No results found.

Magento 2 & Adobe Commerce

Production-tested guides, tools, and insights from 8+ years of building, securing, and scaling Magento 2 stores.

Magento 2 (now Adobe Commerce) remains one of the most powerful and flexible ecommerce platforms available - but it demands deep operational knowledge to run well. From navigating Adobe's patching strategy to configuring Varnish correctly, from defending against real-world attacks to building reliable deployment pipelines, there's a lot that separates a Magento store that works from one that works well.

This resource hub brings together everything I've written about Magento across blog posts, technical documentation, and open-source projects. Whether you're a developer looking for debugging tips, a DevOps engineer building CI/CD pipelines, or a technical lead evaluating Magento's security posture - you'll find practical, production-tested content here.

Every guide is based on hands-on experience operating Magento stores in production, not theoretical knowledge. I've responded to active security incidents, analysed real malware samples, and built tooling that's used across multiple agencies and merchants.

Latest Magento Articles

Recent blog posts covering Magento development, security, DevOps, and more.

All Magento posts

Adobe's Isolated Patch Strategy: A Community Response

Adobe's new monthly isolated patch approach for Magento creates maintenance burden. Here's how a community meta-package can help restore sanity to security patching.

· 3 min
  • magento2
  • security
  • devops
  • +2

Strengthening Magento 2 Security in CI/CD Pipelines with Sansec Ecomscan

Learn how to integrate Sansec Ecomscan into Magento 2 CI/CD pipelines to detect malware, enforce security patches, and secure build artifacts. Step-by-step guides for GitHub Actions and Bitbucket Pipelines included.

· 3 min
  • magento2
  • security
  • devsecops
  • +2

Cloudflare Outage November 2025 - Retrospective

Cloudflare accidentally took half the internet down for half a day, right before Black Friday. What can we learn from this, and how can we engineer more resilient infrastructure to survive similar outages in the future?

· 3 min
  • magento2
  • devops
  • site-reliability-engineering

Check if your Magento site is safe from Session Reaper (CVE-2025-54236)

How to guide on checking if your Magento 2 store is safe from the Session Reaper (CVE-2025-54236) exploit. And guidance on how to patch and secure your site if it is not.

· 5 min
  • magento2
  • security
  • devsecops
  • +2

How to efficiently patch Magento 2 deployments at scale

Approaches to simply deploying patches across a large inventory of Magento 2 deployments

· 3 min
  • magento2
  • security
  • devops
  • +1

Verbose Magento 2 DB Schema Status

Ever found yourself wondering why a store required downtime to deploy? Or even the case where `setup:db:status` constantly reports `Declarative Schema is not up to date` despite you just update it?

· 2 min
  • magento2
  • devops
  • debugging
  • +1

Documentation & Guides

In-depth technical docs and step-by-step guides for Magento developers and operators.

All Magento docs

Open-Source Projects & Tools

Magento-related tools, modules, and infrastructure projects.

All projects
👾

Magento 2 Patching at Scale

Demo monorepo showcasing approaches for distributing patches across lots of Magento 2 Projects at scale, with practical examples and best practices.

< 5 minutes
Rollout Time / site
95%
Cost Savings
🚀

Ephemeral Feature Environments

Automated deployment of temporary Magento 2 environments for pull requests, using anonymised production data to reduce risk and speed up reviews

Removed
Blocked Releases
Reduced
Production Bugs
🔒

Ansible Ecomscan Role

Ansible role for either triggering ondemand Sansec Malware scans or configuring scheduled scanning across an entire fleet of distributed infrastructure

Galaxy Role
Molecule Tests
🚀

Fully Automated Magento Updates

Zero-touch Magento core and module updates using Dependabot, automated E2E testing, and continuous deployment - enabling non-technical teams to manage security patches independently.

95%
Time Saved
Same Day
Patch Speed
👾

FishPig WordPress Theme Builder

Composer package for the FishPig WordPress theme with automated build system, enabling modern dependency management in professional WordPress workflows via Packagist.

Packagist
Registry
Automated
Updates

Magento 2 development and platform engineering

I’ve been working with Magento for 8+ years, focusing on performance, security, and scalability. Based in the UK, I enjoy solving technical challenges and connecting with other developers and engineers.