Magento Commerce Security Vulnerabilities
artisansystem.com
artisansystem.com
I think someone could do very well offering Magento as a hosted service once it matures. Server administration is the cause of a lot of strife, and few online retailers are interested in that.
I've not played around with Magento but my understanding is that it's based on the Zend Framework. Zend_Form has a dedicated element for preventing CSRF attacks: Zend_Form_Element_Hash. That said this looks more like a poor design choice rather than a limitation of the tools/framework used.
(Checking the referrer certainly helps, but will cause problems for anyone who has referrers disabled in browser privacy settings or is behind a proxy that strips referrer headers)
Interface-wise, Magento is years ahead of the rest. Just visit a demo site.
It does run on the Zend Framework, so studying that (and OO PHP in general) is a requisite for writing modules. The ZF brings sophisticated inheritance logic, both in terms of object overloading and template inheritance. Thus, extending Magento is a breeze compared to other software.
Magento's downsides stem from being young and free. The documentation is hit-or-miss, and the forum is full of FUD from inexperienced users who are attracted to the price tag.
The Magento team has a habit of scrambling a maintenance patch right after a release, which probably means bad QA. If a new release comes out, it's best to wait a couple weeks and watch for x.0.1.
Having a dedicated server with a solid control panel and shell access will be a lifesaver. Crontab control is a must. I'm amazed how many people try to jam this thing on GoDaddy.