Jump to content

Edit History

MathiasReker

MathiasReker


New major version

security-pro-all-in-one.thumb.jpg.ef9724df1f6ede4f5d8f05daca8a99ed.jpg
 
 
Price: Only 69,99 EURO (Free support included)
 
 

Cheap doesn't always mean bad. I spent more than a year on this project and I want to help as many store owners as possible. You get all the security features that you need in this module and I update the module on a regular basis.

PrestaShop in its own is very secure. It's among the most secure content management systems available. When that is said, PrestaShop advice you to set file- and folder permissions by your own, and secure your back-end with another layer of security from your webserver itself. This part is not covered by PrestaShop. I added those functions to the module, so you can do it without any coding knowledge. I added all the functions that you need to follow best practice. Trust me - this module will save you months of work.

I did not add settings that are obviously already covered by PrestaShop core with another technique, but if some technique having more layers is good practice, I added those extra layers of security. You can for instance enable Two-Factor Authentication and setup e-mail alert in case of brute force attacks.

Example of a great feature: You can enable e-mail notifications for filechanges. You choose the time interval to check for, by a cronjob. Then you will get an e-mail if there were any filechanges since last check.

In case you get malware, spyware etc., or you mess something up by yourself, you will get an e-mail with paths to the files that was changed. In that way you know exactly where to check!

Here are what you get with Security Pro (all the configurations are not listed, check screenshots for additional information):

Brute force protection:

  •     Enable/Disable "Brute force protection for back office"
  •     Enable/Disable "E-mail notification in case of fail attempts to login"
  •     Enable/Disable "E-mail notification in case of successfully login"
  •     Enable/Disable "Log"


Two-factor authentication

  •     Enable/Disable "Two-factor authentication" (for back office)


Second login

  •     Enable/Disable "Second login" (from your webserver itself)


Secure front office

  •     Enable/Disable "Click-jack protection"
  •     Enable/Disable "XSS protection"
  •     Enable/Disable "Disable content sniffing"
  •     Enable/Disable "Force secure connection with HSTS"
  •     Enable/Disable "Expect CT"
  •     Enable/Disable "Referrer policy"


Anti-SPAM

  •     Enable/Disable "Prevent fake accounts / Block bots"
  •     Enable/Disable "Contact form"
  •     Enable/Disable "Block TOR IPv4 and IPv6 addresses"
  •     Enable/Disable "Block custom list of IP addresses" (The module can handle IPv4, IPv6 addresses, as well as IP ranges, in CIDR formats like ::1/128 or 127.0.0.1/32 and in pattern format like ::*:* or 127.0.*.*)
  •     Enable/Disable "Block custom list of user agents"


Anti-virus

  •     Enable/Disable "Malware scanner"
  •     Enable/Disable "filechanges scanner"
  •     Enable/Disable "Log"
  •     Enable/Disable "Block file uploads" (for back office)


Firewall (WAF)

  •     Enable/Disable "Anti-flood / Anti DDoS protection"
  •     Enable/Disable "Bot check"
  •     Enable/Disable "Anti-SQL injection"
  •     Enable/Disable "Anti-XXS injection"
  •     Enable/Disable "Anti-SHELL injection"
  •     Enable/Disable "Anti-HTML injection"
  •     Enable/Disable "Anti-XST injection"
  •     Enable/Disable "Block too long HTTP requests"
  •     Enable/Disable "Block user agents with too long names"
  •     Enable/Disable "Block old HTTP protocols"
  •     Enable/Disable "Block file-upload" (front office)
  •     Enable/Disable "Log"


Protect content

  •     Enable/Disable "Disable right click"
  •     Enable/Disable "Disable right click on images only"
  •     Enable/Disable "Disable drag and drop"
  •     Enable/Disable "Disable copy"
  •     Enable/Disable "Disable cut"
  •     Enable/Disable "Disable paste"
  •     Enable/Disable "Disable text selection"


Automatic backups

  •     Enable/Disable "Backup database to local"
  •     Enable/Disable "Backup database to Dropbox"
  •     Enable/Disable "Backup files to local"
  •     Enable/Disable "Backup files to Dropbox"


Admin directory

  •     Change name of admin directory in a few clicks.


Password generator

  •     Strong password generator for MySQL database, FTP, hosting panel/cPanel, SSH access and back office.


Scripts

  •     Fix insecure permissions vulnerability
  •     Fix directory traversal vulnerability


Analyze system for all known vulnerabilities

  •     CVE-2020-5293
  •     CVE-2020-5288
  •     CVE-2020-5287
  •     CVE-2020-5286
  •     CVE-2020-5285
  •     CVE-2020-5279
  •     CVE-2020-5278
  •     CVE-2020-5276
  •     CVE-2020-5272
  •     CVE-2020-5271
  •     CVE-2020-5270
  •     CVE-2020-5269
  •     CVE-2020-5265
  •     CVE-2020-5264
  •     CVE-2020-5250
  •     CVE-2019-13461
  •     CVE-2019-11876
  •     CVE-2018-8823
  •     CVE-2018-8824
  •     CVE-2018-7491
  •     CVE-2018-19355
  •     CVE-2018-19124
  •     CVE-2018-19125
  •     CVE-2018-19126
  •     CVE-2018-13784
  •     CVE-2017-9841
  •     CVE-2015-1175


Analyze your server for insecure settings

  •     session.use_cookies
  •     session.use_only_cookies
  •     session.cookie_httponly
  •     session.hash_function
  •     session.use_trans_sid
  •     session.cookie_secure
  •     session.use_strict_mode
  •     session.cookie_lifetime
  •     session.lazy_write
  •     session.sid_length
  •     session.gc_divisor
  •     session.sid_bits_per_character
  •     allow_url_fopen
  •     allow_url_include
  •     display_errors
  •     log_errors
  •     error_reporting
  •     display_startup_errors
  •     expose_php
  •     register_globals
  •     register_argc_argv
  •     short_open_tag
  •     xdebug.default_enable
  •     xdebug.remote_enable
  •     file_uploads
  •     upload_max_filesize
  •     post_max_size
  •     max_input_vars
  •     max_input_time
  •     memory_limit
  •     max_execution_time
  •     default_charset


Analyze you PrestaShop configuration for insecure settings

  •     PHP version (7.2.19)
  •     SSL enabled
  •     SSL Enabled everywhere
  •     PrestaShop token
  •     Mod Security
  •     PrestaShop admin directory name
  •     Database table prefix
  •     PrestaShop debug mode


Analyze SSL

  •     Analyze your SSL certificate
  •     Scan your website for mixed content


Recommandation
The module does not use overrides and none of the core-files are modified, so you are completely safe against conflicts between other modules.

Works on all major server software (Apache, Nginx, LiteSpeed, etc.).
Works on PrestaShop 1.6.1.x, 1.7.x.x and on thirty bees 1.x.x.
Works on PHP 5.6.x, 7.0.x, 7.1.x and 7.2.x.

Everything is very well tested. No known bugs exist and the module is battle tested! The module is already in production on many stores.

The code quality is high and it follows PretaShop's guidelines.

The code is optimized for performance and security.

If you want to see a demo of the module, or if you have questions please contact me. Contact link: https://addons.prestashop.com/en/contact-us?id_product=44413

1.thumb.png.ccba84010138499506a7ab0a1724c1f0.png2.thumb.png.f073d2585a5ca55938d326471981e788.png

17.thumb.png.943a0f24b48f0ade4213be6de26e062c.png

3.thumb.png.e6a6abf704101d57f8145a0a9d27e6f8.png4.thumb.png.97d0a264154a1bbf80ed0ca4386c8838.png5.thumb.png.b4328ed2fa9ef4917e0364d73e83dc55.png6.thumb.png.ac289e94fd6099456149f4fdf718a94c.png7.thumb.png.e6de4ad25ba02d8e560301f2fedfb7f5.png

8.thumb.png.dae07c27c697d5134b36409d70462f28.png18.thumb.png.ef7dc64b2d1abbf747e1b2b4d976f314.png

9.thumb.png.016f92a303093fa67814c061cf174bec.png10.thumb.png.96f610ee5349d0f2de47f1316eb21a36.png11.thumb.png.937a60981d6c38d9b9a380c188ef9043.png12.thumb.png.b539d158fafa5c4c32562b1b37bb93f7.png13.thumb.png.44c7b4b4af7cc24645ed20a9c867ed9b.png15.thumb.png.c8b42f020d349f9d5d154803d9ed5253.png111.thumb.png.7e1a8a3da12d20b0857e78a1c03fb563.png

 

14.png

MathiasReker

MathiasReker

security-pro.thumb.jpg.54109ac9bb597330997d914ed691fe2e.jpg
 
 
Price: Only 59,99 EURO (Free support included)
 
 
PrestaShop in its own is very secure. It is among the most secure content management systems available. When that is said, PrestaShop advice you to set file- and folder permissions by your own, and secure your back-end with .htpasswd. This part is not covered by PrestaShop. I added those functions to the module, so you can do it without any coding knowledge.
 
I did not add settings that are obviously already covered by PrestaShop core with another technique, but when that it said, if some technique having more layers is good practice, I added those extra layers of security.
 
Example of a great feature: You can enable e-mail notifications for filechanges. You choose the time interval to check for by a cron-job. You will get an e-mail if there were any filechanges since last check.
So in case you get malware, spyware etc., or you mess something up by yourself, you will get an e-mail with paths to files that changed. So you know exactly where to check!
 
Here are just some of the other features you will have with this module (check screenshot for more information's):
 
  • Brute force protection
  • Prevent unauthorized access to your back end
  • Click-jack protection
  • XSS protection
  • Disable content sniffing
  • Force secure connection with HSTS
  • Expect CT
  • Referrer policy
  • Cookie secure flag
  • Cookie HttpOnly flag
  • Block specific files
  • Block bad user-agents / bots
  • Block custom list of IP’s
  • Add missing index.php files
  • Fix insecure permissions
  • E-mail notification if case of file changes
  • E-mail notification in case of malicious code (malware scan)
  • Disable right click
  • Disable drag and drop
  • Disable copy
  • Disable cut
  • Disable paste
  • Disable text selection
  • Fix insecure admin directory name
  • Check system for vulnerabilities

13.thumb.jpg.27c1d55ec081a9110bf7cd1f268d934f.jpg

security-pro2.thumb.jpg.5cc3756df77cfaa006383e80ce2ad038.jpg

security-pro3.thumb.jpg.778f88e6167e1c742e3f3cb41b284c83.jpg

security-pro4.thumb.jpg.822a604b70db2b2cfc13bc2f56c9ade9.jpg

security-pro5.thumb.jpg.004ace4719c46c93b9989af8d963513b.jpg

security-pro6.thumb.jpg.1cf6f84f8d695c8635bb97b26147f4d2.jpg

security-pro7.thumb.jpg.2a85c8944942ae5586f05ea5dddab94a.jpg

security-pro8.thumb.jpg.b2dfe5b227101bfe2df7f0dfd50e792f.jpg

security-pro9.thumb.jpg.e6d68a1d11bd9e22b0503de6d3d70886.jpg

security-pro10.thumb.jpg.07d860174201dda46eee143f4d433698.jpg

security-pro11.thumb.jpg.dd996b0e6fad18ed0db3f4eedad6e27c.jpg

 

14.thumb.jpg.82637ed19c950935667fe73c0d4b0fed.jpg

12.thumb.jpg.b0ca9ab2bb9e5200a824a70fc3849f22.jpg

 

 
MathiasReker

MathiasReker

security-pro.thumb.jpg.54109ac9bb597330997d914ed691fe2e.jpg
 
 
Price: Only 59,99 EURO
 
Support: Free
 
 
PrestaShop in its own is very secure. It is among the most secure content management systems available. When that is said, PrestaShop advice you to set file- and folder permissions by your own, and secure your back-end with .htpasswd. This part is not covered by PrestaShop. I added those functions to the module, so you can do it without any coding knowledge.
 
I did not add settings that are obviously already covered by PrestaShop core with another technique, but when that it said, if some technique having more layers is good practice, I added those extra layers of security.
 
Example of a great feature: You can enable e-mail notifications for filechanges. You choose the time interval to check for by a cron-job. You will get an e-mail if there were any filechanges since last check.
So in case you get malware, spyware etc., or you mess something up by yourself, you will get an e-mail with paths to files that changed. So you know exactly where to check!
 
Here are just some of the other features you will have with this module (check screenshot for more information's):
 
  • Brute force protection
  • Prevent unauthorized access to your back end
  • Click-jack protection
  • XSS protection
  • Disable content sniffing
  • Force secure connection with HSTS
  • Expect CT
  • Referrer policy
  • Cookie secure flag
  • Cookie HttpOnly flag
  • Block specific files
  • Block bad user-agents / bots
  • Block custom list of IP’s
  • Add missing index.php files
  • Fix insecure permissions
  • E-mail notification if case of file changes
  • E-mail notification in case of malicious code (malware scan)
  • Disable right click
  • Disable drag and drop
  • Disable copy
  • Disable cut
  • Disable paste
  • Disable text selection
  • Fix insecure admin directory name
  • Check system for vulnerabilities

13.thumb.jpg.27c1d55ec081a9110bf7cd1f268d934f.jpg

security-pro2.thumb.jpg.5cc3756df77cfaa006383e80ce2ad038.jpg

security-pro3.thumb.jpg.778f88e6167e1c742e3f3cb41b284c83.jpg

security-pro4.thumb.jpg.822a604b70db2b2cfc13bc2f56c9ade9.jpg

security-pro5.thumb.jpg.004ace4719c46c93b9989af8d963513b.jpg

security-pro6.thumb.jpg.1cf6f84f8d695c8635bb97b26147f4d2.jpg

security-pro7.thumb.jpg.2a85c8944942ae5586f05ea5dddab94a.jpg

security-pro8.thumb.jpg.b2dfe5b227101bfe2df7f0dfd50e792f.jpg

security-pro9.thumb.jpg.e6d68a1d11bd9e22b0503de6d3d70886.jpg

security-pro10.thumb.jpg.07d860174201dda46eee143f4d433698.jpg

security-pro11.thumb.jpg.dd996b0e6fad18ed0db3f4eedad6e27c.jpg

 

14.thumb.jpg.82637ed19c950935667fe73c0d4b0fed.jpg

12.thumb.jpg.b0ca9ab2bb9e5200a824a70fc3849f22.jpg

 

 
MathiasReker

MathiasReker

security-pro.thumb.jpg.54109ac9bb597330997d914ed691fe2e.jpg
 
 
Price: Only 59,99 EURO
 
 
PrestaShop in its own is very secure. It is among the most secure content management systems available. When that is said, PrestaShop advice you to set file- and folder permissions by your own, and secure your back-end with .htpasswd. This part is not covered by PrestaShop. I added those functions to the module, so you can do it without any coding knowledge.
 
I did not add settings that are obviously already covered by PrestaShop core with another technique, but when that it said, if some technique having more layers is good practice, I added those extra layers of security.
 
Example of a great feature: You can enable e-mail notifications for filechanges. You choose the time interval to check for by a cron-job. You will get an e-mail if there were any filechanges since last check.
So in case you get malware, spyware etc., or you mess something up by yourself, you will get an e-mail with paths to files that changed. So you know exactly where to check!
 
Here are just some of the other features you will have with this module (check screenshot for more information's):
 
  • Brute force protection
  • Prevent unauthorized access to your back end
  • Click-jack protection
  • XSS protection
  • Disable content sniffing
  • Force secure connection with HSTS
  • Expect CT
  • Referrer policy
  • Cookie secure flag
  • Cookie HttpOnly flag
  • Block specific files
  • Block bad user-agents / bots
  • Block custom list of IP’s
  • Add missing index.php files
  • Fix insecure permissions
  • E-mail notification if case of file changes
  • E-mail notification in case of malicious code (malware scan)
  • Disable right click
  • Disable drag and drop
  • Disable copy
  • Disable cut
  • Disable paste
  • Disable text selection
  • Fix insecure admin directory name
  • Check system for vulnerabilities

13.thumb.jpg.27c1d55ec081a9110bf7cd1f268d934f.jpg

security-pro2.thumb.jpg.5cc3756df77cfaa006383e80ce2ad038.jpg

security-pro3.thumb.jpg.778f88e6167e1c742e3f3cb41b284c83.jpg

security-pro4.thumb.jpg.822a604b70db2b2cfc13bc2f56c9ade9.jpg

security-pro5.thumb.jpg.004ace4719c46c93b9989af8d963513b.jpg

security-pro6.thumb.jpg.1cf6f84f8d695c8635bb97b26147f4d2.jpg

security-pro7.thumb.jpg.2a85c8944942ae5586f05ea5dddab94a.jpg

security-pro8.thumb.jpg.b2dfe5b227101bfe2df7f0dfd50e792f.jpg

security-pro9.thumb.jpg.e6d68a1d11bd9e22b0503de6d3d70886.jpg

security-pro10.thumb.jpg.07d860174201dda46eee143f4d433698.jpg

security-pro11.thumb.jpg.dd996b0e6fad18ed0db3f4eedad6e27c.jpg

 

14.thumb.jpg.82637ed19c950935667fe73c0d4b0fed.jpg

12.thumb.jpg.b0ca9ab2bb9e5200a824a70fc3849f22.jpg

 

 
×
×
  • Create New...