Platform guide
PrestaShop security and cookie consent scanner
PrestaShop shops get most of their tracking from modules, and many of them load on every page as soon as they are configured. SecurityScan shows which cookies appear before a visitor consents, and checks the shop’s security basics at the same time.
What the scan checks
Cookies before consent
Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.
Outdated JavaScript
Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.
Security headers
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
SSL/TLS certificate
A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.
Exposed files and server settings
Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.
What we usually find on PrestaShop
Modules that track straight away
Analytics, ads and remarketing modules often add their tags site-wide once configured. If the consent module doesn’t control them, the cookies load immediately. The scan names each tracking cookie it saw before any consent choice.
A consent module without “Reject”
The scan checks that a consent banner is shown and that it has a reject button alongside accept.
Old theme JavaScript
Themes on older PrestaShop versions often bundle jQuery and plugins that are years out of date. The scan compares the versions the shop loads with versions that have known vulnerabilities.
Headers and leftover files
Self-hosted shops often send no security headers, and leftovers such as a .git folder or an .env file can stay reachable from the web.
Fixing findings on PrestaShop
For tracking, check each analytics or ads module in the back office for a consent option, or have your consent module block it until the visitor agrees. Headers and blocked paths go in the web server configuration or .htaccess.
The scan recognises PrestaShop from its generator tag, its JavaScript object and its session cookie. Recognition is informational and never changes the score.
Questions
- Do I need to install a PrestaShop module?
- No. The scan runs from outside and needs only the domain.
- Which PrestaShop versions does it support?
- Any. The checks look at what the shop serves to visitors, not at its code.
- Is this legal advice?
- No. It is a technical check. It does not replace a consultation with a lawyer.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.