TECHNOLOGIES: PRESTASHOP

PrestaShop Penetration Testing

Every module, profile and cart rule you add to PrestaShop can change what checkout and payments actually do. We test the roles, modules and rules your store actually runs. CREST-certified testers, fixed price from £2,760 for a 2-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
PrestaShop Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Renamed

During installation PrestaShop renames the /admin folder to a unique string such as /admin091anufki and treats that as done. The new name is not a permission boundary, and what a logged-in profile can still reach depends entirely on what its Permissions page grants.

Why PrestaShop findings sit in profiles, modules and cart rules, not a renamed folder

During installation PrestaShop renames the default /admin folder to a unique string such as /admin091anufki, done automatically “for security reasons”, and back-office token protection, enabled by default, ties every back-office URL to the session that requested it. Neither replaces the actual permission model underneath: PrestaShop ships four default profiles, SuperAdmin, Logistician, Translator and Salesman, and any profile you create starts with access to none of the back office until you grant it, tab by tab, across five menu permissions and three module permissions. We test what a profile’s checked boxes actually allow once every tab and module is accounted for, not what its name suggests.

Every module on a PrestaShop store, whether pulled from the official Addons marketplace or built for you, extends the shop through hooks: named points where PrestaShop hands a module live objects from the order it is processing. A payment module extends the core PaymentModule class, implementing hookPaymentOptions() to offer a way to pay and hookPaymentReturn() to handle what comes back, and the core actionValidateOrder hook then treats that cart, order, customer and currency as confirmed. We test whether that confirmation step actually re-checks the amount and currency a gateway reports, rather than trusting whatever value arrived with the request, and what any other installed module can reach through the hooks it has registered.

The webservice is switched off until you enable it, and every access key you generate afterwards carries its own per-resource permissions, a grid of read, write and delete checkboxes across every resource that key can reach. A cart rule carries its own quantity, quantity-per-customer, minimum amount and percentage or fixed reduction, alongside restrictions by country, carrier, customer group, product and shop, and we test whether checkout enforces every one of those restrictions on the server rather than trusting what the browser sends. Where Multistore is enabled, the same shop context that scopes the webservice also scopes which shop’s data an employee account or a cart rule can actually see, and we test whether that boundary holds everywhere it should.

SCOPE

What we pen test on a PrestaShop store

PS-01

Third-Party Modules and Registered Hooks

Modules from the official Addons marketplace, and any built for you, extend PrestaShop by registering hooks that hand them live cart, order and customer objects at defined points in checkout. We map every installed module against the hooks it has registered and test what each one can actually read or change through that access.

PS-02

Employee Profiles and Back-Office Permissions

PrestaShop ships four default profiles, SuperAdmin, Logistician, Translator and Salesman, and a profile you create yourself starts with access to none of the back office until you grant it across five menu permissions and three module permissions. We test whether a profile’s actual permissions match the job it is meant to do.

PS-03

Back-Office Folder, Login and Session Handling

PrestaShop renames the /admin folder to a unique string during installation and, by default, ties every back-office URL to the session that requested it. We test how well the login behind that renamed path is actually protected, rather than treating the renamed folder itself as a control.

PS-04

Cart Rules, Vouchers and Price Manipulation

A cart rule carries its own quantity, quantity-per-customer, minimum amount, and a percentage or fixed reduction, plus restrictions by country, carrier, customer group, product and shop. We test whether checkout enforces every one of those restrictions on the server, and whether a rule’s code or reduction can be replayed or altered from the browser.

PS-05

Order and Customer Data Access by ID

Orders, customers and addresses are all reachable through the webservice as directly addressable resources, referenced by their own numeric ID against the REST endpoint. We test whether an authenticated shopper or a scoped webservice key can reach another customer’s order or address purely by changing that ID.

PS-06

Payment Module Callbacks and Order Validation

A payment module extends the core PaymentModule class and implements hookPaymentOptions() to offer a way to pay and hookPaymentReturn() to handle the result, after which the core actionValidateOrder hook treats the cart, order and currency as confirmed. We test whether that step re-checks the amount and currency a gateway reports rather than trusting a value the request supplied.

PS-07

Webservice API Keys and Resource Permissions

The webservice stays disabled until switched on, and each access key you generate afterwards carries its own per-resource permissions: a grid of read, write and delete checkboxes across every resource, with a shortcut to select an entire row or column at once. We test what a key scoped to one part of your catalogue can actually reach once every resource and right is enumerated.

PS-08

Debug Mode

Debug mode is a store-wide switch, readable and toggleable from the command line with a single console command, and it is meant to stay off on a live shop. We check whether it has been left on in production and what a real request actually returns while it is.

PS-09

Core and Module Version, Patch Level

PrestaShop’s core codebase and every installed module carry their own version number and release history, separate from whatever your team last actually deployed. We check the installed core and module versions against what has genuinely been patched, rather than assuming an available update was applied.

PS-10

Multistore Context and Employee Shop Association

Enabling Multistore adds a shop and shop-group context to the webservice, where a request’s id_shop parameter decides which shop’s data it returns, and to employee accounts, which are associated with specific shops rather than the whole installation. We test whether that shop boundary is enforced everywhere it should be, not only where your team looks day to day.

OUR PROCESS

PrestaShop Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the environments, back-office accounts and webservice keys in scope, and map every installed module, profile and payment integration before testing begins.

02

Automated and Authenticated Scanning

Authenticated scanning runs against the storefront, the renamed back-office path and the webservice’s actual resource permissions, alongside targeted checks for known PrestaShop configuration weaknesses.

03

Manual Exploitation

A CREST-certified tester manually tests profile permissions, cart rule logic, payment module callbacks and webservice key scope, chaining findings where they compound across your store.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST PrestaShop pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent PrestaShop Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,760–£4,180
2 to 4 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,520–£9,370
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From PrestaShop Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our PrestaShop store?

A back-office account with a profile you control, so we see the store the way a real employee would, plus at least one storefront customer account. Where the webservice or a payment module is in scope, its own access key or sandbox credentials come too, scoped to what that integration is meant to do.

Does this touch our live data?

We test against a staging store or a cloned copy of your catalogue and customer data wherever one exists. Where only production is available, any check that could place a real order or move real payment data is agreed and scoped in advance, and read-only checks are logged as they happen.

How long does a PrestaShop penetration test take?

A single-platform PrestaShop engagement is scoped at 2 testing days as a starting point, rising with the number of installed modules, payment methods and shops in a Multistore setup. Reporting and a walkthrough call follow testing, with a free retest once fixes are in.

Is PrestaShop hosted or something we install ourselves?

PrestaShop is open source software you install and run on your own server or hosting account, rather than a platform PrestaShop hosts for you. We test the store your team deployed, including its modules, configuration and custom code, not PrestaShop’s own project codebase.

What is out of scope?

The PrestaShop core codebase itself is out of scope, since securing that is the PrestaShop project’s own responsibility. Third-party modules you have installed are tested for what they can reach given the profile and hook access available to them, not audited as a vendor’s product in their own right, and any wider server or network review sits outside a single-platform scope unless you add it.

Do you need our source code?

No. Testing is black-box against the running store by default. A grey-box option, where we review installed module code, cart rule configuration and webservice key permissions alongside testing, is available if you want faster or deeper coverage of specific findings.

Does PrestaShop have a policy on testing your own store’s security?

PrestaShop’s security policy covers reporting vulnerabilities found in the core PrestaShop codebase itself, by email or through its Bug Bounty Program, and is aimed at security researchers rather than customer testing authorisation. PrestaShop is self-hosted software you install and control, so there is no vendor multi-tenant policy restricting you from testing your own store, though if it runs on managed or shared hosting, that provider’s own testing policy still applies and we confirm the current terms with you during scoping.

Do you test the modules we installed from the Addons marketplace?

We test what each installed module can reach given the hooks it has registered and the back-office permissions assigned to it, since that access is what actually matters to your store. We do not audit that module as a standalone vulnerability review of the vendor’s own code, which stays theirs to secure.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your PrestaShop store

Every module, profile and cart rule you add to PrestaShop can change what checkout and payments actually do. We test the roles, modules and rules your store actually runs. CREST-certified testers, fixed price from £2,760 for a 2-day single-platform scope, quoted within 24 hours.