Security AI for Magento 2
Catch risky CMS content early
- CMS Scanning Pages and blocks
- AI Summaries Only when rules hit
- File Integrity Hash and heuristics
- Email Alerts Findings and summaries
Catch risky CMS content early
Injected scripts and risky HTML in CMS pages are easy to miss. Security AI scans Magento CMS pages and blocks with deterministic regex checks, then optionally adds AI Core risk summaries when rules hit.
- Flags scripts, event handlers, iframes, and secrets
- Optional AI risk summaries only after rule hits
- Scheduled full scans and scan-on-CMS-save checks
- Findings grid plus email alerts for open risks
Built for your store
Built for Magento 2.4.4+ with PHP 8.1–8.4. Requires AI Core and Toweringmedia Base; detection is server-side and not theme-dependent.
- Requires AI Core and Toweringmedia Base
- Configure under Content Security AI settings
- Findings under Content Security Scan admin grid
- Deterministic-only mode available to avoid AI spend
AI-Assisted CMS Security Scanning for Magento
Security AI scans your Magento CMS pages and blocks for injected malicious code, risky HTML patterns, and content security risks. It uses deterministic regex checks as the first line of defence — detecting inline scripts, event handlers, external iframes, suspicious assets, and exposed secrets — and then optionally calls AI Core to generate plain-language risk summaries when rule hits are found.
Every finding is surfaced in a clean admin grid under Towering Media → Security & Compliance → Content Security Scan, with entity type, severity, detected patterns, and an optional AI-generated explanation of the risk. Scheduled filesystem integrity and heuristic malware scans, plus admin-event findings (admin user, integration, and OAuth token creates), are reported in the same grid.
- Deterministic checks: inline scripts, event handlers (onclick, onload, etc.)
- Iframe detection with external domain flagging
- External asset loading checks (CDN-hosted scripts, tracking pixels)
- Exposed secrets detection (API keys, tokens in CMS content)
- AI risk summaries via AI Core (only triggered when rule hits exist)
- Scheduled full scans via Magento cron
Real-Time Save-Triggered Scanning
Beyond scheduled cron runs, Security AI scans individual entities automatically when they are saved in admin. Every CMS page or block edit that introduces a new risk is flagged immediately — no waiting for the next nightly scan.
Because the AI summary layer only activates when deterministic rule hits are found, AI Core API credits are used efficiently. Clean content costs nothing; risky content gets a prioritised, actionable explanation that non-technical team members can act on without reading raw HTML.
- Save-triggered single-entity scan on every CMS save event
- Findings grid with entity name, type, severity, and pattern detail
- AI risk summary only when deterministic check finds a hit (efficient API use)
- Covers CMS pages, CMS blocks, filesystem paths, and admin-event findings
- Scans run by Magento cron, CMS-save observers, and admin — detect-and-report only (no quarantine)
Requirements
- Magento 2.4.4+ · PHP 8.1+
toweringmedia/module-ai-coretoweringmedia/module-base- Composer:
toweringmedia/module-security-ai
Works Great With
Frequently Asked Questions
Does Security AI require Toweringmedia AI Core to function?
toweringmedia/module-ai-core). Deterministic HTML and filesystem checks still run if you set AI Analysis Enabled to No under Content Security AI → AI Budget. Optional risk summaries need a configured AI Core provider.What kinds of threats does Security AI detect?
Is Security AI compatible with Hyvä themes?
Does it work with Magento 2.4.x?
Does Security AI quarantine or remove risky content?
Key Features
Deterministic CMS and filesystem checks with optional AI Core summaries, schedules, and admin alerts.
- Deterministic HTML rules Flags scripts, event handlers, iframes, assets, and secret patterns.
- AI risk summaries Plain-language explanations via AI Core only after rule hits.
- Scheduled full scans Cron-driven CMS scans on a frequency and hour you set.
- Scan on CMS save Single-entity checks when pages or blocks are saved.
- Filesystem malware scan Integrity baselines plus heuristic checks on configured paths.
- Findings admin grid Review open risks under Content Security Scan.
- Finding email alerts Immediate alerts and scheduled scan summary emails.
- AI spend budgets Per-scan, daily, and monthly caps, or deterministic-only mode.
Frequently Asked Questions
Where do I configure Content Security AI?
Go to Stores → Configuration → Towering Media → Content Security AI. Review findings under Towering Media → Security & Compliance → Content Security Scan. Configure your AI provider under Towering Media → AI Core.
Does Security AI remove or quarantine risky content?
No. It detects and reports findings for your team to review. It does not delete, quarantine, or rewrite CMS content or files on its own.
Can I run scans without spending AI credits?
Yes. Under Content Security AI → AI Budget, set AI Analysis Enabled to No. Scans still run the deterministic rule and filesystem checks with zero API spend.
Do you offer support?
Yes. Email support@toweringmedia.com or call (773) 466-2454. Updates and support continue while your subscription is active.
Can I try a demo?
Yes. Use the View Demo button on this page. For a guided walkthrough, email support@toweringmedia.com.
What happens when I don’t renew?
Uncheck auto-renew at purchase, or cancel later. You keep access until the end of the paid period. After that, updates and support stop.
Compatible with your Magento 2 store
Built for Magento 2.4.4+ with PHP 8.1–8.4. Requires toweringmedia/module-ai-core and toweringmedia/module-base. Install via Composer as toweringmedia/module-security-ai. Detection runs server-side in admin and cron; it is not theme-dependent.
-
Magento 2.4
Open Source & Adobe Commerce
Hyvä compatibleBuilt for modern storefronts
Updates & supportKeep your store running smoothly