Unsupported

Support status · Magento 1

Is Magento 1 still supported?

Magento 1 support ended on 30 June 2020.

If you already know it has to move

Talk to the engineer, not a form

Two fields and one question. The reply comes from the person who would read the code.

How customised is the checkout?

One reply, written by a person who has read your answers. Nothing else is ever sent.

Adobe ended support for all Magento 1 versions on that date, covering both Magento Commerce 1 and Magento Open Source 1. No official security patch has been issued since. The store still takes orders, which is exactly why the replacement keeps being deferred. The difference from every other unsupported platform is that this one processes card payments, so on top of the security exposure there is an annual compliance attestation that somebody has to sign.

Support ended
30 June 2020
Adobe security patches since
None
Third-party extensions
Largely abandoned
PCI DSS
v4.0.1 is the only active version

Source: PCI Security Standards Council: document library. Check it. We would rather you did.

  • Dates and standards linked
  • No email needed to read them
  • A hosted platform is often the right answer

What that actually means

The position most estates are in

  1. Your acquirer's questionnaire is the real deadline

    PCI DSS does not name platforms, so nothing about Magento 1 is automatically non-compliant. What it does is move the entire burden onto you: every requirement about patching and known vulnerabilities now has to be answered with compensating controls and evidence, every year, for software that will never be patched again.

  2. A checkout on an abandoned platform is a standing target

    Card-skimming groups look for payment pages on ecommerce software that stopped receiving patches, because a single injected script on a checkout page harvests real card numbers. This is a documented and long-running pattern against Magento 1 specifically, not a hypothetical.

  3. The extensions are the store, and half of them are abandoned

    A Magento 1 store is core plus twenty or forty third-party extensions, several unmaintained since before end of life, and usually a core that has been patched locally in ways nobody recorded. That collection, not the core version, is what makes the replatform hard to price.

Exposure

What breaks, how likely, what it costs

Stated generically here because it is generic until someone looks at your estate. These are the scenarios that actually land, in the columns your risk register already has.

ScenarioLikelihoodImpact
A vulnerability is found in Magento 1 core or an extension you runCertain over timeNo vendor patch will exist. Mitigation is yours to build, buy or accept
A skimmer is injected into the checkoutA documented, ongoing pattern against this platformCard data compromised, forensic investigation, acquirer fines, disclosure
Your annual PCI attestation comes roundEvery year, without exceptionCompensating controls and evidence for every patching requirement, indefinitely
The PHP version the store needs reaches end of lifeAlready the case for most Magento 1 storesTwo unsupported layers, and hosting options narrowing each year
A payment provider drops support for the integration you useHappens without warningCheckout stops taking money, with a rebuild required under maximum pressure

What we do about it

The work itself

An honest read on whether you should be rebuilt at all

A store with standard catalogue and checkout behaviour should go to a hosted platform, and we will say so rather than quote for a rebuild. Bespoke work is justified by bespoke behaviour: unusual pricing, B2B account rules, or an ERP that has to stay in step.

What the customisation actually does

The custom modules, the extension overrides and the local core patches read at volume and written down as business rules. In a store this age the pricing and fulfilment logic is spread across all three and exists nowhere as a specification.

Behaviour pinned before anything moves

Characterisation tests against the running store through real journeys, adding to basket, applying the discount that only works for trade accounts and completing checkout, because the discount rules are where replatforms quietly lose money.

Cut over with the URLs and the history intact

Products, customers, order history and the URL structure are a data migration with a known shape, and the redirect map is part of the deliverable rather than an afterthought. Losing the organic rankings costs more than the project.

What decides the cost

The three things worth knowing before anyone quotes

Checkout customisation
A stock checkout replatforms cheaply. A customised one is the most expensive thing in the store to reproduce faithfully, and the most expensive to get wrong.
Extension count
How many third-party extensions are installed, and how many are still maintained, decides whether this is a migration or an archaeology project.
Patched core
Local edits to core files are undocumented behaviour that every migration path silently drops. Finding them early is what stops the surprises.

The engagement

How the work runs

  1. You tell us what you have

    Roughly how many products and extensions, whether the checkout is customised, and what would hurt most if it went wrong.

  2. We read the code

    Custom modules, extension overrides, local core patches, and how much of the behaviour is genuinely unusual rather than just old.

  3. You get the recommendation, plainly

    Hosted platform, Magento 2, or a bespoke build, with the reason, including when the answer is that you do not need us.

  4. The move runs in stages

    Catalogue and customers first, then the journeys, with the old store live until the new checkout has taken real orders.

Questions

Frequently asked

Is Magento 1 still supported?

No. Adobe ended support for all Magento 1 versions on 30 June 2020, covering both Magento Commerce 1 and Magento Open Source 1, and no official patch has been issued since. Third-party vendors and agencies sell patch services for it, which is a real holding position, but the platform itself is closed.

Does Magento 1 make us automatically non-compliant with PCI DSS?

No, and anyone telling you otherwise is oversimplifying. PCI DSS sets requirements, not an approved platform list. The practical position is worse than a simple ban would be: the requirements about patching and known vulnerabilities still apply, so you have to satisfy them with compensating controls and documented evidence, every year, on software that will never be patched. Some merchants do this successfully. It is a permanent cost, and it gets harder rather than easier: v4.0.1 is now the only active version of the standard and its future-dated requirements are already mandatory.

Should we go to Magento 2, Shopify, or something bespoke?

For most stores, a hosted platform is the correct answer and we will say so. Shopify or similar removes the patching problem permanently, and if your catalogue and checkout are conventional then paying for a bespoke build is paying for a liability. Magento 2 makes sense with genuine B2B complexity and a team who knows the platform. Bespoke is justified when the business logic is genuinely unusual: trade pricing tiers, contract-specific catalogues, an ERP that must stay in step. That is the part a hosted platform makes you fight.

What happens to our Google rankings and our URLs?

They are protected deliberately or they are damaged accidentally; there is no third outcome. The URL structure and a complete redirect map are part of the work rather than a task at the end. Losing established rankings on category and product pages costs more than most of these projects, and it is the failure mode that replatforms are most often remembered for.

Can this be done without closing the store?

Yes, and it should be. Catalogue and customers migrate first while the old store keeps trading, and the new checkout takes real orders before the old one is switched off. A hard cutover on a single evening is how stores lose a week of revenue and their order history at the same time.

We are still on Magento 1 and nothing has gone wrong. Is the risk overstated?

The absence of an incident is not evidence of safety when the exposure is card data: skimmers are designed to be quiet, and merchants routinely learn about them from their acquirer rather than from their own monitoring. That said, a store on a well-maintained patch service, behind a decent WAF, with a hosted payment page that keeps card data out of your pages entirely, is in a genuinely better position than one without those, and it is worth establishing which you are before spending anything.

Have you migrated Magento specifically?

Our deepest delivery experience is ColdFusion, not Magento. If the honest answer for your store is a hosted platform, a specialist replatform agency will do it better and cheaper than we would, and we will tell you that. Where we are useful is a store whose real complexity is business logic rather than ecommerce plumbing, which is the case that hosted platforms handle badly.

Talk to someone who would read the code

A name, an email, and three optional questions. What comes back is a reply from the engineer who would read the code, and it is either a conversation about replacing it or an honest pointer to a better-suited supplier.

One reply, written by a person who has read your answers. Nothing else is ever sent.

Other platforms

Something else in the estate on borrowed time?