Check my Magento security status

Ways how you can ensure you have all latest security patches applied:

  • Upgrade to the latest version CE 1.9.2.1 or EE 1.14.2.1 - these versions have all latest patches included
  • Apply patches in development systems via SSH to have the added to /etc/applied.patches.list

Additionally:

  • Run MageScan (tool by Steve Robbins) to check your sites status (this will not give you information about the patches though)
  • Run the Shoplift tester (as already mentioned above by Willem)
  • Hire a Magento developer to check your site (which will be a hard task if updates where done via FTP).
  • It's probably easier trying to apply the patches again via SSH and see if they work or fail and then check the files.

If you want to be sure the patches are installed properly (and more security checks, check https://www.MageReport.com (shoplift.byte.nl also redirects now)


Test if your site is still vulnerable at https://shoplift.byte.nl