# aligent/magento2-pci-4-compatibility

> Provide compatibility with PCI DSS 4.0 requirements

`composer require aligent/magento2-pci-4-compatibility`

Canonical URL: https://packagento.com/aligent/magento2-pci-4-compatibility

## At a glance

- **Vendor**: aligent (https://packagento.com/aligent.md)
- **Latest version**: 1.4.1 — released 2026-02-27
- **Pricing**: Free
- **Package type**: Magento 2 module
- **Status**: active, accepting new buyers

## Installation

Packagento is licence-gated, so even free packages need a licence on a project before Composer can resolve them.

1. **Sign in or create an account** at https://packagento.com/customer/account/.

2. **Add the package to your account.** Open https://packagento.com/aligent/magento2-pci-4-compatibility and complete the free checkout. A licence is minted automatically.

3. **Create or pick a project, then activate the licence on it.**
   - Projects represent the Magento installs you deploy to. Manage them at https://packagento.com/projects/.
   - Activate the new licence on the project you'll deploy this package to. Activation is what generates the Composer credentials scoped to that project.

4. **Add the project credentials to your Magento codebase.**

   Grab the project's public + private key from https://packagento.com/projects/ (open the project, then its Credentials tab), and add them to `auth.json`:

   ```json
   {
     "http-basic": {
       "packagento.com": {
         "username": "ppk_live_...",
         "password": "psk_live_..."
       }
     }
   }
   ```

   Add the Packagento Composer repository to `composer.json`:

   ```json
   {
     "repositories": [
       { "type": "composer", "url": "https://packagento.com" }
     ]
   }
   ```

5. **Install and apply.**

   ```bash
   composer require aligent/magento2-pci-4-compatibility:*
   bin/magento setup:upgrade
   bin/magento setup:di:compile
   bin/magento cache:flush
   ```

## What it does

Provide compatibility with PCI DSS 4.0 requirements

## README

A Magento 2 module to bring the use of admin accounts in-line with the [PCI DSS 4.0 requirements](https://east.pcisecuritystandards.org/document_library?category=pcidss&document=pci_dss), with changes covering the following requirements:
* 8.2.6
   * Inactive user accounts are removed or disabled within 90 days of inactivity
* 8.2.8
   * If a user session has been idle for more than 15 minutes, the user is required to re-authenticate to re-activate the terminal or session.
* 8.3.4
   * Invalid authentication attempts are limited by:
      * Locking out the user ID after not more than 10 attempts.
      * Setting the lockout duration to a minimum of 30 minutes or until the user’s identity is confirmed.
* 8.3.6
   * If passwords/passphrases are used as authentication factors to meet Requirement 8.3.1, they meet the following minimum level of complexity:
      * A minimum length of 12 characters (or IF the system does not support 12 characters, a minimum length of eight characters).
      * Contain both numeric and alphabetic characters

The changes invovled for each requirement are as follows:
* 8.2.6
   * A new cron job (scheduled once per day) will automatically make any account that has not logged in for 90 days inactive
* 8.2.8
   * The configuration setting in admin for idle timeout has been modified to only accept values less than or equal to 900 seconds (15 minutes).
* 8.3.4
   * The configuration setting in admin for the number of incorrect login attempts before an account is locked has been modified to only accept values less than or equal to 10.
   * The configuration setting in admin for the time an account is locked for has been modified to only accept values greater than or equal to 30.
* 8.3.6
   * The minimum number of characters a password must have has been increased from 7 to 12.

### Installation
```shell
composer require aligent/magento2-pci-4-compatibility
bin/magento module:enable Aligent_Pci4Compatibility
bin/magento setup:upgrade

```

## Recent Versions

| Version | Released |
|---|---|
| 1.4.1 | 2026-02-27 |
| 1.4.0 | 2026-02-18 |
| 1.3.1 | 2025-10-24 |
| 1.3.0 | 2025-10-21 |
| 1.2.0 | 2025-04-15 |
| 1.1.3 | 2025-03-18 |
| 1.1.2 | 2025-03-18 |
| 1.1.1 | 2025-03-12 |
| 1.1.0 | 2025-01-07 |
| 1.0.0 | 2025-01-06 |

## Dependencies

### Require

| Package | Constraint |
|---|---|
| php | ^8.1.0\|^8.2.0\|^8.3.0\|^8.4.0 |

## Quality

Latest release (1.4.1) fails the Packagento QA pipeline. Verdicts below are per-cell (Magento line × PHP version) for the matrixed tools, and run-once for the static / security tiers.


### Compatibility

Each Magento line is installed on its supported PHP versions, then the module is built (DI compile + static-content deploy). Cells show passed / failed / untested; staircase gaps render as `–`.

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | Pass | Pass | – | – |
| 2.4.8 | – | Pass | Pass | – |
| 2.4.9 | – | – | Pass | Pass |


### Code Quality

Advisory checks against the module's source. Never affect the Compatibility verdict — a phpcs finding can't make a module incompatible.

#### Static Analysis

Coding standards (phpcs), mess detection (phpmd), copy-pasted code (cpd), PHP cross-version compatibility, composer.json validity. Each runs once for the whole module.

| Tool | Status | Findings | Summary |
|---|---|---|---|
| PHPCS | Fail | 11 | 1 error, 10 warnings (ruleset: Magento2) — 8 auto-fixable with phpcbf |
| PHPMD | Warning | 6 | 6 rule violations (UnusedFormalParameter:3, UndefinedVariable:1, UnusedLocalVariable:1, MissingImport:1) |
| Cpd | Pass | 0 |  |
| Composer validate | Pass | 0 |  |

#### PHPStan

Type-checks the module against a real Magento install. Re-runs per Magento + PHP version because resolvable symbols differ between releases.

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | 2 | 2 | – | – |
| 2.4.8 | – | 2 | 2 | – |
| 2.4.9 | – | – | 2 | 2 |


### Tests

Unit and integration suites run per Magento + PHP cell. Test failures speak to the module's behaviour, not its compatibility with a line, so they're reported here separately.

#### Unit Tests

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | N/A | N/A | – | – |
| 2.4.8 | – | N/A | N/A | – |
| 2.4.9 | – | – | N/A | N/A |

#### Integration Tests

| Magento | PHP 8.2 | PHP 8.3 | PHP 8.4 | PHP 8.5 |
|---|---|---|---|---|
| 2.4.7 | Pass | Pass | – | – |
| 2.4.8 | – | Pass | Error | – |
| 2.4.9 | – | – | Pass | not tested |


### Security

Dependency-advisory audit (composer audit) plus a source malware scan. A malware detection fails the version outright.

| Tool | Status | Findings | Summary |
|---|---|---|---|
| Composer audit | Pass | 0 |  |
| Malware scan | Pass | 0 |  |

## Licence and pricing

Free. A licence is still minted on checkout and bound to your project for Composer access — no payment step.

Refundable within 14 days of first purchase via https://packagento.com/account/refunds/.

## Install via Claude Code or any MCP client

The Packagento MCP server can run the licence + project + Composer steps above in one tool call:

```
purchase_and_install_packages(
  composer_names=["aligent/magento2-pci-4-compatibility"],
  project_id="proj_xxx"
)
```

This handles cart, checkout, licence minting, project activation, and writes auth.json credentials. Connect a client with `claude mcp add packagento https://mcp.packagento.com`. Full setup at https://packagento.com/docs/mcp-setup.

## Vendor

aligent is a Magento 2 vendor on Packagento. See https://packagento.com/aligent.md for their full catalogue.

