No results found.

Magento 2 & Adobe Commerce

Production-tested guides, tools, and insights from 8+ years of building, securing, and scaling Magento 2 stores in production.

Magento 2 (now Adobe Commerce) remains one of the most powerful and flexible ecommerce platforms available - but it demands deep operational knowledge to run well. From navigating Adobe's patching strategy to configuring Varnish correctly, from defending against real-world attacks to building reliable deployment pipelines, there's a lot that separates a Magento store that works from one that works well.

This resource hub brings together everything I've written about Magento across blog posts, technical documentation, and open-source projects. Whether you're a Magento developer looking for debugging tips, a DevOps engineer building CI/CD pipelines, or a technical lead evaluating your store's security posture โ€” you'll find practical, production-tested content here.

Every guide is based on 8+ years of hands-on experience operating Magento stores in production for UK agencies and merchants. I've responded to active security incidents, analysed real malware samples, reported vulnerabilities to Adobe, and built CI/CD tooling used across multiple teams โ€” not theoretical knowledge.

Latest Magento Articles

Recent blog posts covering Magento development, security, DevOps, and more.

All Magento posts

Magento 2 E2E Testing: A Playwright Suite You Configure, Not Fork

An open source Playwright end to end testing suite for Magento 2.4.7 to 2.4.9 and Mage-OS, with Luma and Hyvรค supported out of the box, adapted to a store through five JSON config files instead of a per-client fork.

· 5 min
  • magento2
  • testing
  • devops
  • +2

m2-meta-security-patches Swaps vaimo for a New Patch Installer

m2-meta-security-patches now applies patches through samjuk/magento-patch-installer instead of vaimo/composer-patches. Two config lines, one composer update, and it coexists with vaimo or cweagans.

· 5 min
  • magento2
  • security
  • adobe-commerce
  • +2

StyleSmuggler and September's Isolated Patch Land in m2-meta-security-patches

Adobe shipped two Magento 2 security patches a day apart โ€” the StyleSmuggler emergency fix (VULN-39341 / APSB26-146) and September's routine isolated patch (2026-09-001 / APSB26-138). Both are now wired into m2-meta-security-patches.

· 6 min
  • magento2
  • security
  • adobe-commerce
  • +2

StyleSmuggler (CVE-2026-75650): Emergency Magento 2 Mitigation & Recovery

How to detect, contain and recover from StyleSmuggler (CVE-2026-75650 / VULN-39341, APSB26-146) โ€” the actively exploited Magento and Adobe Commerce zero-day RCE.

· 17 min
  • magento2
  • security
  • adobe-commerce
  • +3

APSB26-92: Adobe Commerce's August 2026 Isolated Patch

APSB26-92 is Adobe Commerce's August 2026 isolated security patch, stacking on top of July's. Here's what's in it, WAF rules for the account takeover, the July packaging problems now fixed properly, and a vaimo/composer-patches bug that silently reverts your patches.

· 8 min
  • magento2
  • security
  • adobe-commerce
  • +2

APSB26-73: How to Apply Adobe Commerce's July 2026 Isolated Security Patch

APSB26-73 is Adobe Commerce's July 2026 isolated security patch, covering 2.4.6-p15, 2.4.7-p10, 2.4.8-p5 and 2.4.9. Here's what's in it, the non-cumulative gotcha that trips people up, and the fastest way to apply it.

· 4 min
  • magento2
  • security
  • adobe-commerce
  • +2

Documentation & Guides

In-depth technical docs and step-by-step guides for Magento developers and operators.

All Magento docs

Open-Source Projects & Tools

Magento-related tools, modules, and infrastructure projects.

All projects
๐Ÿ‘พ

Magento 2 Patching at Scale

Demo monorepo showcasing approaches for distributing patches across lots of Magento 2 Projects at scale, with practical examples and best practices.

< 5 minutes
Rollout Time / site
95%
Cost Savings
๐Ÿš€

Ephemeral Feature Environments

Automated deployment of temporary Magento 2 environments for pull requests, using anonymised production data to reduce risk and speed up reviews

Removed
Blocked Releases
Reduced
Production Bugs
๐Ÿ”’

Ansible Ecomscan Role

Ansible role for either triggering ondemand Sansec Malware scans or configuring scheduled scanning across an entire fleet of distributed infrastructure

โœ…
Galaxy Role
โœ…
Molecule Tests
๐Ÿš€

Fully Automated Magento Updates

Zero-touch Magento core and module updates using Dependabot, automated E2E testing, and continuous deployment - enabling non-technical teams to manage security patches independently.

95%
Time Saved
Same Day
Patch Speed
๐Ÿ‘พ

FishPig WordPress Theme Builder

Composer package for the FishPig WordPress theme with automated build system, enabling modern dependency management in professional WordPress workflows via Packagist.

Packagist
Registry
Automated
Updates

Magento 2 development and platform engineering

Iโ€™ve been working with Magento for 8+ years, based in Cardiff, Wales. Focusing on performance, security, and scalability across UK agencies and merchants. Happy to connect with other developers and engineers.