E-Commerce Security Test

Is your store protected? The free security scan reveals missing HTTP headers, weak cookie settings, outdated SSL configurations and other security issues.

Zadarmo · Bez registrácie · Výsledky za 60 sekúnd

Čo kontrolujeme

SSL/TLS certificate — validity and configuration
HTTP → HTTPS redirect
HSTS — HTTP Strict Transport Security
Content-Security-Policy (CSP) — XSS protection
X-Frame-Options — clickjacking protection
X-Content-Type-Options
Referrer-Policy and Permissions-Policy
Cookie security flags (Secure, HttpOnly, SameSite)
Technology disclosure (Server, X-Powered-By)
Subresource Integrity (SRI) on external scripts
security.txt (RFC 9116)
WAF / CDN protection (Cloudflare, Sucuri, Fastly)

Prečo na tom záleží

43% of cyber attacks target small and mid-size merchants — exactly those with the fewest defensive resources. Missing HTTP security headers are the most common reason e-commerce stores fall victim to XSS, clickjacking, and man-in-the-middle attacks. Beyond direct financial damage, you risk GDPR fines (up to 4% of annual turnover) and loss of customer trust. The security audit takes 60 seconds and can save thousands of euros.

Často kladené otázky

Is the security scan dangerous for my store?
No. We perform only passive, non-invasive checks — reading HTTP headers, the SSL certificate, and publicly accessible files. We don't run penetration tests, send malicious requests, or attempt weak passwords. It's as safe as a regular page visit.
What is a WAF and why do I need one?
A WAF (Web Application Firewall) is a protection layer between your store and the internet that blocks malicious requests — SQL injection attempts, XSS attacks, bot scanning, DDoS. The most popular options: Cloudflare (free tier), Sucuri, Fastly. Our scan detects whether you have a WAF active.
Does it work with PrestaShop?
Yes. The scan works with PrestaShop (all versions), WooCommerce, Magento, Shopify, and custom stores. Beyond the basic checks we detect platform-specific security issues — e.g. exposed PrestaShop admin panel, wp-config.php on WordPress, Magento downloader.
What are HTTP security headers?
HTTP security headers are instructions your server sends to the browser to limit attack surface. The most important ones: Strict-Transport-Security (HSTS — enforces HTTPS), Content-Security-Policy (blocks unauthorized scripts), X-Frame-Options (clickjacking protection). Missing headers are the most common security issue for e-commerce stores.
Do you check for vulnerable modules and PHP versions?
Yes, in the Vulnerability category we detect outdated jQuery and Bootstrap libraries, end-of-life PHP versions, outdated PrestaShop and WordPress installations, and CMS information leaks. For deeper code security review we recommend expert consulting.
What if the scan reveals issues?
Every issue in the report has a recommendation on how to fix it. For PrestaShop we have the Turbo Security module that fixes most issues automatically. For more serious issues we offer expert security consulting via Inger.sk.

Pripravení na audit?

Zadarmo · 100+ kontrol · Výsledky za 60 sekúnd