Magento Custom Options Hygiene (magento-custom-options-hygiene)
Summary
Magento-gated checks: custom_options path deny, PHP execution under that tree, and known PolyShell IoC filenames (no uploads).
Classification
- Category:
SECURITY - Plugin id:
magento-custom-options-hygiene - Version:
1.0.0 - Target types:
WEBSITE,WEBSHOP - Weight class:
LIGHT - Risk level:
HIGH - Browser required: No (HTTP / Node / other — see source)
- Tier / group: Tier 1 — HTTP-only
Schedule
- scheduleHints:
{ defaultInterval: '25 */6 * * *', priority: 3 } - Prerequisites: None declared on this plugin.
Configurable inputs
Public keys are derived from inputSchema: z.object({ ... }) (underscore-prefixed keys are runtime-only and omitted here).
| Field | Notes |
|---|---|
timeout |
Zod field in inputSchema — see source for defaults, min/max, and .describe(). |
requireMagento |
Zod field in inputSchema — see source for defaults, min/max, and .describe(). |
Runtime / injected config
- None documented beyond standard worker context (
target,config,logger,reportProgress). Underscore-prefixed keys are internal.
What it does
- Runs as part of the worker test execution pipeline; results become
Runrows and may createFindingrecords. - Magento-gated checks: custom_options path deny, PHP execution under that tree, and known PolyShell IoC filenames (no uploads).
- For finding titles, metrics, and artifacts specific to this plugin, refer to the implementation linked below.
Source
packages/test-plugins/src/plugins/magento-custom-options-hygiene.ts