Security Scan is a free module for PrestaShop stores that answers the question every merchant eventually asks: is my shop safe? It scans the store from the inside, entirely locally, and returns a security score, a grade and a prioritised list of findings. Setup is installing it and pressing one button.
It settles the uncertainty that follows every headline about hacked shops and skimmed cards. Instead of a feeling, you get evidence: which risks exist in your shop, how severe each one is, and what to do about each, before a stranger finds them first.
One scan covers five areas: known vulnerabilities in your PrestaShop version and installed modules, exposed files such as backup archives, database dumps and leftover install folders, malware indicators including web shells, hidden code in media folders and files changed where no change belongs, risky code patterns in modules, and hardening posture from secure cookies to debug settings and abandoned modules.
Every finding arrives as a card with its severity, what was found, why it matters and ordered manual fix steps, so the report ends in actions rather than anxiety. The score and grade make progress measurable, history keeps every scan, scheduled scans repeat the check on their own, and an alert reaches you when a new critical finding appears. Nothing is ever uploaded anywhere: the scan runs inside your shop and the findings stay yours, with the source open to read.
You learn the truth about your shop's exposure in minutes and for nothing, the fixes come with instructions, progress becomes a number, and agencies connect many shops to one fleet view through the consented connector, where Security Revolution takes over prevention.
Summary of what the module offers
Security Scan is a free, local, read-only security examination of a PrestaShop store with a clear verdict. The map below covers the six sections.
- Five check areas: vulnerabilities, exposed files, malware indicators, risky code, hardening
- A 0-100 score with an A-F grade and severity totals
- Finding cards with manual fix steps for every issue
- Complete privacy: nothing leaves the shop, source open to read
- History, scheduled scans and a critical-finding alert
- An optional consented fleet view for agencies and multiple shops

What exactly does the scan check?
Five areas in one pass. Known vulnerabilities: your PrestaShop version and its end-of-life status, the risk of an outdated server platform, and every installed module compared against curated advisory data. Exposure: public version-control folders, backup archives, database dumps, leftover install directories, diagnostic files and directory listing.
Then malware indicators, web shells, hidden loaders, code where only images should live; risky code patterns inside modules; and hardening posture, from secure cookies and admin protection signals to debug settings and abandoned module code that still sits reachable on disk.

What does a finding look like?
A card, not a codeword. Each finding states its severity, what was found and where, why it matters in plain terms, and the ordered steps to fix it manually. An exposed dump names the file; a vulnerable module names the module and version.
The report is triage you can act on the same afternoon, alone or handed to whoever maintains the shop.

Does any of my data leave the shop?
No. The scan runs entirely inside your shop, reads local state, and sends nothing to any third party, including us. The findings are private to you, and the module's source is open to read, so the privacy claim is verifiable rather than promised.
The module is also honest about its role: it detects and explains, and it deliberately does not block traffic, patch files or change settings behind your back.

How do I stay safe after the first scan?
Every scan is stored, so the score becomes a line over time and security work becomes visible progress. Scheduled scans repeat the examination on their own, and when a new critical finding appears, an alert reaches you instead of waiting to be discovered.
Re-scanning after each fix confirms it worked, and after each shop change confirms nothing new opened.

What about agencies and more than one shop?
An optional connector, enrolled explicitly and signed, reports scans to one central fleet dashboard and accepts remote scan triggering over the consented channel. Ten client shops become one screen.
For prevention beyond detection, the paid Security Revolution suite takes over from the same fleet view: the scanner finds, the suite defends.

-
Referencemprsecurityscan
-
In stock2147483647 Items
-
PrestaShop CompatibilityPS 1.7 – 9.x
-
Pricing ModelFree
-
Module TypeBack-office
-
GDPR RelevantNo
-
Business GoalLegal & Compliance
-
External Account NeededNo
-
Module ComplexityLightweight Widget
-
Customer Journey StageManage Store
-
Works With PlatformNo External Platform
What customers say about us
Be the first to share your experience with this module.
Write a Review
Free, open-source local security scanner for PrestaShop. Security Scan runs inside the merchant's own shop, reads local PrestaShop/module/PHP state, and produces a private report with a 0-100 score, a letter grade, and manual fix steps.
It is detection-only. It does not block traffic, patch files, change settings, remove malware, or send findings to mypresta.rocks.
- Addedthe signed Security Fleet connector used by explicit, consent-based fleet workflows.
- Hardened the scan runner's read-only database guard so local checks cannot execute write SQL.
- ImprovedBack Office report persistence and history data for repeated scan comparisons.
Works Well With Security Scan
Modules our team genuinely pairs with this one, and exactly why each belongs in the same setup.
One of the things Security Scan flags in its hardening checks is stale and inactive modules, leftover code that widens your attack surface even when it is switched off. The scan tells you they are there; it does not remove anything.
Cleanup Revolution is the tool that acts on that finding. It helps you safely remove unused modules, orphaned data and leftover files, shrinking exactly the kind of dormant code and exposed leftovers the scanner warns about.
Pairing them is a simple hygiene routine: scan to see which stale components and leftovers are raising your risk, then use Cleanup Revolution to clear them out, and re-scan to confirm the score improves. Less unused code means fewer places for a vulnerability to hide.
The free Security Scan is an automated triage tool. Its version/CVE, exposed-file, malware and hardening checks are honest heuristics, useful signals, but the report itself notes that serious findings should be reviewed by a person before you act.
The PrestaShop Security Audit & Hardening Report is that human review. A specialist takes the same kind of evidence the scanner collects, verifies which findings are real, rules out false positives in the static and malware heuristics, and writes up a prioritised hardening plan specific to your shop.
Use the scanner to see where you stand today at no cost, then bring in the expert audit when a finding is ambiguous, when you suspect a compromise, or when you want a second opinion before changing production files.
Security Scan is detection-only: it reads your shop's local state and produces a private report with a 0–100 score, a letter grade and prioritised findings, but it deliberately does not change anything. It shows you what is wrong and how to fix each item by hand.
Security Revolution is the remediation side of the same workflow. Where the free scan lists an exposed file, an end-of-life branch or a weak hardening setting, Security Revolution applies the guided one-click fixes and ongoing monitoring so the issues the scan surfaces actually get closed and stay closed.
Running them together gives you the full loop: the scanner finds and grades the risk for free, and Security Revolution turns that to-do list into fixes and continuous protection. It is the natural upgrade path once the scan has shown you where your shop stands.
Loading feature requests...
Easy return - no questions asked
Install, set up and take profit
Priority Help & Satisfaction Over Sales