Everything you'd want to know before you install.
A detailed look at how PrestaShop Security Headers: CSP, HSTS and an A+ Grade Without Server Access works, why we built it the way we did, and the thinking behind the features above.
Why your shop gets F on securityheaders.com
PrestaShop sends almost no security headers. Without a Content-Security-Policy, a script injected by a compromised module or an XSS flaw can read the fields of the payment form. Without HSTS, the first visit can go over http. Without X-Frame-Options, your shop can be displayed inside the frame of a trap site. Public scanners see this in seconds, and agencies, auditors and some payment partners check these grades.
Building a CSP without breaking the checkout
A CSP that is too strict blocks Google Analytics, the chat widget or the Stripe form. The module therefore starts from a policy compatible with PrestaShop themes and lets you tick the services you use. In test mode, the policy applies to your IP addresses and test devices, while visitor browsers report in Report-Only what would be blocked. You browse the shop, handle the violations, then switch to enforced mode once the list stays empty.
unsafe-inline, nonce and the A+ grade
Grade A requires an enforced CSP, HSTS of at least six months and the usual headers. A+ also requires that inline scripts are no longer allowed without control. The nonce mode adds a random token to every script tag of the page and removes unsafe-inline. Two limits to know: a full page cache module serves the HTML with the nonce of the first visitor, and custom HTML tags in Google Tag Manager must use the GTM nonce variable. The violation log shows these cases before you go live.
A module that keeps watching after go-live
Once the CSP is enforced, a theme or module update can load a new domain. The module spots resources that are really blocked and had never been seen, and emails the recipients you choose, at most once per hour. Every settings change is kept with the employee who made it and the differences with the current state: if a page breaks, the previous version is restored in one click.
From PrestaShop rather than from the server
Headers are sent by PHP at the start of each request, on the front office and, if you wish, on the back office. No SSH access or .htaccess file is needed, which suits shared hosting. If your host or Cloudflare already adds some headers, the built-in scanner flags the duplicates. And if you finally prefer the server to handle the headers, the module generates the matching Apache and Nginx blocks.
There are no reviews yet.