S SecurityScan

Platform guide

OpenCart security and cookie consent scanner

On OpenCart, tracking usually sits in extensions or in code pasted into the theme’s header template, which often bypasses whatever consent banner the shop uses. SecurityScan shows what loads before consent and checks the shop’s security basics.

securityscan --free

No account needed. We email a mini report — technical check, not legal advice. By scanning you confirm you are authorised to scan this domain and agree to our Terms and Privacy Policy.

What the scan checks

Cookies before consent

Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.

Outdated JavaScript

Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.

Exposed files and server settings

Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.

Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

SSL/TLS certificate

A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.

What we usually find on OpenCart

Tracking in the header template

Analytics or pixel code pasted straight into the theme header runs on every page, before any consent choice. The scan names the tracking cookies it produced.

Old jQuery

Older OpenCart versions and many themes ship an old jQuery. The scan reads the version from the page and compares it with versions that have known vulnerabilities.

Files reachable from the web

A .git folder, an .env file, composer.json or an error log left in the web root. The scan requests a fixed list of such paths and reports any that answer.

Session cookie flags

The scan checks every cookie it sees, including the OCSESSID session cookie, for the Secure, HttpOnly and SameSite flags.

Fixing findings on OpenCart

Move tracking code out of the header template and into an extension or tag manager that your consent banner controls. Block sensitive paths and add security headers in the web server configuration or .htaccess.

The scan recognises OpenCart from its session cookie, its catalog/view asset paths and its index.php?route= links. Recognition is informational and never changes the score.

Questions

Do I need to install an OpenCart extension?
No. The scan runs from outside and needs only the domain.
Will updating jQuery break my theme?
It can, especially across major versions. Test the update on a copy of the shop first, then re-scan to confirm the finding is gone.
Is this legal advice?
No. It is a technical check. It does not replace a consultation with a lawyer.