The key improvements we ship to keep your store protected.
Last updated: 9 June 2026
As soon as a file is flagged, our system studies it in depth. You now see in your dashboard which way that analysis leans, likely false alarm or real threat, along with its confidence level, without waiting for us to step in behind the scenes. So you know right away what deserves your attention.
Some merchants also run a WordPress inside their PrestaShop store. It is not advisable, but it happens, and its core sometimes set off alerts by mistake. The same went for the test libraries shipped with certain modules and for compressed JavaScript files. The scanner now recognises these ordinary components and sets them aside, without easing off on the files that genuinely carry risk. Your scan reports become easier to read.
Some attackers graft an invisible script onto your back-office login page to capture your username and password every time you sign in, then reinstall themselves after a simple password change. That is how they keep coming back day after day. We now spot this kind of graft: a script quietly loaded into the admin and a hidden browser marker, even when the attacker renames the files to cover their tracks. Found on a real store, this trap used to go unnoticed and now triggers a critical alert.
On stores with a very large number of files, or with heavy activity logs, the analysis could stop midway because it ran out of memory. It now keeps its usage in check as it goes and runs all the way through, whatever the size of the site.
We hardened detection of card skimmers (Magecart-style) that hide their collection address in encoded form inside a script or a fake image, as well as loaders that run a backdoor downloaded from an external server, even when the code is deliberately disguised. Spotted on real stores, these patterns now surface as a critical alert instead of slipping under the radar.
We now hunt down backdoors that camouflage themselves, by disguising their code (for instance playing with letter case to fool antiviruses) or by reinstalling on their own through a file downloaded from outside. Found on real stores, often hidden inside pirated modules, these traps used to stay "quiet": they now trigger a critical alert.
No more abrupt “Access denied” page. After repeated attempts, the customer sees the store's usual login form with a clear message: too many attempts, remaining wait time and a direct link to reset their password. The threshold has been relaxed so a customer who simply mistypes their password isn't penalised, while automated attacks are still blocked instantly.
View the content of a flagged file, or its comparison with the official PrestaShop version, straight from your PrestaSecure dashboard, no SSH or FTP needed. Read-only access, strictly limited to your store and to safe file types.
The scanner now inspects the configuration and the editorial content displayed on your store, not just the files. This closes a blind spot exploited by some attackers to inject a card-skimming script outside the site's files, a vector seen in a real customer incident.
Catalogues of several million files, multistore: the scan now analyses the entire estate, with no truncation or memory overflow, chaining several automatic passes if needed. No part of the site is left out.
Recurring scans now only analyse the files actually modified since the last run, instead of re-scanning everything. The time saving is considerable on large stores, with no loss of coverage: a single changed byte is still detected.
The report builds before your eyes: threats appear as the scan progresses, with their severity and grouping, instead of waiting until the very end.
The module scans your store's PHP error log for known attack signatures (template injection, attempts to read sensitive configuration files, remote file inclusion, etc.). Attackers often leave months of failed attempts before succeeding: you're alerted from the very first signals.
No folder is skipped during the scan anymore (dependencies, themes, back office, upload folders, etc.). Malicious code can hide anywhere, including in a dependency or a webshell dropped into the admin. The analysis now covers the whole site.
Fix things in a few clicks: applying validated security patches, cleaning infected files, removing phantom modules (present on disk but unknown to PrestaShop) and updating vulnerable modules, all with automatic backup and rollback.
A badge shows, for every detected vulnerability, whether it's already neutralised by the PrestaSecure application firewall. You can tell at a glance what's protected from what needs action.
Apply patches for known vulnerabilities in the PrestaShop core and modules straight from your dashboard, with a prior backup, automatic verification after applying and the option to undo at any time.
First release: protection dashboard with a score, antivirus (file and fingerprint scanning), application firewall (SQL injection, XSS, brute force, path traversal), remediation tools, exportable security report and automatic module updates.