When it comes to magecart attacks, no one can do anything locally, no matter what uber-awesome security softs you have; no browsers, no AV, no Ai, no Cloud, no sandbox, no anti-exe, no SRP !
Why? because it is 100% server side attack using malicious javascript, and only the site dev can fix this.
You personally , the best you can do ? disable javascript but then you will break most sites especially the shopping ones you aimed to go.
So when you see some dumb marketing statement saying they will protect you from all threats, it is just plain BS. Every vendors is here for money, they won't say they can't protect you, some will even lie to your face to make you buy their product.
Real cybercriminals don't care much anymore of sending some malicious exe to your personal system, they aim the big fishes: compromising servers and skimming customers datas.
Why need a skimmer on your system that will be flagged by most security solutions when you can put an obfuscated one on the site servers which are barely monitored...
How many sites are coded properly? how many uses only proprietary code and not mixing it with 3rd party ones (which can also be compromised) hence preventing a proper audit? almost none.
So basically, when it comes to external security, you have no control but that security vendors will never tell you, why?
You pay them for some security, they won't tell you they can't protect you if you buy online, if they did, why pay them then...
So go ahead, buy SafeOnline this, SecureOnline that , in the end, cybercriminals just laugh at you.