<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Zelpex</title>
    <description>The latest articles on DEV Community by Zelpex (zelpex).</description>
    <link>https://dev.to/zelpex</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F13872%2F00f1d8e8-434f-45e7-a016-996376863322.jpeg</url>
      <title>DEV Community: Zelpex</title>
      <link>https://dev.to/zelpex</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zelpex"/>
    <language>en</language>
    <item>
      <title>Magento 2.4.6 Lost Support in August: What Waiting Actually Costs</title>
      <dc:creator>Andrii B.</dc:creator>
      <pubDate>Wed, 23 Sep 2026 18:19:09 +0000</pubDate>
      <link>https://dev.to/zelpex/magento-246-lost-support-in-august-what-waiting-actually-costs-bie</link>
      <guid>https://dev.to/zelpex/magento-246-lost-support-in-august-what-waiting-actually-costs-bie</guid>
      <description>&lt;p&gt;If your store runs Magento 2.4.6, it stopped receiving security patches on 11 August 2026. The one exception is Adobe Commerce, the paid edition, which gets one more year. Magento Open Source, the free edition, does not.&lt;/p&gt;

&lt;p&gt;So the decision in front of you is about exposure, not features: how long you are willing to run a checkout that nobody will fix when the next hole is found, and what it costs to stop.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who is out of support, and until when
&lt;/h2&gt;

&lt;p&gt;Adobe gives every 2.4 release three years of standard support, then stops shipping patches for it. For 2.4.6 and 2.4.7 it adds one extra year, but its lifecycle policy grants that year to "Adobe Commerce customers" only.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Version&lt;/th&gt;
&lt;th&gt;Standard support ended / ends&lt;/th&gt;
&lt;th&gt;Adobe Commerce only, extended to&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;2.4.6&lt;/td&gt;
&lt;td&gt;11 August 2026&lt;/td&gt;
&lt;td&gt;31 August 2027&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2.4.7&lt;/td&gt;
&lt;td&gt;31 May 2027&lt;/td&gt;
&lt;td&gt;31 May 2028&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2.4.8&lt;/td&gt;
&lt;td&gt;31 May 2028&lt;/td&gt;
&lt;td&gt;–&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;2.4.9&lt;/td&gt;
&lt;td&gt;31 May 2029&lt;/td&gt;
&lt;td&gt;–&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;There is a second clock under the first, and it catches Adobe Commerce customers too. Magento 2.4.6 runs on PHP 8.1 or 8.2. PHP 8.1 stopped receiving security fixes on 25 November 2025, and PHP 8.2 stops on 31 December 2026. So even a licence holder using the extra year will spend most of it on a language version that no longer gets security fixes of its own. The extension buys time to plan the upgrade. It is not a place to stay.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxwj260a0lglxh63y4fkd.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fxwj260a0lglxh63y4fkd.jpg" alt="Timeline showing PHP 8.1 and 8.2 losing security support around the end of Magento 2.4.6 standard support in August 2026, with 2.4.9 supported until May 2029." width="799" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What waiting has cost other stores
&lt;/h2&gt;

&lt;p&gt;The usual argument for waiting is that nothing has gone wrong yet. The last two years of Magento security history say otherwise.&lt;/p&gt;

&lt;p&gt;In June 2024 Adobe patched CosmicSting (CVE-2024-34102), a flaw that let attackers read files on the server, including the store's secret encryption key. Sansec, which monitors Magento stores, reported that by that autumn 5% of all Adobe Commerce and Magento stores had a payment skimmer on their checkout page: 4,275 stores, attacked by seven competing groups. Some of them had installed the patch. Patching did not invalidate keys that had already been stolen, so stores that skipped rotating the key stayed open.&lt;/p&gt;

&lt;p&gt;In September 2025 Adobe shipped an emergency fix for SessionReaper (CVE-2025-54236), a critical flaw that could lead to remote code execution. Six weeks later, when attacks began, Sansec found 62% of Magento stores still unpatched.&lt;/p&gt;

&lt;p&gt;Two things follow for a store deciding what to do about 2.4.6. The gap between a fix and mass exploitation is measured in weeks, not years. And on an unsupported version there is no fix to install when the next one arrives: you are in the 62% by default, with no way out except the upgrade you postponed.&lt;/p&gt;

&lt;h2&gt;
  
  
  The compliance side
&lt;/h2&gt;

&lt;p&gt;If you take card payments, PCI DSS requirement 6.3.3 expects critical security patches to be installed within 30 days of release. Version 4.0.1 of the standard narrowed that to critical vulnerabilities only, but kept the deadline.&lt;/p&gt;

&lt;p&gt;A store on an unsupported version cannot meet that requirement the ordinary way, because no patch will be released. That doesn't make you non-compliant overnight, and it isn't legal advice. It does mean that at your next assessment you will need to explain which compensating controls you rely on instead, and that conversation gets harder every month the version stays in place.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the upgrade actually involves
&lt;/h2&gt;

&lt;p&gt;The upgrade itself is rarely the expensive part. What makes it expensive is everything around the Magento code.&lt;/p&gt;

&lt;p&gt;The infrastructure moves first. Magento 2.4.8 runs on PHP 8.3 or 8.4, and 2.4.9 only on PHP 8.5 with OpenSearch 3, so the hosting stack has to change along with the application. Then come extensions and integrations: Adobe's own guidance notes that Marketplace extensions and third-party integrations may be affected, and each one has to be checked, updated or replaced. A store with a handful of well-maintained extensions and a stock theme is a very different project from one with years of custom modules and a hand-built ERP sync.&lt;/p&gt;

&lt;p&gt;That is also why the cost of waiting compounds. Adobe says plainly that regular updates take less overall effort than infrequent ones. A store that moves every release does a small upgrade each time. A store that skips two or three does all of them at once, under pressure, usually after something has already gone wrong.&lt;/p&gt;

&lt;p&gt;Our view on the target: go to the newest release your extensions support. If everything you rely on runs on 2.4.9, that buys support until May 2029. If a critical extension isn't ready, 2.4.8 is a sound stop until May 2028, and the next step from there is smaller.&lt;/p&gt;

&lt;h2&gt;
  
  
  The options, honestly
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Upgrade on Magento.&lt;/strong&gt; For most stores this is the answer. It keeps your catalogue, customers, order history and integrations where they are.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Move to Mage-OS.&lt;/strong&gt; Mage-OS is a community-maintained distribution of Magento Open Source that ships its own releases and security patches, with the aim of patching faster. It is currently based on Magento 2.4.9, so switching is itself an upgrade, not a way to stay on 2.4.6. It is worth considering if you would rather not depend on Adobe's release schedule for the free edition.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Replatform.&lt;/strong&gt; If the upgrade estimate comes back close to the cost of moving, it is fair to ask whether Magento is still the right platform. That is a bigger decision with its own hidden costs; we compared the platforms in &lt;a href="https://zelpex.com/blog/exploring-the-cost-of-ownership-magento-shopify-and-bigcommerce-compared" rel="noopener noreferrer"&gt;what Adobe Commerce, Shopify and BigCommerce actually cost&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do nothing.&lt;/strong&gt; A web application firewall and closer monitoring reduce risk while you plan. They buy time. They don't replace patches, and they don't help with the PHP version underneath.&lt;/p&gt;

&lt;h2&gt;
  
  
  Before you get an estimate
&lt;/h2&gt;

&lt;p&gt;Four questions decide how big this job is:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Which edition are you on?&lt;/strong&gt; Adobe Commerce gives you until 31 August 2027. Open Source gave you until 11 August 2026.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Which PHP version does the server run?&lt;/strong&gt; If it is 8.1, the language itself is already out of security support.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;How many extensions and custom modules does the store use, and who maintains them?&lt;/strong&gt; This list drives the estimate more than anything else.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;What sits around the store?&lt;/strong&gt; ERP, PIM, payment and shipping integrations each need testing against the new version.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If you would rather work through this against your own store's extension list and integrations, &lt;a href="https://zelpex.com/contact-us" rel="noopener noreferrer"&gt;talk to us&lt;/a&gt;.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Support dates verified against Adobe's &lt;a href="https://experienceleague.adobe.com/en/docs/commerce-operations/release/planning/lifecycle-policy" rel="noopener noreferrer"&gt;software lifecycle policy&lt;/a&gt; and &lt;a href="https://experienceleague.adobe.com/en/docs/commerce-operations/installation-guide/system-requirements" rel="noopener noreferrer"&gt;system requirements&lt;/a&gt;, and PHP dates against &lt;a href="https://www.php.net/supported-versions.php" rel="noopener noreferrer"&gt;php.net&lt;/a&gt;, in September 2026. Incident figures from Sansec's reports on &lt;a href="https://sansec.io/research/cosmicsting-fallout" rel="noopener noreferrer"&gt;CosmicSting&lt;/a&gt; and &lt;a href="https://sansec.io/research/sessionreaper-exploitation" rel="noopener noreferrer"&gt;SessionReaper&lt;/a&gt;; PCI DSS changes from the &lt;a href="https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1" rel="noopener noreferrer"&gt;PCI Security Standards Council&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://zelpex.com/blog/magento-2-4-6-end-of-support-cost-of-waiting" rel="noopener noreferrer"&gt;zelpex.com&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>magento</category>
      <category>ecommerce</category>
      <category>security</category>
      <category>php</category>
    </item>
    <item>
      <title>When a Manufacturer's CRM Should Be Built, Not Bought</title>
      <dc:creator>Andrii B.</dc:creator>
      <pubDate>Wed, 23 Sep 2026 17:50:28 +0000</pubDate>
      <link>https://dev.to/zelpex/when-a-manufacturers-crm-should-be-built-not-bought-1imn</link>
      <guid>https://dev.to/zelpex/when-a-manufacturers-crm-should-be-built-not-bought-1imn</guid>
      <description>&lt;p&gt;Most manufacturers who ask whether they should build their own CRM are asking about the wrong piece of software. The part their sales team uses every day is close to a commodity, and buying it is usually right. The part their dealers, distributors and service technicians touch is where the business is genuinely different, and it is also where the licence bill grows fastest.&lt;/p&gt;

&lt;p&gt;So the useful question is narrower: which part of the CRM should you build, and which part would you be foolish to build?&lt;/p&gt;

&lt;h2&gt;
  
  
  Why manufacturing sales breaks generic CRM
&lt;/h2&gt;

&lt;p&gt;A CRM is designed around a contact, a deal and a pipeline. Manufacturing sales rarely looks like that. The customer is a distributor with negotiated contract pricing. The order is a spare part identified by a code that was superseded two revisions ago. The delivery date depends on a production slot the ERP knows about and the CRM does not. And the person asking is often a technician on a plant floor, not a buyer in an office.&lt;/p&gt;

&lt;p&gt;None of that data belongs to the CRM. Price, availability and lead time live in the ERP, and they have to stay there. Every CRM project for a manufacturer therefore turns into the same work: showing people outside the ERP an honest answer from inside it, without exposing how complicated it is to produce. That is true whether you buy the CRM or build it, and it is the part of the budget people tend to underestimate.&lt;/p&gt;

&lt;h2&gt;
  
  
  What buying actually costs
&lt;/h2&gt;

&lt;p&gt;The vendors built for this are not cheap, and they price per person. Salesforce's industry product for manufacturers, Manufacturing Cloud, lists at &lt;strong&gt;$275 per user per month&lt;/strong&gt; for its Sales or Service "Core" editions, $425 for the Advanced edition, and $650 to $700 for the "Max" editions that bundle its AI agents, all on annual contracts. HubSpot's Sales Hub is the lighter alternative at &lt;strong&gt;$90 per seat per month&lt;/strong&gt; on Professional (billed annually) and $150 on Enterprise, plus a mandatory one-off onboarding fee of $1,500 or $3,500.&lt;/p&gt;

&lt;p&gt;Seats for your own staff are only half the bill. The other half is everyone outside the company who needs to log in.&lt;/p&gt;

&lt;p&gt;Salesforce prices its partner portal, Partner Relationship Management, at &lt;strong&gt;$25 per member per month&lt;/strong&gt;, with a more capable tier at $50 and login-based pricing available for users who rarely sign in. Run the list prices for a hypothetical mid-size manufacturer: 15 internal users on Manufacturing Cloud Sales Core and 300 dealer accounts on the partner portal.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Line&lt;/th&gt;
&lt;th&gt;Calculation&lt;/th&gt;
&lt;th&gt;Per year, list price&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Internal users&lt;/td&gt;
&lt;td&gt;15 × $275 × 12&lt;/td&gt;
&lt;td&gt;$49,500&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dealer portal members&lt;/td&gt;
&lt;td&gt;300 × $25 × 12&lt;/td&gt;
&lt;td&gt;$90,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total licences&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;$139,500&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The dealers cost almost twice as much as the sales team, before a single integration is built. List prices get discounted and login-based licences cut the portal line for dealers who sign in rarely, so treat the table as the shape of the bill rather than a quote. The shape is the point: in manufacturing, the external audience is usually larger than the internal one, and per-member pricing scales with it every year.&lt;/p&gt;

&lt;h2&gt;
  
  
  The quoting trap
&lt;/h2&gt;

&lt;p&gt;Quoting is usually where a packaged CRM starts to fit badly. Prices come from rules, not a table: the customer's contract, the volume, the configuration, which options are compatible with which, and what the ERP says a variant actually costs to make.&lt;/p&gt;

&lt;p&gt;The standard answer used to be Salesforce CPQ, and it is no longer sold to new customers. Existing customers keep it, with support and renewals but no new features, while new buyers are pointed at its successor, Revenue Cloud Advanced. Salesforce is careful to call this end of sale, not end of life. For a manufacturer choosing today, though, it means the configure-price-quote layer most comparison articles describe is not the one you would be buying, and a quoting project is a separate licence and a separate implementation on top of the CRM.&lt;/p&gt;

&lt;p&gt;This is the first place building starts to make sense. If your pricing logic is yours alone, encoding it in a quoting tool you own is often cheaper and clearer than bending a generic rules engine around it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where building earns its place
&lt;/h2&gt;

&lt;p&gt;We would split the system in three and treat each part differently.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The internal CRM: buy it.&lt;/strong&gt; Accounts, pipeline, activity history, service cases, reporting. This is well-solved software. Building it means rebuilding permissions, audit trails, email sync and mobile access that a vendor already maintains, and your team would be maintaining them for ever.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The ERP: leave it alone.&lt;/strong&gt; It is the system of record for price, stock and lead time. Neither the CRM nor anything you build should hold a second copy of those numbers that can drift.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The dealer portal and quoting rules: build them when they are where you compete.&lt;/strong&gt; This is the software your customers actually use. It carries your contract pricing, your supersession chains for spare parts, your serial-number history for service, and your availability promises. A custom portal is priced once to build and then maintained, not charged per dealer per month, and it can read the ERP directly instead of through a CRM in the middle.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F79lberq2b1fqno2gipuh.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F79lberq2b1fqno2gipuh.jpg" alt="Diagram of an ERP kept as the system of record, a bought CRM for the sales team and a custom-built dealer portal reading from both." width="799" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The split is not free. A custom portal needs an owner, a hosting bill, security updates and someone who understands it when the person who built it has moved on. If you have no one to own software, the per-member licence is the price of not needing them, and it can be worth paying.&lt;/p&gt;

&lt;h2&gt;
  
  
  The test
&lt;/h2&gt;

&lt;p&gt;Before deciding, answer four questions honestly.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;How many people outside the company need to log in?&lt;/strong&gt; If it is a handful, a vendor portal is fine. If it is hundreds of dealers or technicians, price the per-member line over five years before anything else.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Is your pricing a table or a set of rules?&lt;/strong&gt; A price list fits any CRM. Contract pricing, configuration rules and ERP-derived costs are where packaged quoting gets expensive and awkward.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Where does the true answer on availability live?&lt;/strong&gt; If it is the ERP, whatever customers see has to read from it, and that integration is the real project either way.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Who will own the software in three years?&lt;/strong&gt; Building only works if the answer is a named person or a partner, not "IT".&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If the answers are "few", "a table", "the ERP" and "nobody", buy the whole thing and keep the configuration shallow. If they are "hundreds", "rules", "the ERP" and "we can", buy the CRM, build the portal, and let the ERP stay the source of truth.&lt;/p&gt;

&lt;p&gt;If you would rather work this through against your own dealer network and pricing rules, &lt;a href="https://zelpex.com/contact-us" rel="noopener noreferrer"&gt;talk to us&lt;/a&gt;.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Prices verified against &lt;a href="https://www.salesforce.com/manufacturing/cloud/pricing/" rel="noopener noreferrer"&gt;Salesforce Manufacturing Cloud&lt;/a&gt;, &lt;a href="https://www.salesforce.com/sales/partner-relationship-management/pricing/" rel="noopener noreferrer"&gt;Salesforce Partner Relationship Management&lt;/a&gt; and &lt;a href="https://www.hubspot.com/pricing/sales" rel="noopener noreferrer"&gt;HubSpot Sales Hub&lt;/a&gt; pricing pages, and Salesforce's &lt;a href="https://www.salesforce.com/sales/cpq/end-of-life/" rel="noopener noreferrer"&gt;CPQ end-of-sale page&lt;/a&gt;, in September 2026. All figures are list prices in US dollars.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://zelpex.com/blog/manufacturer-crm-build-vs-buy" rel="noopener noreferrer"&gt;zelpex.com&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>crm</category>
      <category>salesforce</category>
      <category>manufacturing</category>
      <category>saas</category>
    </item>
  </channel>
</rss>
