Total Difensore

Suite di sicurezza completa con firewall, scanner e protezione accesso

Price: 199,00 €
Tasse incluse

Protezione Completa di Sicurezza e Anti-Spam per PrestaShop

Total Defender è una suite di sicurezza a spettro completo che protegge il tuo negozio PrestaShop da spam, bot, attacchi brute-force, malware e vulnerabilità. Combina limitazione della frequenza, gestione IP, monitoraggio dell'integrità dei file, firewall per applicazioni web, sicurezza email, gestione backup e 2FA amministrativa in un unico modulo — nessun servizio esterno richiesto.

  • Protezione Anti-Spam — campi honeypot, integrazione CAPTCHA, filtraggio messaggi e validazione link per bloccare lo spam
  • Limitazione della Frequenza — throttling per azione su carrello, registrazione, moduli di contatto e commenti con blocco automatico degli IP
  • Gestione Bot e Crawler — rilevamento comportamentale, sfide JS e whitelist dei crawler per separare i bot buoni da quelli malevoli
  • Gestione IP — whitelist, blacklist, punteggio di penalità, rilevamento nodi di uscita TOR e regole basate su GeoIP
  • Monitoraggio Integrità dei File — snapshot di riferimento con avvisi quando i file del core o dei moduli vengono modificati inaspettatamente
  • Firewall per Applicazioni Web — regole personalizzate per bloccare XSS, SQL injection e altri attacchi basati sull'input
  • Scanner di Vulnerabilità — verifica il core di PrestaShop, i moduli e la versione PHP rispetto ai CVE noti
  • Header di Sicurezza — generazione CSP e registrazione delle violazioni per rafforzare la sicurezza lato browser
  • Sicurezza Email — limitazione delle email in uscita, blocco dei domini usa e getta e rilevamento dei pattern di abuso
  • Sistema di Backup — backup completi e incrementali con pianificazione, adattatori di archiviazione multipli e punti di ripristino
  • 2FA Amministrativa — autenticazione a due fattori basata su TOTP per gli account dei dipendenti del back office
  • Tracciamento Sessioni — monitora le sessioni dei visitatori con attribuzione, pagine visualizzate, parametri UTM e rilevamento dispositivo
  • Registro di Audit — cronologia completa delle azioni di amministrazione con indirizzi IP, user agent e timestamp

Compatibile con PrestaShop 1.7 fino a 9.x. Una licenza, aggiornamenti a vita, 90 giorni di supporto dedicato.

Product availability: Download immediato dopo l'acquisto
Condividi
3 viewed
2 watching now

Complete Security — From Spam to Sophisticated Attacks

E-commerce stores face a constant barrage of threats. Automated bots submit hundreds of spam registrations per day. Credential-stuffing attacks target admin and customer logins around the clock. Malicious scripts probe for known vulnerabilities in PrestaShop core and modules. A single breach can expose customer payment data, destroy trust, and trigger regulatory penalties under GDPR.

Total Defender is a full-spectrum security suite that protects your store at every layer. Anti-spam stops form abuse. Rate limiting prevents brute-force attacks. A web application firewall blocks injection attacks. File integrity monitoring catches unauthorized code changes. Vulnerability scanning alerts you to known CVEs. Admin two-factor authentication ensures that stolen passwords alone cannot compromise your back office. And a comprehensive audit log gives you forensic visibility into every action.

Anti-Spam Protection

Spam is the most common and most visible attack vector. Fake registrations pollute your customer database, spam contact form messages waste support time, and fake reviews damage your store's credibility. Total Defender blocks spam at the source.

  • Honeypot fields — invisible form fields that catch automated bots without affecting real customers
  • CAPTCHA integration — support for reCAPTCHA v2, v3, and hCaptcha on registration, contact, and comment forms
  • Message filtering — keyword-based filtering to block messages containing spam patterns, excessive links, or prohibited terms
  • Link validation — detect and block form submissions containing suspicious URLs or redirect chains
  • Disposable email blocking — reject registrations from known disposable email providers

Rate Limiting & Brute-Force Protection

  • Per-action throttling — separate rate limits for cart additions, registration, contact form submissions, login attempts, and comments
  • Automatic IP blocking — IPs that exceed rate limits are automatically blocked for a configurable duration
  • Progressive lockout — repeat offenders face escalating block durations (1 hour → 24 hours → permanent)
  • Admin login protection — separate, stricter rate limits for back-office login attempts
  • API rate limiting — throttle webservice API requests to prevent abuse and resource exhaustion

Bot & Crawler Management

  • Behavioral detection — identify bots by browsing patterns (speed, mouse movement, JavaScript execution) rather than just user-agent strings
  • JavaScript challenges — serve lightweight JS challenges to suspicious visitors that real browsers pass instantly but headless bots fail
  • Crawler whitelisting — ensure Google, Bing, and other legitimate crawlers are never accidentally blocked
  • TOR exit node detection — identify and optionally block connections from TOR exit nodes
  • User-agent filtering — block known malicious bot user-agents and tools

IP Management & GeoIP

  • IP whitelist — ensure your own IPs and trusted partners are never blocked
  • IP blacklist — permanently block specific IPs or CIDR ranges
  • Penalty scoring — accumulate risk scores based on suspicious behavior before triggering a block
  • GeoIP-based rules — allow or block access from specific countries or regions
  • Admin panel restriction — limit back-office access to specific IP addresses or ranges

File Integrity Monitoring

  • Baseline snapshots — SHA-256 hash of every monitored file stored as a reference point
  • Change detection — identify files that have been added, modified, or removed since the last baseline
  • Scheduled scans — automatic integrity checks via cron (hourly, daily, or weekly)
  • Exclusion rules — exclude cache, log, and other expected-change directories
  • Email alerts — immediate notification when unauthorized modifications are detected
  • Diff viewer — side-by-side comparison showing exactly what changed in modified files

Web Application Firewall & Security Headers

  • XSS protection — detect and block cross-site scripting attempts in form inputs and URL parameters
  • SQL injection blocking — pattern-based detection of SQL injection payloads in requests
  • Custom firewall rules — define your own rules to block specific request patterns
  • Content Security Policy (CSP) — visual builder for CSP headers with violation logging
  • HSTS, X-Frame-Options, Referrer-Policy — configure all security headers from the admin panel
  • Permissions-Policy — restrict browser API access (camera, microphone, geolocation) on your pages

Vulnerability Scanner

  • PrestaShop core CVE check — compare your installed version against known vulnerabilities
  • Module vulnerability scanning — check installed modules against known CVE databases
  • PHP version check — verify your PHP version is not end-of-life or known-vulnerable
  • Severity ratings — each finding includes a severity level (critical, high, medium, low) and remediation advice
  • Scheduled scanning — run vulnerability checks on a regular schedule with email alerts for new findings

Admin 2FA, Backup & Audit

  • TOTP two-factor authentication — compatible with Google Authenticator, Authy, and any TOTP app
  • Per-employee enforcement — require 2FA for all employees or specific profiles
  • Recovery codes — single-use backup codes for employees who lose their 2FA device
  • Backup system — full and incremental backups with scheduling and multiple storage adapters
  • Session tracking — monitor active visitor sessions with device, IP, and UTM attribution
  • Complete audit log — every admin action recorded with IP, user agent, and timestamp
  • Email rate limiting — prevent outbound email abuse from compromised forms

Why is this module unique?

  • The most comprehensive PrestaShop security module available — combines anti-spam, rate limiting, WAF, file integrity, vulnerability scanning, 2FA, backups, and audit logging in a single package
  • No external services required — everything runs on your own server with no monthly fees, API dependencies, or data leaving your infrastructure
  • Behavioral bot detection with JavaScript challenges catches sophisticated bots that user-agent filtering misses
  • Penalty scoring system reduces false positives by accumulating risk before blocking, rather than blocking on a single suspicious action
  • CSP header visual builder eliminates the notoriously difficult process of writing Content Security Policy rules by hand

Use Cases

  • Stores processing payments — PCI DSS compliance requires file integrity monitoring, access controls, and strong authentication
  • Stores handling personal data — GDPR requires audit trails of data access and modification
  • Stores targeted by spam — anti-spam and rate limiting eliminate automated form abuse
  • Stores with multiple admin users — 2FA and audit logging ensure accountability across the team
  • Stores previously compromised — file integrity monitoring and vulnerability scanning provide ongoing assurance after a breach cleanup
  • High-traffic stores — rate limiting and bot management prevent resource exhaustion from automated traffic
  • Riferimento
    mprtotaldefender
  • In magazzino
    999 Articoli
  • Compatibilita PrestaShop
    PS 1.7 – 9.x
  • Modello di prezzo
    Acquisto singolo
  • Tipo di modulo
    Front & Back-office
  • Rilevante per GDPR
    Si
  • Obiettivo di business
    Ottimizzare le operazioni
  • Account esterno necessario
    No
  • Complessita del modulo
    Soluzione completa
  • Fase del percorso cliente
    Gestire il negozio
  • Funziona con piattaforma
    Nessuna piattaforma esterna
0.0
0 reviews
5 ★
0
4 ★
0
3 ★
0
2 ★
0
1 ★
0

No reviews yet. Be the first to leave a review!

Write a Review

Rate specific aspects (optional)
Qualita
Rapporto qualita-prezzo
Stabilita
Compatibilita
Supporto
Reso entro 30 giorni
Reso semplice - senza domande
Moduli Plug & Play
Installa, configura e guadagna
Supporto al primo posto
Priorita ad aiuto e soddisfazione

Altro da questa categoria

  • Nuovo
Vetrina clienti
149,00 €
Caricamento in corso ...
Torna all'inizio