S SecurityScan

Platform guide

WooCommerce security and cookie consent scanner

A shop runs more marketing tags than most WordPress sites: analytics, ad pixels, product feeds, review widgets. SecurityScan loads your shop like a first-time visitor and shows which of them set cookies before consent, along with the security basics.

securityscan --free

No account needed. We email a mini report — technical check, not legal advice. By scanning you confirm you are authorised to scan this domain and agree to our Terms and Privacy Policy.

What the scan checks

Cookies before consent

Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.

WordPress exposures

Public user lists in the REST API, enabled XML-RPC, a readable debug.log, wp-config.php backups, a listable uploads folder and an announced version.

Security headers

HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.

SSL/TLS certificate

A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.

Outdated JavaScript

Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.

Exposed files and server settings

Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.

What we usually find on WooCommerce shops

Pixels from marketing and feed plugins

Ads, remarketing and product-feed plugins often add their tags to every page, before the consent banner has been answered. The scan lists each tracking cookie present before any consent choice.

A banner with no way to refuse

The scan checks that a consent banner is shown and that it has a reject button, not only “Accept”.

Forms without consent

Newsletter sign-ups and contact forms that collect an email address with no consent checkbox.

Cookies without security flags

Cookies set without Secure, HttpOnly or SameSite. The finding lists the cookies and which flags each one is missing.

How the scan recognises WooCommerce

The scan recognises WooCommerce from its generator tag, its JavaScript objects and its cookies, so a shop is not mistaken for a plain WordPress blog.

Because WooCommerce runs on WordPress, the shop also gets the WordPress-specific checks: user accounts listed by the REST API, enabled XML-RPC, a readable debug.log, downloadable wp-config.php backups and a listable uploads folder. The WordPress security scanner page explains each one.

Keeping it fixed

Shops add and update plugins often, and one update can bring back a pixel that ignores consent. With a plan, the shop is re-scanned automatically and the report is emailed to you, so a regression shows up within days.

Questions

Will the scan affect my shop?
It loads pages like a visitor, reads cookies and headers, and requests a short list of well-known file paths. It does not log in, place orders or send attack payloads.
Is scanning WooCommerce different from scanning WordPress?
The checks are the same, including the WordPress-specific ones. What differs is where findings usually come from: on a shop, most tracking comes from marketing and feed plugins.
Is this legal advice?
No. It is a technical check. It does not replace a consultation with a lawyer.