Free · Passive check · No signup

Free PrestaShop Security Scanner

Check any store you own in seconds — no install, no signup.

Enter your store address and we instantly fingerprint your PrestaShop and PHP versions, flag end-of-life risk, and check your HTTPS security headers. It reads only what any visitor already sees — for the deep, private scan of your modules, files and permissions, install the free module and run it from inside your own store.

This public check only reads your homepage and visible headers — it does not probe files or test for vulnerabilities. It is not a penetration test.

What the public check looks at

Four fast, passive signals any visitor could see — read from your homepage and its response headers.

PrestaShop & PHP fingerprint

Confirms the store runs PrestaShop and, if the version is publicly exposed, which one — so you know exactly which security advisories apply to you.

End-of-life warning

Flags PrestaShop branches that no longer receive upstream security maintenance — the single biggest risk for older stores.

HTTPS & redirects

Checks that the storefront is served over HTTPS and follows a clean redirect chain, so customer data travels encrypted.

Security headers

Looks for HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy — the browser-level defences that block clickjacking, script injection and data leaks.

Why this scan is passive — on purpose

We only read what any visitor already sees. Probing a stranger's files, backups, admin folder or config without consent isn't a scan — it's an attack, and in most countries it's illegal. So we don't do it, and neither should a tool that scans a URL you just typed in.

The deep checks — module-by-module vulnerability matching, exposed .git or backups, malware and web-shell detection, file permissions and hardening — need to run from inside the shop, where it is your store and consent is built in. That is exactly what the free module does. The public check stays honest and safe; the real audit happens where you have the right to run it.

Public check vs. the private deep scan

The public check sees only what any visitor can. The free module, installed in your shop, sees everything from the inside — where the risks that actually get stores hacked really live.

Public URL check

  • PrestaShop & PHP version fingerprint
  • End-of-life version warning
  • HTTPS & security-header check
  • Module-level vulnerability matching
  • Exposed .git / backups / config files
  • Malware & web-shell detection
  • File-permission & hardening audit

Everything below the line needs inside access — the free module does it.

Installed module scan Free

  • PrestaShop & PHP version fingerprint
  • End-of-life version warning
  • HTTPS & security-header check
  • Every installed module matched to advisories
  • Exposed .git / backups / config files
  • Malware & web-shell heuristics
  • File-permission & hardening audit + 0–100 score
Get the free module

What you get after installing

A single 0–100 security score with a letter grade, every finding grouped by severity, and plain-language fix steps you can follow yourself. Re-run it after each update to watch your score climb.

Get the free module
The Security Scan report: a 0-100 score with letter grade, severity chips and findings with fix steps

Common findings and what they mean

End-of-life PrestaShop

You're on a branch that no longer gets security patches. Every new PrestaShop CVE stays open on your store. Plan an upgrade to a supported version.

Publicly exposed version

Your exact version is visible in the page source. That hands attackers a shortlist of known exploits to try. Hide it where your theme allows.

Missing HSTS

Without Strict-Transport-Security, browsers may still attempt insecure HTTP first — a window for downgrade and interception attacks.

No Content-Security-Policy

A CSP is one of the strongest defences against injected scripts and card-skimming malware. Its absence means less protection if something slips in.

Your privacy

To prevent abuse we keep a short-lived record — your IP address stored only as a one-way hash, plus the domain you checked — for up to two hours, then it is deleted automatically. We never publish, sell, share, or build a public database of scanned sites, and we never post "site X is vulnerable" anywhere. The scan result is shown to you and to no one else.

Frequently asked questions

Is it safe to run this scan on my store?

Yes. It only requests your public homepage and reads the response headers — exactly like a normal visitor. It never logs in, never submits forms, and never touches your files.

Do you store the URL I scan?

Only briefly, to stop abuse: your IP as a one-way hash plus the domain, kept up to two hours then deleted. We never publish or share scanned sites.

Why can't the public check see my modules or vulnerabilities?

Those live inside your shop. Reading them from outside without permission would be unauthorized testing. The free module runs the deep checks from inside, where it is your store and consent is built in.

Is this a penetration test?

No. It is a fast, passive fingerprint — a useful first look, not a security audit or a pentest. Deep audits and live incidents still need a human.

My version wasn't detected — is that bad?

No, it's usually good. We only report a version when a store publicly exposes it. A well-configured store hides it, so "not detected" often means you are doing the right thing.

Built and maintained by mypresta.rocks. Our advisory data is seeded from the Friends of Presta security cell and curated for PrestaShop 1.6–9. We build the PrestaShop security modules used across production stores.

Guide: how to self-audit with the installed free module · PrestaShop hardening checklist · Automatic fixes & monitoring: Security Revolution

Loading...
Back to top