Platform guide
WooCommerce security and cookie consent scanner
A shop runs more marketing tags than most WordPress sites: analytics, ad pixels, product feeds, review widgets. SecurityScan loads your shop like a first-time visitor and shows which of them set cookies before consent, along with the security basics.
What the scan checks
Cookies before consent
Tracking cookies set before any consent choice, the consent banner and its reject option, the privacy policy link and consent on forms.
WordPress exposures
Public user lists in the REST API, enabled XML-RPC, a readable debug.log, wp-config.php backups, a listable uploads folder and an announced version.
Security headers
HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
SSL/TLS certificate
A valid certificate, days until it expires, and whether plain HTTP redirects to HTTPS.
Outdated JavaScript
Library versions the pages load, such as jQuery or Bootstrap, compared with versions that have known CVEs.
Exposed files and server settings
Files like .git or .env reachable from the web, version-revealing headers, risky HTTP methods, open CORS and cookie flags.
What we usually find on WooCommerce shops
Pixels from marketing and feed plugins
Ads, remarketing and product-feed plugins often add their tags to every page, before the consent banner has been answered. The scan lists each tracking cookie present before any consent choice.
A banner with no way to refuse
The scan checks that a consent banner is shown and that it has a reject button, not only “Accept”.
Forms without consent
Newsletter sign-ups and contact forms that collect an email address with no consent checkbox.
Cookies without security flags
Cookies set without Secure, HttpOnly or SameSite. The finding lists the cookies and which flags each one is missing.
How the scan recognises WooCommerce
The scan recognises WooCommerce from its generator tag, its JavaScript objects and its cookies, so a shop is not mistaken for a plain WordPress blog.
Because WooCommerce runs on WordPress, the shop also gets the WordPress-specific checks: user accounts listed by the REST API, enabled XML-RPC, a readable debug.log, downloadable wp-config.php backups and a listable uploads folder. The WordPress security scanner page explains each one.
Keeping it fixed
Shops add and update plugins often, and one update can bring back a pixel that ignores consent. With a plan, the shop is re-scanned automatically and the report is emailed to you, so a regression shows up within days.
Questions
- Will the scan affect my shop?
- It loads pages like a visitor, reads cookies and headers, and requests a short list of well-known file paths. It does not log in, place orders or send attack payloads.
- Is scanning WooCommerce different from scanning WordPress?
- The checks are the same, including the WordPress-specific ones. What differs is where findings usually come from: on a shop, most tracking comes from marketing and feed plugins.
- Is this legal advice?
- No. It is a technical check. It does not replace a consultation with a lawyer.
Technical checks, not legal advice. SecurityScan does not replace a consultation with a lawyer.