S SecurityScan

Platform guide

Odoo website security and cookie consent scanner

An Odoo website runs on the same server as your ERP, so a weakness on the public site is a weakness next to your customers, invoices and stock. SecurityScan checks the site from the outside, the way a visitor sees it, and adds checks for the Odoo routes that are most often left open.

securityscan --free

No account needed. We email a mini report — technical check, not legal advice. By scanning you confirm you are authorised to scan this domain and agree to our Terms and Privacy Policy.

What the scan checks

Odoo exposures

A public database manager, including one with no master password set, and a Website Info page that lists the Odoo version and installed apps.

Cookies before consent

Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.

Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

SSL/TLS certificate

A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.

Outdated JavaScript

Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.

Exposed files and server settings

Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.

Checks that run only on Odoo

When the scan recognises Odoo, from its generator tag, its odoo JavaScript object, its asset bundles or its frontend_lang cookie, it also requests two well-known Odoo addresses. It confirms each one by its content, so a site that answers every address with a normal page doesn’t produce false alarms.

A public database manager

Whether /web/database/manager opens for anyone. That page can back up, duplicate, restore and delete whole databases, and only the master password protects it. If Odoo itself warns that no master password is set, the report says so, because then anyone can set one.

Version and installed apps on show

Whether /website/info lists the Odoo version and every installed application. It tells an attacker which known vulnerabilities are worth trying.

Where Odoo problems usually come from

Self-hosted defaults

A self-hosted Odoo lists its databases and serves the database manager unless list_db is switched off in the configuration file. Many installs behind Nginx or Apache never block the /web/database/ addresses in the proxy either.

Tracking code outside the cookie bar

Analytics and ad tags pasted into the website’s custom head code, or added by a theme or third-party module, can run before a visitor answers the cookie bar. The scan names each tracking cookie it saw before any consent choice.

A cookie bar that is off or has no way to refuse

The Odoo cookie bar is optional and has to be switched on in the website settings. The scan checks that a banner is shown and that it offers a choice such as “Only essentials” next to “I agree”.

Headers left to the proxy

Odoo itself sends few security headers. Strict-Transport-Security, Content-Security-Policy and Referrer-Policy are usually added in the reverse proxy in front of it.

Fixing findings on Odoo

Set list_db = False and a long, unique admin_passwd in the Odoo configuration, block /web/database/ in the reverse proxy, and restart the server. Add the security headers in the same proxy configuration. Tracking code belongs behind the cookie bar, not in the custom head code.

Module updates and new installs can reopen what you closed. With a plan, the site is re-scanned automatically and the report is emailed to you.

Questions

Does it work with Odoo Online and Odoo.sh?
Yes. The scan needs only the website’s domain. On Odoo’s own hosting some settings, such as the database manager and the server headers, are managed by Odoo, so the useful findings there are mostly about cookies and consent.
Does the scan log in to Odoo or touch my data?
No. It loads public pages like a visitor and requests a short list of well-known addresses, including the two Odoo ones above. It never logs in, never tries a password and never submits a form.
Which Odoo versions does it support?
Any version with the Website app. The checks look at what the site serves to visitors, not at its code.
Is this legal advice?
No. It is a technical check. It does not replace a consultation with a lawyer.