Most merchants discover their store's security issues the day they get hacked. Yet the vast majority of attacks exploit known, documented vulnerabilities: outdated versions, accessible sensitive files, neglected configurations. A simple audit detects them in seconds.
We analyzed 60 French e-commerce stores (PrestaShop and WooCommerce) using only passive techniques: reading HTTP headers, the homepage, and probing public paths. No server access, no intrusion.
CMS and PHP versions, compared to official end-of-life dates.
Sensitive directories publicly accessible: /install, /admin, /.git, SQL backups.
HTTPS, redirects, security headers (HSTS, X-Frame-Options, CSP, nosniff).
Secure, HttpOnly and SameSite attributes on session cookies.
Free, passive, no signup. Your /100 score in 30 seconds.
If your score is good, you know the basics are sound — keep it that way (updates, offline backups). If it's bad, the report lists the issues and fixes in priority order. For PrestaShop stores, the PrestaShield module automates everything: malware scan, email alerts, history, PDF report.
Study conducted in August 2026 on 60 French stores from a public sample. Passive methodology: HTTP headers, public content, standard path probing.