The problems that actually get PrestaShop stores hacked rarely look dramatic — an outdated module with a public CVE, an exposed .git folder or a leftover backup .sql, debug mode left on, world-writable directories, weak cookie and admin hardening, or a stray PHP file dropped in /img. They hide in exactly the places a quick glance never reaches.
Security Scan is a free, open-source module that runs entirely inside your own shop and audits all of it locally in seconds: core & module versions against a bundled CVE/advisory database, exposed files & endpoints, malware & file-integrity signatures, risky code patterns, and configuration hardening (SSL, cookies, admin, brute-force). You get a single 0–100 security score, an A–F grade, and a prioritised list of findings — each with a clear, step-by-step fix you can actually follow.
It is detection-only and safe on a live store: it reads your files, configuration and database, checks your own public URLs, never changes a thing, and only ever writes its own scan history. Nothing leaves your server. Install it, press Scan now, and know exactly where you stand.
When you are ready to act on what it finds, Security Revolution turns findings into one-click fixes with continuous file-integrity monitoring, brute-force protection and fleet-wide oversight.
- Version & CVE checks. Your PrestaShop core, every installed module and PHP, matched against a curated advisory list (seeded from the Friends of Presta security cell) — flags end-of-life versions and modules with published vulnerabilities.
- Verifiable, not alarmist. Every version and CVE match links the official advisory (the CVE record or GitHub Security Advisory) and carries a confidence level, so you can check each flag yourself — low-confidence heuristics are scored low, never dressed up as certainty.
- Exposed files & endpoints. Confirms against your own public URLs that
.git, backup.sql/.zip,/install,phpinfo, directory listing and a readableparameters.phpare not reachable from the web. - Hardening audit. Forced SSL, secure cookie flags, admin-folder protection, CSRF token, brute-force lockout, stale modules and recently-created admin accounts.
- Malware & integrity heuristics. Web-shell and injected-loader signatures, and PHP hiding in image folders — flagged clearly and honestly, never as a false certainty.
- Code-level static scan. Patterns in module code that can indicate unsafe input handling, surfaced privately for your review — never as a public accusation.
- 0–100 score & letter grade. One number, a grade and the passed checks, so you can prioritise the fixes that matter and track your store’s security over time.
- Free, open-source & local. Runs entirely inside your shop; detection-only and safe on live; compatible with PrestaShop 1.7, 8 and 9 and PHP 7.1+.
- Public URL check too. A free ad-hoc scanner passively fingerprints any store you own straight from its URL — no install required.
Run a full security scan from inside your shop
Install and enable the free module, open Configure → Security Scan → Scan & Report and click Run scan now. In a few seconds you get a 0–100 score, a letter grade and every finding grouped by severity, with the passed checks shown too so you can see exactly what was verified. It is safe on a live store — the module only reads your shop and writes its own scan-history record, never touching products, orders or customers.


See exactly what is exposed — and how to fix it
Every finding tells you what was found, why it matters and the exact manual steps to fix it: an exposed .git folder carrying your source history, a backup .sql sitting in the webroot, an /install directory left in place, debug mode still on. The exposure checks are confirmed against your own public URLs, so you are fixing what is genuinely reachable from the internet — not chasing false alarms.
Harden your store and watch the score climb
Beyond exposures, Security Scan audits the configuration that keeps a shop safe: forced SSL everywhere, secure cookie flags, admin-folder protection, CSRF token, brute-force lockout, plus stale modules and recently-created admin accounts. Re-run it after every PrestaShop or module update and watch your grade improve — the History page tracks your score over time so security becomes something you can actually measure.


Check any store by URL — before you even install
Not ready to install yet? Our free public PrestaShop Security Scanner passively fingerprints any store you own straight from its address — PrestaShop and PHP version, end-of-life risk and HTTPS security headers — in seconds, with nothing to set up. It reads only what any visitor already sees, so it is safe and lawful. It is the fastest way to see where a store stands; the installed module then does the deep, private audit of your files, modules and permissions.
From detection to protection
Security Scan finds and explains; when you want to act, Security Revolution applies one-click fixes, hardens your store, monitors core-file integrity, alerts you the moment something changes and manages a whole fleet of stores from one dashboard. Same findings — it just acts on them and keeps watching. Start free here, upgrade when you are ready.
New to security audits? Follow the step-by-step PrestaShop self-audit guide.
-
Referencemprsecurityscan
-
In stock2147483647 Items
-
PrestaShop CompatibilityPS 1.7 – 9.x
-
Pricing ModelFree
-
Module TypeBack-office
-
GDPR RelevantNo
-
Business GoalLegal & Compliance
-
External Account NeededNo
-
Module ComplexityLightweight Widget
-
Customer Journey StageManage Store
-
Works With PlatformNo External Platform
What customers say about us
Be the first to share your experience with this module.
Write a Review
Security Scan
Free, open-source local security scanner for PrestaShop. Security Scan runs inside the merchant's own shop, reads local PrestaShop/module/PHP state, and produces a private report with a 0-100 score, a letter grade, and manual fix steps.
It is detection-only. It does not block traffic, patch files, change settings, remove malware, or send findings to mypresta.rocks.
- Addedthe signed Security Fleet connector used by explicit, consent-based fleet workflows.
- Hardened the scan runner's read-only database guard so local checks cannot execute write SQL.
- ImprovedBack Office report persistence and history data for repeated scan comparisons.
Works Well With Security Scan
Modules our team genuinely pairs with this one — and exactly why each belongs in the same setup.
One of the things Security Scan flags in its hardening checks is stale and inactive modules — leftover code that widens your attack surface even when it is switched off. The scan tells you they are there; it does not remove anything.
Cleanup Revolution is the tool that acts on that finding. It helps you safely remove unused modules, orphaned data and leftover files, shrinking exactly the kind of dormant code and exposed leftovers the scanner warns about.
Pairing them is a simple hygiene routine: scan to see which stale components and leftovers are raising your risk, then use Cleanup Revolution to clear them out, and re-scan to confirm the score improves. Less unused code means fewer places for a vulnerability to hide.
The free Security Scan is an automated triage tool. Its version/CVE, exposed-file, malware and hardening checks are honest heuristics — useful signals, but the report itself notes that serious findings should be reviewed by a person before you act.
The PrestaShop Security Audit & Hardening Report is that human review. A specialist takes the same kind of evidence the scanner collects, verifies which findings are real, rules out false positives in the static and malware heuristics, and writes up a prioritised hardening plan specific to your shop.
Use the scanner to see where you stand today at no cost, then bring in the expert audit when a finding is ambiguous, when you suspect a compromise, or when you want a second opinion before changing production files.
Security Scan is detection-only: it reads your shop's local state and produces a private report with a 0–100 score, a letter grade and prioritised findings, but it deliberately does not change anything. It shows you what is wrong and how to fix each item by hand.
Security Revolution is the remediation side of the same workflow. Where the free scan lists an exposed file, an end-of-life branch or a weak hardening setting, Security Revolution applies the guided one-click fixes and ongoing monitoring so the issues the scan surfaces actually get closed and stay closed.
Running them together gives you the full loop: the scanner finds and grades the risk for free, and Security Revolution turns that to-do list into fixes and continuous protection. It is the natural upgrade path once the scan has shown you where your shop stands.
Loading feature requests...
Easy return - no questions asked
Install, set up and take profit
Priority Help & Satisfaction Over Sales