Gift card exploit

I don’t use Magento, but I’ve got a question for people who do.

I recently got a gift card for an online shop for my birthday, and was surprised to see the code to use was a simple numeric (it had letters in it, but they looked like they’d be the same every time). I wondered what would happen if I used the next number up, and was surprised to see the voucher applied and £5 come off my bill! I took it off again, because that’s somebody else’s money, but it made me curious if this company’s gift card codes were that easy to crack, so I wrote a quick script to see.

I was shocked to find a whole load of codes, just worked out by increasing the number at the end. I looked at some of the markup of the company’s website and it looks like they’re using Magento

I let the company know yesterday, and they’re “looking into it”.

It made me wonder if there’s a gift card extension to Magento that people know of that uses such a simple incrementing number for gift card codes. Does anybody know (maybe you’re using it?). If there is, they’re just asking for trouble!

submitted by /u/andrewmccafferty
[link] [comments]

Evaluating Magento Partners

Hello, I am the owner of two e-commerce companies which have sales of over $6M per season, which for us is about 9 months long each year. Both companies are on Magento 2 and we stay up regularly with upgrades and security patches.

Although we’ve had some hiccups with our current U.S. based developer, overall they have been fairly decent. I’m not blown away but I’m not quite disappointed enough to necessarily leave them. We engage with them multiple times per week for support issues and new developments. Our current monthly retainer is for 35 hours per month and the cost is just shy of $5K per month.

Our sites are highly customized. What troubles me is that our organic rankings have been trending downward. We have engaged a reputable U.S. based digital marketing company who is working through the SEO on our sites. In conversations with the developer and digital marketing companies, they have suggested it may be due to CLS/page speed scores. Although they have identified some areas of potential improvement, our developer is suggesting we consider migrating to a different theme. Our sites currently use the Pearl theme and they have suggested we look at the Hyva theme, saying this could improve our standings with SERP by doing so.

As you all know, it is difficult to consider moving away from a developer, especially when they know your site and customizations so intimately. However, we have spent several hundred thousand dollars over the last 5-6 years to build and maintain our M2 sites. I believe I owe it to our company to at least find another partner that can give us a review of our current developer and be a neutral party we can consult with to evaluate any potential moves to a new theme and our ongoing costs (which are substantial IMO) for site maintenance and development. I’d like a check on our current developer in terms of their suggestions and what this should all cost to develop, as I know the price tag is going to be a large one.

Any suggestions or insights into anything I’ve written above? Thank you in advance!

submitted by /u/ImObviouslySuperior
[link] [comments]

Future of Magento

Hi everyone, first time poster.

I was fortunate enough to have learnt Magento (and the full stack languages) as we moved over from a Dreamweaver website 10 years ago, taught by a PHP dev who no longer works for the company.

I myself am now freelance, if you want the check the site out it’s The Spicery.

It’s heavily customised with custom warehouse integration for picking/packing and internal server written in .NET that handles postage labels for royal mail.

There’s always a been budget/admin friendly issues. We use a lot of page builders now (Magezon, Amasty etc) which work, but there’s a always a line between good code and letting the content creators loose.

Really, is there an alternative that could be worth looking into? I am 1 year into learning Laravel and love the simplicity, could there be an avenue there?

Cheers

submitted by /u/Surr3alDisc0
[link] [comments]

Do i need to switch from magento

Hi im from India i have 2years of experience in Magento 2 development. i got fired on may 2024 my last ctc is 4lpa. from may 2024 Im searching for Magento developer job i have not got one i dont know wheather im overpaid on my last company. nd im losing hope on continue searching magento jobs nd im confused what to do next someone suggest/guide me what i need to do next?

submitted by /u/Ok-Baby7019
[link] [comments]

Skipping quote on legacy order import

I’m curious what people’s thoughts are on skipping the quote creating when importing legacy orders from an old system.

The orders are strictly for records only. No reordering off them or anything like that. For the frontend we’re using a headless approach with custom graphql endpoints.

My initial test are showing everything working but I’m wondering if I might be missing something. If I skip the quote process the import is speed up by almost 100% which is a lot when we need to bring in 70k orders.

submitted by /u/fab5freddy
[link] [comments]

Canonical urls in sitemap

Hi, does anyone know if it’s possible to have a product’s canonical url included in the site map? My xml site map only includes products with the full category url, so there are lots of duplicates where a product sits in multiple categories. But the canonical version of the product in the root folder does not show up at all.

I think this is the wrong way around, from an SEO perspective. A site map should include thr canonical but not all the duplicates across each category.

Can anyone advise? Cheers!

submitted by /u/SamuraiDan1
[link] [comments]

GA4/tagmanager tracking

Hi,

I’m consulting a client with 2 websites and 2 different tracking configurations, both coupled to the same magento environment.

One is configured manually, 8years ago, with a lot of custom variables, scripts, Ajax listeners,,

The other is configured using the free Magefan plugins.

My goal is to standardize tracking and make them twins to ease processes. I would prefer to avoid magefan and do it myself. When I’m trying to set up the configuration I notice add to carts and checkouts initiated don’t fire in Google tag manager because they are form submission. I assume that’s why the Ajax listeners is used in the other container, and the amount of custom variables. But when I replicate the configuration it doesn’t fire, one reason I assume is because there is an old form submission listener in the 8y old container that’s not available anymore.

I’ve spent 12 hours figuring out why and the only solution seems to be buy a paid extension/add-on, but I would really like to learn how to make it work manually. Anyone solved this problem before?

submitted by /u/SnoooCookies
[link] [comments]

Snowdog Megamenu – Admin Performance

We’re considering using this: https://github.com/SnowdogApps/magento2-menu

We currently have Ubertheme Megamenu on our site. It’s fine, I gues, but it has a few issues. One being performance on the admin panel. When we try and moe an entry, it takes multiple minutes to process the move and save it. Often having errors. The plugin developer can’t help.

Does anyone here use SnowDog as their megamenu? If so, how do you find performance?

submitted by /u/antde5
[link] [comments]

Does Adobe give any insight into the future?

Is there any ability to gain insight into what Adobe is up to?

Hi I am a WordPress engineer but I would really like to be able to use Magento instead of WooCommerce, and even though Shopify is getting all the buzz right I think 5 years from now Magento could make a comeback if Mage OS and Adobe actually move the needle.

As someone on the outside looking in… is there anyway that Magento can steal some of Shopify’s current shine?

submitted by /u/outsellers
[link] [comments]