S SecurityScan

Platform guide

Shopify cookie consent and security scanner

On Shopify, the hosting, the certificate and the server settings are managed for you. So the useful part of a scan is different: apps and pixels that track visitors before they agree, and the JavaScript your theme and apps add.

securityscan --free

No account needed. We email a mini report — technical check, not legal advice. By scanning you confirm you are authorised to scan this domain and agree to our Terms and Privacy Policy.

What the scan checks

Cookies before consent

Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.

Outdated JavaScript

Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.

Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

SSL/TLS certificate

A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.

What matters most on a Shopify store

Apps that track before consent

Marketing, review and chat apps add scripts to the storefront, and some set tracking cookies on the first page view. The scan lists every tracking cookie it saw before any consent choice.

The consent banner

Shopify offers its own cookie banner, and many stores use an app instead. The scan checks that a banner is shown and that it has a reject button, not only “Accept”.

Theme and app JavaScript

Older themes can include outdated copies of jQuery or other libraries. The scan compares the versions it finds with versions that have known vulnerabilities.

Forms and the privacy policy

Whether newsletter and contact forms ask for consent, and whether the privacy policy link is there and the page actually loads.

What you can’t change on Shopify

Shopify serves every store over HTTPS with a certificate it manages, and merchants can’t add their own HTTP response headers. If the report shows a missing header such as Content-Security-Policy on a Shopify store, that is the platform’s configuration, not something in your theme.

The report still shows these findings so you have the full picture, but your own fixes belong in apps, pixels and theme code.

Keeping it fixed

Installing or updating an app can add a new tracker without anyone noticing. With a plan, the store is re-scanned automatically and the report is emailed to you.

Questions

Do I need to install a Shopify app?
No. The scan needs only the domain your customers visit, including a custom domain.
Can SecurityScan fix the problems for me?
No. It finds them and says what to change. The changes happen in your Shopify admin, your apps or your theme.
Is this legal advice?
No. It is a technical check of cookies and consent. It does not replace a consultation with a lawyer.