S SecurityScan

Platform guide

PrestaShop security and cookie consent scanner

PrestaShop shops get most of their tracking from modules, and many of them load on every page as soon as they are configured. SecurityScan shows which cookies appear before a visitor consents, and checks the shop’s security basics at the same time.

securityscan --free

No account needed. We email a mini report — technical check, not legal advice. By scanning you confirm you are authorised to scan this domain and agree to our Terms and Privacy Policy.

What the scan checks

Cookies before consent

Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.

Outdated JavaScript

Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.

Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

SSL/TLS certificate

A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.

Exposed files and server settings

Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.

What we usually find on PrestaShop

Modules that track straight away

Analytics, ads and remarketing modules often add their tags site-wide once configured. If the consent module doesn’t control them, the cookies load immediately. The scan names each tracking cookie it saw before any consent choice.

A consent module without “Reject”

The scan checks that a consent banner is shown and that it has a reject button alongside accept.

Old theme JavaScript

Themes on older PrestaShop versions often bundle jQuery and plugins that are years out of date. The scan compares the versions the shop loads with versions that have known vulnerabilities.

Headers and leftover files

Self-hosted shops often send no security headers, and leftovers such as a .git folder or an .env file can stay reachable from the web.

Fixing findings on PrestaShop

For tracking, check each analytics or ads module in the back office for a consent option, or have your consent module block it until the visitor agrees. Headers and blocked paths go in the web server configuration or .htaccess.

The scan recognises PrestaShop from its generator tag, its JavaScript object and its session cookie. Recognition is informational and never changes the score.

Questions

Do I need to install a PrestaShop module?
No. The scan runs from outside and needs only the domain.
Which PrestaShop versions does it support?
Any. The checks look at what the shop serves to visitors, not at its code.
Is this legal advice?
No. It is a technical check. It does not replace a consultation with a lawyer.