Security AI for Magento 2

Catch risky CMS content early

  • CMS Scanning Pages and blocks
  • AI Summaries Only when rules hit
  • File Integrity Hash and heuristics
  • Email Alerts Findings and summaries

Catch risky CMS content early

Injected scripts and risky HTML in CMS pages are easy to miss. Security AI scans Magento CMS pages and blocks with deterministic regex checks, then optionally adds AI Core risk summaries when rules hit.

  • Flags scripts, event handlers, iframes, and secrets
  • Optional AI risk summaries only after rule hits
  • Scheduled full scans and scan-on-CMS-save checks
  • Findings grid plus email alerts for open risks

Built for your store

Built for Magento 2.4.4+ with PHP 8.1–8.4. Requires AI Core and Toweringmedia Base; detection is server-side and not theme-dependent.

  • Requires AI Core and Toweringmedia Base
  • Configure under Content Security AI settings
  • Findings under Content Security Scan admin grid
  • Deterministic-only mode available to avoid AI spend

AI-Assisted CMS Security Scanning for Magento

Security AI scans your Magento CMS pages and blocks for injected malicious code, risky HTML patterns, and content security risks. It uses deterministic regex checks as the first line of defence — detecting inline scripts, event handlers, external iframes, suspicious assets, and exposed secrets — and then optionally calls AI Core to generate plain-language risk summaries when rule hits are found.

Every finding is surfaced in a clean admin grid under Towering Media → Security & Compliance → Content Security Scan, with entity type, severity, detected patterns, and an optional AI-generated explanation of the risk. Scheduled filesystem integrity and heuristic malware scans, plus admin-event findings (admin user, integration, and OAuth token creates), are reported in the same grid.

  • Deterministic checks: inline scripts, event handlers (onclick, onload, etc.)
  • Iframe detection with external domain flagging
  • External asset loading checks (CDN-hosted scripts, tracking pixels)
  • Exposed secrets detection (API keys, tokens in CMS content)
  • AI risk summaries via AI Core (only triggered when rule hits exist)
  • Scheduled full scans via Magento cron

Real-Time Save-Triggered Scanning

Beyond scheduled cron runs, Security AI scans individual entities automatically when they are saved in admin. Every CMS page or block edit that introduces a new risk is flagged immediately — no waiting for the next nightly scan.

Because the AI summary layer only activates when deterministic rule hits are found, AI Core API credits are used efficiently. Clean content costs nothing; risky content gets a prioritised, actionable explanation that non-technical team members can act on without reading raw HTML.

  • Save-triggered single-entity scan on every CMS save event
  • Findings grid with entity name, type, severity, and pattern detail
  • AI risk summary only when deterministic check finds a hit (efficient API use)
  • Covers CMS pages, CMS blocks, filesystem paths, and admin-event findings
  • Scans run by Magento cron, CMS-save observers, and admin — detect-and-report only (no quarantine)

Requirements

  • Magento 2.4.4+ · PHP 8.1+
  • toweringmedia/module-ai-core
  • toweringmedia/module-base
  • Composer: toweringmedia/module-security-ai

Works Great With

Frequently Asked Questions

Does Security AI require Toweringmedia AI Core to function?

Yes as a Composer dependency (toweringmedia/module-ai-core). Deterministic HTML and filesystem checks still run if you set AI Analysis Enabled to No under Content Security AI → AI Budget. Optional risk summaries need a configured AI Core provider.

What kinds of threats does Security AI detect?

It flags risky CMS HTML (inline scripts, event handlers, iframes, external assets, secret patterns), filesystem integrity changes and heuristic malware signatures on configured paths, and admin-event findings such as new admin users, integrations, and OAuth tokens. It is not a shopper-login or order-fraud scorer.

Is Security AI compatible with Hyvä themes?

Yes. The detection logic runs server-side and is completely theme-agnostic — it works with Hyvä, Luma, and React Checkout Pro storefronts.

Does it work with Magento 2.4.x?

Yes. Security AI targets Magento 2.4.4+ and supports PHP 8.1, 8.2, 8.3, and 8.4.

Does Security AI quarantine or remove risky content?

No. It detects and reports findings for your team to review. It does not delete, quarantine, or rewrite CMS content or files on its own. Scan scope is CMS pages and blocks, configured filesystem paths, and admin events only.

Key Features

Deterministic CMS and filesystem checks with optional AI Core summaries, schedules, and admin alerts.

  • Deterministic HTML rules Flags scripts, event handlers, iframes, assets, and secret patterns.
  • AI risk summaries Plain-language explanations via AI Core only after rule hits.
  • Scheduled full scans Cron-driven CMS scans on a frequency and hour you set.
  • Scan on CMS save Single-entity checks when pages or blocks are saved.
  • Filesystem malware scan Integrity baselines plus heuristic checks on configured paths.
  • Findings admin grid Review open risks under Content Security Scan.
  • Finding email alerts Immediate alerts and scheduled scan summary emails.
  • AI spend budgets Per-scan, daily, and monthly caps, or deterministic-only mode.

Frequently Asked Questions

Where do I configure Content Security AI?

Go to Stores → Configuration → Towering Media → Content Security AI. Review findings under Towering Media → Security & Compliance → Content Security Scan. Configure your AI provider under Towering Media → AI Core.

Does Security AI remove or quarantine risky content?

No. It detects and reports findings for your team to review. It does not delete, quarantine, or rewrite CMS content or files on its own.

Can I run scans without spending AI credits?

Yes. Under Content Security AI → AI Budget, set AI Analysis Enabled to No. Scans still run the deterministic rule and filesystem checks with zero API spend.

Do you offer support?

Yes. Email support@toweringmedia.com or call (773) 466-2454. Updates and support continue while your subscription is active.

Can I try a demo?

Yes. Use the View Demo button on this page. For a guided walkthrough, email support@toweringmedia.com.

What happens when I don’t renew?

Uncheck auto-renew at purchase, or cancel later. You keep access until the end of the paid period. After that, updates and support stop.

Compatible with your Magento 2 store

Built for Magento 2.4.4+ with PHP 8.1–8.4. Requires toweringmedia/module-ai-core and toweringmedia/module-base. Install via Composer as toweringmedia/module-security-ai. Detection runs server-side in admin and cron; it is not theme-dependent.

  • Magento 2.4 Open Source & Adobe Commerce
  • HyväHyvä compatibleBuilt for modern storefronts
  • Updates & supportKeep your store running smoothly

My Cart

Loading...

Customer Login

Checkout as a new customer

Creating an account has many benefits:

  • See order and shipping status
  • Track order history
  • Check out faster