every open issue needs an accountable next step.
Checkout allows unapproved third-party script sources.
Coming soon
- How Findings Are Created — Coming soon
- Finding Statuses — Coming soon
- Finding Ownership — Coming soon
- Severity and Remediation SLA — Coming soon
- Verification Tickets — Coming soon
- Remediation Tickets — Coming soon
- Submit a Fix — Coming soon
- Pending Verification — Coming soon
- Verify an Automated Fix — Coming soon
- Verify a Human-Required Fix — Coming soon
- Recurring Findings — Coming soon
- Finding Resolution Types — Coming soon
Risk and Exceptions
Request, review, approve, expire, or revoke risk and exception decisions without hiding unresolved security conditions.
Risk and exception decision
Unresolved conditions remain visible.
Independent approval and mandatory review date
Temporary postponement with future expiry
Separate independent review
Coming soon
- Request Risk Acceptance — Coming soon
- Review and Approve Risk — Coming soon
- Risk Review and Expiry — Coming soon
- Revoke Risk Acceptance — Coming soon
- Defer a Finding — Coming soon
- False Positive Review — Coming soon
- Not Applicable Decisions — Coming soon
- Separation of Duties — Coming soon
Monitoring
Continue receiving scan results, detect stale or expired verification, and keep the approved Magento security state visible after the initial assessment.
Baseline monitoring
Current security state against the approved baseline.
Coming soon
- Enter Monitoring — Coming soon
- Recurring CLI Verification — Coming soon
- Scan Frequency — Coming soon
- Scan Required and Scan Overdue — Coming soon
- Agent Offline and Outdated — Coming soon
- Post-Deployment Verification — Coming soon
- Stale Results — Coming soon
- Human Verification Expiry — Coming soon
- Deferral and Risk Review Expiry — Coming soon
- Assessment Review Due — Coming soon
- Monitoring Health States — Coming soon
Reports and Audit
Export immutable Assessment snapshots and review append-only records of user, Agent, and system activity.
Assessment snapshot
Immutable evidence of the assessment at export time.
2026-08-07
Coming soon
- Export a Report Snapshot — Coming soon
- Report Contents — Coming soon
- Assessment vs Report — Coming soon
- Audit Log — Coming soon
- In-app Notifications — Coming soon
Administration and Security
Manage Company membership, dynamic Roles, scoped permissions, secure Evidence, Agent tokens, and approval separation.
Security Reviewer
Company-defined Role · Scoped to selected Instances
Server-side authorization enforces tenant isolation and prevents self-approval.
Coming soon
- Company Membership — Coming soon
- Dynamic Roles — Coming soon
- Permissions — Coming soon
- Role Assignment Scope — Coming soon
- Tenant Isolation — Coming soon
- Server-Side Authorization — Coming soon
- Evidence Storage and Access — Coming soon
- Agent Token Security — Coming soon
- Approval Separation — Coming soon
Reference
Find precise technical references and supporting security resources.
CLI and API reference
Precise commands, endpoints, Rules, and operating guidance.
$ php magebean.phar scan --path=/var/www/magento
Instance Acme Store — Production
Revision deploy-a81f42
Profile basic
Status Scan completedClear checks. Visible human work. Defensible outcomes.
Magebean automates only requirements that can be reliably observed by the CLI or supported integrations. Human-required rules remain visible and must be verified through testing, review, or evidence. Magebean supports security and compliance workflows; it does not provide certification or guarantee compliance.