Support status · Magento 1
Is Magento 1 still supported?
Magento 1 support ended on 30 June 2020.
Adobe ended support for all Magento 1 versions on that date, covering both Magento Commerce 1 and Magento Open Source 1. No official security patch has been issued since. The store still takes orders, which is exactly why the replacement keeps being deferred. The difference from every other unsupported platform is that this one processes card payments, so on top of the security exposure there is an annual compliance attestation that somebody has to sign.
- Support ended
- 30 June 2020
- Adobe security patches since
- None
- Third-party extensions
- Largely abandoned
- PCI DSS
- v4.0.1 is the only active version
Source: PCI Security Standards Council: document library. Check it. We would rather you did.
- Dates and standards linked
- No email needed to read them
- A hosted platform is often the right answer
What that actually means
The position most estates are in
Your acquirer's questionnaire is the real deadline
PCI DSS does not name platforms, so nothing about Magento 1 is automatically non-compliant. What it does is move the entire burden onto you: every requirement about patching and known vulnerabilities now has to be answered with compensating controls and evidence, every year, for software that will never be patched again.
A checkout on an abandoned platform is a standing target
Card-skimming groups look for payment pages on ecommerce software that stopped receiving patches, because a single injected script on a checkout page harvests real card numbers. This is a documented and long-running pattern against Magento 1 specifically, not a hypothetical.
The extensions are the store, and half of them are abandoned
A Magento 1 store is core plus twenty or forty third-party extensions, several unmaintained since before end of life, and usually a core that has been patched locally in ways nobody recorded. That collection, not the core version, is what makes the replatform hard to price.
Exposure
What breaks, how likely, what it costs
Stated generically here because it is generic until someone looks at your estate. These are the scenarios that actually land, in the columns your risk register already has.
| Scenario | Likelihood | Impact |
|---|---|---|
| A vulnerability is found in Magento 1 core or an extension you run | Certain over time | No vendor patch will exist. Mitigation is yours to build, buy or accept |
| A skimmer is injected into the checkout | A documented, ongoing pattern against this platform | Card data compromised, forensic investigation, acquirer fines, disclosure |
| Your annual PCI attestation comes round | Every year, without exception | Compensating controls and evidence for every patching requirement, indefinitely |
| The PHP version the store needs reaches end of life | Already the case for most Magento 1 stores | Two unsupported layers, and hosting options narrowing each year |
| A payment provider drops support for the integration you use | Happens without warning | Checkout stops taking money, with a rebuild required under maximum pressure |
What we do about it
The work itself
An honest read on whether you should be rebuilt at all
A store with standard catalogue and checkout behaviour should go to a hosted platform, and we will say so rather than quote for a rebuild. Bespoke work is justified by bespoke behaviour: unusual pricing, B2B account rules, or an ERP that has to stay in step.
What the customisation actually does
The custom modules, the extension overrides and the local core patches read at volume and written down as business rules. In a store this age the pricing and fulfilment logic is spread across all three and exists nowhere as a specification.
Behaviour pinned before anything moves
Characterisation tests against the running store through real journeys, adding to basket, applying the discount that only works for trade accounts and completing checkout, because the discount rules are where replatforms quietly lose money.
Cut over with the URLs and the history intact
Products, customers, order history and the URL structure are a data migration with a known shape, and the redirect map is part of the deliverable rather than an afterthought. Losing the organic rankings costs more than the project.
What decides the cost
The three things worth knowing before anyone quotes
- Checkout customisation
- A stock checkout replatforms cheaply. A customised one is the most expensive thing in the store to reproduce faithfully, and the most expensive to get wrong.
- Extension count
- How many third-party extensions are installed, and how many are still maintained, decides whether this is a migration or an archaeology project.
- Patched core
- Local edits to core files are undocumented behaviour that every migration path silently drops. Finding them early is what stops the surprises.
The engagement
How the work runs
You tell us what you have
Roughly how many products and extensions, whether the checkout is customised, and what would hurt most if it went wrong.
We read the code
Custom modules, extension overrides, local core patches, and how much of the behaviour is genuinely unusual rather than just old.
You get the recommendation, plainly
Hosted platform, Magento 2, or a bespoke build, with the reason, including when the answer is that you do not need us.
The move runs in stages
Catalogue and customers first, then the journeys, with the old store live until the new checkout has taken real orders.
Questions
Frequently asked
Is Magento 1 still supported?
No. Adobe ended support for all Magento 1 versions on 30 June 2020, covering both Magento Commerce 1 and Magento Open Source 1, and no official patch has been issued since. Third-party vendors and agencies sell patch services for it, which is a real holding position, but the platform itself is closed.
Does Magento 1 make us automatically non-compliant with PCI DSS?
No, and anyone telling you otherwise is oversimplifying. PCI DSS sets requirements, not an approved platform list. The practical position is worse than a simple ban would be: the requirements about patching and known vulnerabilities still apply, so you have to satisfy them with compensating controls and documented evidence, every year, on software that will never be patched. Some merchants do this successfully. It is a permanent cost, and it gets harder rather than easier: v4.0.1 is now the only active version of the standard and its future-dated requirements are already mandatory.
Should we go to Magento 2, Shopify, or something bespoke?
For most stores, a hosted platform is the correct answer and we will say so. Shopify or similar removes the patching problem permanently, and if your catalogue and checkout are conventional then paying for a bespoke build is paying for a liability. Magento 2 makes sense with genuine B2B complexity and a team who knows the platform. Bespoke is justified when the business logic is genuinely unusual: trade pricing tiers, contract-specific catalogues, an ERP that must stay in step. That is the part a hosted platform makes you fight.
What happens to our Google rankings and our URLs?
They are protected deliberately or they are damaged accidentally; there is no third outcome. The URL structure and a complete redirect map are part of the work rather than a task at the end. Losing established rankings on category and product pages costs more than most of these projects, and it is the failure mode that replatforms are most often remembered for.
Can this be done without closing the store?
Yes, and it should be. Catalogue and customers migrate first while the old store keeps trading, and the new checkout takes real orders before the old one is switched off. A hard cutover on a single evening is how stores lose a week of revenue and their order history at the same time.
We are still on Magento 1 and nothing has gone wrong. Is the risk overstated?
The absence of an incident is not evidence of safety when the exposure is card data: skimmers are designed to be quiet, and merchants routinely learn about them from their acquirer rather than from their own monitoring. That said, a store on a well-maintained patch service, behind a decent WAF, with a hosted payment page that keeps card data out of your pages entirely, is in a genuinely better position than one without those, and it is worth establishing which you are before spending anything.
Have you migrated Magento specifically?
Our deepest delivery experience is ColdFusion, not Magento. If the honest answer for your store is a hosted platform, a specialist replatform agency will do it better and cheaper than we would, and we will tell you that. Where we are useful is a store whose real complexity is business logic rather than ecommerce plumbing, which is the case that hosted platforms handle badly.
Talk to someone who would read the code
A name, an email, and three optional questions. What comes back is a reply from the engineer who would read the code, and it is either a conversation about replacing it or an honest pointer to a better-suited supplier.
Other platforms