Devolucion facil - sin preguntas
Instalar, configurar y beneficiarse
Prioridad en ayuda y satisfaccion
Total Defensor
Suite de seguridad completa con firewall, escáner y protección de inicio de sesión
Protección Integral de Seguridad y Anti-Spam para PrestaShop
Total Defender es una suite de seguridad de espectro completo que protege tu tienda PrestaShop contra spam, bots, ataques de fuerza bruta, malware y vulnerabilidades. Combina limitación de velocidad, gestión de IP, monitoreo de integridad de archivos, firewall de aplicaciones web, seguridad de correo electrónico, gestión de copias de seguridad y 2FA de administración en un único módulo — sin servicios externos.
- Protección Anti-Spam — campos honeypot, integración CAPTCHA, filtrado de mensajes y validación de enlaces para bloquear el spam
- Limitación de Velocidad — restricción por acción para carrito, registro, formularios de contacto y comentarios con bloqueo automático de IP
- Gestión de Bots y Rastreadores — detección por comportamiento, desafíos JS y listas blancas de rastreadores para separar bots buenos de maliciosos
- Gestión de IP — lista blanca, lista negra, puntuación de penalización, detección de nodos de salida TOR y reglas basadas en GeoIP
- Monitoreo de Integridad de Archivos — instantáneas de referencia con alertas cuando se modifican archivos del núcleo o módulos de forma inesperada
- Firewall de Aplicaciones Web — reglas personalizadas para bloquear XSS, SQL injection y otros ataques basados en entrada
- Escáner de Vulnerabilidades — verifica el núcleo de PrestaShop, módulos y versión de PHP contra CVEs conocidos
- Cabeceras de Seguridad — generación de CSP y registro de violaciones para reforzar la seguridad del navegador
- Seguridad de Correo Electrónico — limitación de emails salientes, bloqueo de dominios desechables y detección de patrones de abuso
- Sistema de Copias de Seguridad — copias completas e incrementales con programación, múltiples adaptadores de almacenamiento y puntos de restauración
- 2FA de Administración — autenticación de dos factores basada en TOTP para cuentas de empleados del back office
- Seguimiento de Sesiones — monitorea sesiones de visitantes con atribución, páginas vistas, parámetros UTM y detección de dispositivo
- Registro de Auditoría — historial completo de acciones de administración con direcciones IP, agentes de usuario y marcas de tiempo
Compatible con PrestaShop 1.7 a 9.x. Una licencia, actualizaciones de por vida, 90 días de soporte dedicado.
Complete Security — From Spam to Sophisticated Attacks
E-commerce stores face a constant barrage of threats. Automated bots submit hundreds of spam registrations per day. Credential-stuffing attacks target admin and customer logins around the clock. Malicious scripts probe for known vulnerabilities in PrestaShop core and modules. A single breach can expose customer payment data, destroy trust, and trigger regulatory penalties under GDPR.
Total Defender is a full-spectrum security suite that protects your store at every layer. Anti-spam stops form abuse. Rate limiting prevents brute-force attacks. A web application firewall blocks injection attacks. File integrity monitoring catches unauthorized code changes. Vulnerability scanning alerts you to known CVEs. Admin two-factor authentication ensures that stolen passwords alone cannot compromise your back office. And a comprehensive audit log gives you forensic visibility into every action.
Anti-Spam Protection
Spam is the most common and most visible attack vector. Fake registrations pollute your customer database, spam contact form messages waste support time, and fake reviews damage your store's credibility. Total Defender blocks spam at the source.
- Honeypot fields — invisible form fields that catch automated bots without affecting real customers
- CAPTCHA integration — support for reCAPTCHA v2, v3, and hCaptcha on registration, contact, and comment forms
- Message filtering — keyword-based filtering to block messages containing spam patterns, excessive links, or prohibited terms
- Link validation — detect and block form submissions containing suspicious URLs or redirect chains
- Disposable email blocking — reject registrations from known disposable email providers
Rate Limiting & Brute-Force Protection
- Per-action throttling — separate rate limits for cart additions, registration, contact form submissions, login attempts, and comments
- Automatic IP blocking — IPs that exceed rate limits are automatically blocked for a configurable duration
- Progressive lockout — repeat offenders face escalating block durations (1 hour → 24 hours → permanent)
- Admin login protection — separate, stricter rate limits for back-office login attempts
- API rate limiting — throttle webservice API requests to prevent abuse and resource exhaustion
Bot & Crawler Management
- Behavioral detection — identify bots by browsing patterns (speed, mouse movement, JavaScript execution) rather than just user-agent strings
- JavaScript challenges — serve lightweight JS challenges to suspicious visitors that real browsers pass instantly but headless bots fail
- Crawler whitelisting — ensure Google, Bing, and other legitimate crawlers are never accidentally blocked
- TOR exit node detection — identify and optionally block connections from TOR exit nodes
- User-agent filtering — block known malicious bot user-agents and tools
IP Management & GeoIP
- IP whitelist — ensure your own IPs and trusted partners are never blocked
- IP blacklist — permanently block specific IPs or CIDR ranges
- Penalty scoring — accumulate risk scores based on suspicious behavior before triggering a block
- GeoIP-based rules — allow or block access from specific countries or regions
- Admin panel restriction — limit back-office access to specific IP addresses or ranges
File Integrity Monitoring
- Baseline snapshots — SHA-256 hash of every monitored file stored as a reference point
- Change detection — identify files that have been added, modified, or removed since the last baseline
- Scheduled scans — automatic integrity checks via cron (hourly, daily, or weekly)
- Exclusion rules — exclude cache, log, and other expected-change directories
- Email alerts — immediate notification when unauthorized modifications are detected
- Diff viewer — side-by-side comparison showing exactly what changed in modified files
Web Application Firewall & Security Headers
- XSS protection — detect and block cross-site scripting attempts in form inputs and URL parameters
- SQL injection blocking — pattern-based detection of SQL injection payloads in requests
- Custom firewall rules — define your own rules to block specific request patterns
- Content Security Policy (CSP) — visual builder for CSP headers with violation logging
- HSTS, X-Frame-Options, Referrer-Policy — configure all security headers from the admin panel
- Permissions-Policy — restrict browser API access (camera, microphone, geolocation) on your pages
Vulnerability Scanner
- PrestaShop core CVE check — compare your installed version against known vulnerabilities
- Module vulnerability scanning — check installed modules against known CVE databases
- PHP version check — verify your PHP version is not end-of-life or known-vulnerable
- Severity ratings — each finding includes a severity level (critical, high, medium, low) and remediation advice
- Scheduled scanning — run vulnerability checks on a regular schedule with email alerts for new findings
Admin 2FA, Backup & Audit
- TOTP two-factor authentication — compatible with Google Authenticator, Authy, and any TOTP app
- Per-employee enforcement — require 2FA for all employees or specific profiles
- Recovery codes — single-use backup codes for employees who lose their 2FA device
- Backup system — full and incremental backups with scheduling and multiple storage adapters
- Session tracking — monitor active visitor sessions with device, IP, and UTM attribution
- Complete audit log — every admin action recorded with IP, user agent, and timestamp
- Email rate limiting — prevent outbound email abuse from compromised forms
Why is this module unique?
- The most comprehensive PrestaShop security module available — combines anti-spam, rate limiting, WAF, file integrity, vulnerability scanning, 2FA, backups, and audit logging in a single package
- No external services required — everything runs on your own server with no monthly fees, API dependencies, or data leaving your infrastructure
- Behavioral bot detection with JavaScript challenges catches sophisticated bots that user-agent filtering misses
- Penalty scoring system reduces false positives by accumulating risk before blocking, rather than blocking on a single suspicious action
- CSP header visual builder eliminates the notoriously difficult process of writing Content Security Policy rules by hand
Use Cases
- Stores processing payments — PCI DSS compliance requires file integrity monitoring, access controls, and strong authentication
- Stores handling personal data — GDPR requires audit trails of data access and modification
- Stores targeted by spam — anti-spam and rate limiting eliminate automated form abuse
- Stores with multiple admin users — 2FA and audit logging ensure accountability across the team
- Stores previously compromised — file integrity monitoring and vulnerability scanning provide ongoing assurance after a breach cleanup
- High-traffic stores — rate limiting and bot management prevent resource exhaustion from automated traffic
-
Referenciamprtotaldefender
-
En stock999 Artículos
-
Compatibilidad PrestaShopPS 1.7 – 9.x
-
Modelo de precioCompra unica
-
Tipo de moduloFront & Back-office
-
Relevante para RGPDSi
-
Objetivo comercialOptimizar operaciones
-
Cuenta externa necesariaNo
-
Complejidad del moduloSolucion completa
-
Etapa del recorrido del clienteGestionar la tienda
-
Funciona con plataformaSin plataforma externa
Devolucion facil - sin preguntas
Instalar, configurar y beneficiarse
Prioridad en ayuda y satisfaccion
No reviews yet. Be the first to leave a review!
Write a Review