Platform guide
OpenCart security and cookie consent scanner
On OpenCart, tracking usually sits in extensions or in code pasted into the theme’s header template, which often bypasses whatever consent banner the shop uses. SecurityScan shows what loads before consent and checks the shop’s security basics.
What the scan checks
Cookies before consent
Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.
Outdated JavaScript
Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.
Exposed files and server settings
Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.
Security headers
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
SSL/TLS certificate
A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.
What we usually find on OpenCart
Tracking in the header template
Analytics or pixel code pasted straight into the theme header runs on every page, before any consent choice. The scan names the tracking cookies it produced.
Old jQuery
Older OpenCart versions and many themes ship an old jQuery. The scan reads the version from the page and compares it with versions that have known vulnerabilities.
Files reachable from the web
A .git folder, an .env file, composer.json or an error log left in the web root. The scan requests a fixed list of such paths and reports any that answer.
Session cookie flags
The scan checks every cookie it sees, including the OCSESSID session cookie, for the Secure, HttpOnly and SameSite flags.
Fixing findings on OpenCart
Move tracking code out of the header template and into an extension or tag manager that your consent banner controls. Block sensitive paths and add security headers in the web server configuration or .htaccess.
The scan recognises OpenCart from its session cookie, its catalog/view asset paths and its index.php?route= links. Recognition is informational and never changes the score.
Questions
- Do I need to install an OpenCart extension?
- No. The scan runs from outside and needs only the domain.
- Will updating jQuery break my theme?
- It can, especially across major versions. Test the update on a copy of the shop first, then re-scan to confirm the finding is gone.
- Is this legal advice?
- No. It is a technical check. It does not replace a consultation with a lawyer.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.