Security Audit Pro – Protect Your Store Against AI-Powered Attacks - Module PrestaShop

+290 downloads 4.99 / 5 1.7.X 8.X 9.X 5 languages 🇬🇧 EN 🇫🇷 FR 🇮🇹 IT 🇪🇸 ES 🇵🇱 PL

Security Audit Pro helps merchants and agencies review store security across eight categories. Run a resumable audit, distinguish confirmed issues from points to investigate and track your corrections.

Inspect evidence, compare reports and export JSON or text for your developer or AI assistant. The module does not block attacks or apply automatic fixes.

Features

Everything you need, nothing you don't.

Targeted checks, evidence to review and a history to track corrections to your store.

Resumable audits

Pause an audit, resume after interruption or cancel it.

Findings with evidence

Each finding includes a status, scope, explanation, available evidence and a recommendation where action is useful.

Export for a developer or AI

The text report brings together findings, available evidence and recommendations.

Eight check categories

Headers, files, administration, modules, WebService, SQL code, XSS/CSRF and permissions: targeted coverage with explicit limits.

History and correction tracking

Find dated audits, open reports when needed and compare new, persistent, resolved or unverified findings.

PrestaShop 1.7.8, 8 and 9

Use PrestaShop 1.7.8, 8 or 9 with a PHP version supported by your store. Open the module through Module Manager.

Customer reviews

They use it every day.

5 out of 5 · 4.99 reviews

"J'ai lance l'audit et en 2 minutes j'avais un rapport complet. Plusieurs failles corrigees le jour meme grace aux instructions."

LM Lucas M.

"Fantastico! Ho scoperto che il mio back-office era accessibile senza protezione. Corretto subito grazie alle istruzioni dettagliate."

MR Marco R.

"Ran the audit on our store and found 12 vulnerabilities we had no idea about. The AI-assisted fix feature saved us hours of work."

SK Sarah K.

"Muy completo, detecta cosas que otros modulos de seguridad no ven. Las instrucciones paso a paso son claras y faciles de seguir."

EG Elena G.

"Swietny modul! Wykryl podatnosci w naglowkach HTTP i plikach konfiguracyjnych. Naprawilem wszystko w jeden wieczor."

TW Tomasz W.

"Le score de A a F est tres parlant. On est passe de D a A en une apres-midi. Indispensable pour tout marchand serieux."

SD Sophie D.

"Works perfectly on PrestaShop 9. Found SQL injection risks and exposed config files. Great value for the price."

JT James T.
description Full description expand_more

Security auditing for PrestaShop: understand findings and track corrections

Configuration mistakes, exposed files and vulnerable modules deserve investigation before an incident occurs. Security Audit Pro brings PrestaShop security checks into your back office: HTTP headers, files, administration, modules, WebService, SQL-related code, XSS/CSRF and permissions.

The audit helps you decide what to correct and what needs further investigation. It does not replace a professional penetration test or provide a firewall or protection specific to an attack technology.

How It Works — 3 Steps

Step 1 — Audit: find Security Audit in Modules → Module Manager, click Configure, then Start audit. Pause and resume after reloading; an interruption retains the steps already saved.

Step 2 — Review: filter findings by status, category or search. Step 3 — Follow up: have the recommendations reviewed, recheck a specific finding and compare two reports to track changes.

Export for your developer or AI assistant

The text report brings together findings, available evidence and recommendations. Share it with your developer or AI assistant to prepare suitable corrections; JSON export supports structured analysis.

The module does not apply fixes. A code suspicion needs confirmation before changes are made; have proposed changes reviewed and tested. New reports exclude raw cookie values and secrets identified by the redaction process.

Detailed reports: findings, evidence and recommendations

Each finding includes a status, scope, explanation, available evidence and a recommendation where action is useful. Confirmed issues, suspicions, unverified checks and errors are distinguished from passed checks.

A file path, header or affected module helps direct the investigation. Filters replace the eight old tabs, and details open on demand. Explanations help merchants prioritise; they do not guarantee that a technical fix can be completed without assistance.

Open a finding to inspect evidence, read the recommendation and recheck that point.
Open a finding to inspect evidence, read the recommendation and recheck that point.

Section 1 — HTTP Headers & Server Configuration

Your server's HTTP headers are the first line of defense. Missing or misconfigured headers leave your store exposed to clickjacking, XSS attacks, MIME sniffing, and data leakage.

Review HSTS, CSP, framing protection, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. Reports also identify disclosed server versions and certain cookie attributes.

When a usable HTTPS response is available, the check verifies the certificate and its expiry. CORS observed on a public page provides limited evidence and does not validate every endpoint on the site.

Section 2 — Sensitive Files & Directories

One of the most common and devastating attack vectors: files that should never be publicly accessible. A single exposed .env file can hand your entire database credentials to an attacker.

The module checks a bounded list of sensitive paths, including .env files, Git metadata, PrestaShop configuration, Composer files, common backups and logs. It also looks for directory-listing indicators.

An HTTP200 response to a file probe is a suspicion to confirm, not proof that its contents are exposed. Unavailable or ambiguous responses remain unverified.

Section 3 — Back-Office Security

Review the administration folder name, relevant employee accounts, certain login dates and stored password formats. A missing or invalid login date does not establish that an account is inactive.

Detected protection modules are only indicators; their effectiveness still needs investigation. The module does not attempt brute-force logins or certify back-office protection.

Section 4 — Module Security

Compare core and module versions with the security advisories included in the bundled catalogue, with sources and a review date. Identify unregistered module directories and certain entry points that need inspection.

The catalogue covers an explicit selection of advisories. No match does not prove a module is safe. Audit requests do not call module entry points that could modify data.

Section 5 — WebService API Audit

Check WebService activation, HTTPS usage and the anonymous response from /api/. The module reviews the length and character diversity of active store keys and certain sensitive write permissions.

Reports contain counts and observations without exporting key values. Anonymous-access indicators or broad rights require contextual investigation; customer resources are not extracted to demonstrate an intrusion.

Section 6 — SQL injection indicators and code analysis

A limited search request checks for SQL error disclosure. Bounded reading of PHP files in modules and overrides identifies certain calls and patterns for investigation without executing the analysed code.

Static indicators are suspicions, not confirmed exploitable injections. File depth, count and size are limited, and reaching a limit remains visible in the report.

Section 7 — XSS and CSRF checks

Cross-Site Scripting (XSS) allows attackers to inject malicious scripts into your pages, stealing customer cookies, session tokens, and personal data. Cross-Site Request Forgery (CSRF) tricks authenticated users into performing unwanted actions.

A search probe uses an inert HTML marker to identify reflection that needs review. No executable script is sent. CSP is included in the header observations.

A token field on the contact form does not prove server-side validation. The CSRF check remains unverified and calls for further investigation.

Section 8 — Permissions & Access Control

Review certain configuration-file permissions, the presence of Apache rules in upload directories and a redirect response without following the external destination.

An .htaccess file does not prove that PHP execution is blocked by the server. The module does not try to access other customers’ orders or certify object-ownership checks (IDOR).

An A–F score when the checks support it

Counters highlight critical findings, warnings and verified checks. An overall grade is calculated only for a finished audit whose applicable checks are verified; otherwise it is withheld with an explanation.

A critical finding caps a calculable score. Neither a high grade nor a passed check guarantees overall security; coverage and evidence remain essential to interpretation.

Dashboard, History & Comparison

Find dated audits, open reports when needed and compare new, persistent, resolved or unverified findings. A missing check is not automatically treated as a confirmed correction.

Pause, resume and cancel to stay in control. After a module update or technical intervention, recheck the relevant finding and follow changes in the history.

Follow progress and distinguish findings from checks that still need verification.
Follow progress and distinguish findings from checks that still need verification.

Bounded checks without automatic store changes

Checks read the audited files and settings without automatically correcting them. The module saves its own reports and progress. HTTP requests are bounded, stay on the configured store and do not follow redirects.

The module adds no script to the storefront. Auditing still consumes resources while running; duration depends on the store and hosting. You can pause or cancel it.

Per-store history in multistore

Select a store to view and run its audits. New reports and comparisons are separated by store; findings about shared files are identified as shared.

Old archives without a reliable store association are reserved for the superadministrator and excluded from comparisons. Employee permissions remain enforced for viewing, auditing and deletion.

Compatibility and operation

Access the module through Configure in Module Manager, without an extra sidebar entry. The interface and reports are available in French, English, Spanish, Italian and Polish.

PrestaShop 1.7.8, 8 and 9; PHP 7.4 minimum, using a version compatible with your PrestaShop release. Required extensions: JSON, PDO, mbstring, cURL and OpenSSL. The local interface uses no remote library and requires no compilation by the merchant.

Who Is This Module For?

For merchants who want to understand findings before involving their developer; agencies following several stores; and developers who need to inspect file indicators and compare results after a correction.

Specialist auditing is still needed to confirm suspicions and examine protections that cannot be validated automatically.

Read the security-audit and correction-tracking guide

Comparaison

Why choose us?

See how we compare to the most common alternatives on the market.

Feature Addons
Transparent pricing
Lifetime updates included
Direct developer support
PS 1.7, 8 & 9 compatible
Standardized clean code
Multi-store ready
No hidden renewal fees
Included Not included Partial / Not guaranteed
Preview

Discover the module in images.

PrestaShop security audit: findings and correction tracking

PrestaShop security audit: findings and correction tracking

Follow progress and distinguish findings from checks that still need verification.

Follow progress and distinguish findings from checks that still need verification.

Open a finding to inspect evidence, read the recommendation and recheck that point.

Open a finding to inspect evidence, read the recommendation and recheck that point.

Support

FAQ

Find answers to frequently asked questions about this module

After installing a module, review known advisories and file indicators. After an intervention, recheck the relevant finding. Agencies can keep reports per store and share useful observations with their technical team. Eight categories organise the findings; they do not mean exhaustive coverage of every attack.

Configuration mistakes, exposed files and vulnerable modules deserve investigation before an incident occurs. Security Audit Pro brings PrestaShop security checks into your back office: HTTP headers, files, administration, modules, WebService, SQL-related code, XSS/CSRF and permissions. The audit helps you decide what to correct and what needs further investigation. It does not replace a professional penetration test or provide a firewall or protection specific to an attack technology.

A scan identifies settings, responses and indicators; a penetration test seeks to confirm exploitability within an agreed scope. Security Audit Pro provides targeted diagnostics and does not replace a professional penetration test. Suspicions need human review.

A limited search request checks for SQL error disclosure. Bounded reading of PHP files in modules and overrides identifies certain calls and patterns for investigation without executing the analysed code. Static indicators are suspicions, not confirmed exploitable injections. File depth, count and size are limited, and reaching a limit remains visible in the report. A search probe uses an inert HTML marker to identify reflection that needs review. No executable script is sent. CSP is included in the header observations. A token field on the contact form does not prove server-side validation. The CSRF check remains unverified and calls for further investigation.

Compare core and module versions with the security advisories included in the bundled catalogue, with sources and a review date. Identify unregistered module directories and certain entry points that need inspection. The catalogue covers an explicit selection of advisories. No match does not prove a module is safe. Audit requests do not call module entry points that could modify data.

Checks read the audited files and settings without automatically correcting them. The module saves its own reports and progress. HTTP requests are bounded, stay on the configured store and do not follow redirects. The module adds no script to the storefront. Auditing still consumes resources while running; duration depends on the store and hosting. You can pause or cancel it.

Review the administration folder name, relevant employee accounts, certain login dates and stored password formats. A missing or invalid login date does not establish that an account is inactive. Detected protection modules are only indicators; their effectiveness still needs investigation. The module does not attempt brute-force logins or certify back-office protection.

The text report brings together findings, available evidence and recommendations. Share it with your developer or AI assistant to prepare suitable corrections; JSON export supports structured analysis. The module does not apply fixes. A code suspicion needs confirmation before changes are made; have proposed changes reviewed and tested. New reports exclude raw cookie values and secrets identified by the redaction process.

Join +290 merchants using this module

5-minute installation · Full documentation included

inventory_2 Module 10.70 € 4.28 € one-time -60%
Choose your license
3 months of support for 0.99€ · then 1.99€/month
  • Response within 24 business hours
  • 🔧 Installation & configuration assistance
  • 💬 Direct contact with the developer
No commitment · Cancel in 1 click from your account
Instead of --€/year if purchased separately
Loading...