Helps Magento 2 stores comply with GDPR by allowing customers to delete accounts and addresses. The Pro version adds billing document management and cookie restrictions.
Follows SemVer in Security & Compliance
These modules follow semantic versioning across their audited release history — version bumps honestly reflect the code changes.
Provides PHP methods to determine a customer's country based on their IP address. Enables features like automatic currency and language switching.
Malware Scanner & File Integrity Monitor for Magento 2
mage2kishan/module-malware-scanner 22
Signature-based malware scanner and file integrity monitor that recursively scans the Magento codebase for webshells, backdoors, cryptominers, and injection payloads, with quarantine support, an admin dashboard, scheduled scans, and email alerts.
Looking for contributors - Help fix build issues
EU Withdrawal Button
zwernemann/module-withdrawal 73
Implements the EU right of withdrawal via button click as required by EU Directive 2023/2673, adding a clearly visible withdrawal button to the customer account area for easy contract cancellation starting June 2026.
Defense-in-depth protection against the PolyShell unrestricted file upload vulnerability (APSB25-94) affecting Adobe Commerce and Magento Open Source up to 2.4.9-alpha2, hardening image content validation and processing with polyglot file scanning and a strict extension allowlist. Supersedes the original markshust patch.
Logs admin actions, login attempts, and page visits for audit trails. Tracks field-level changes and allows reverting data for supported entities.
Provides a dashboard to view Composer packages, their status, and security advisories. Sends email reminders about package upgrades and security issues.
Displays Magento Quality Patch status in an admin grid, eliminating the need for CLI access. Notifies users of available updates for relevant patch packages.
Looking for contributors - Help fix build issues
Manages Content Security Policy rules via Magento CLI, storing them in env.php for environment-specific control without database access. Includes automatic CSP header splitting to avoid size limits on servers.
IronCart Security Scanner for Magento 2
ironcartlabs/magento-scan 60
Read-only Magento 2 security scanner that runs whitebox checks — version/patch status, MAGE_MODE, admin URL, 2FA coverage, env.php permissions, Composer advisories, core file integrity, and more — and emits a structured JSON report with severities and remediation links.
Allows administrators to change customer passwords directly from the customer edit page in the admin panel. Includes a command-line interface for password updates.