ALTCHA MIT local for PrestaShop: comparison with Cloudflare, Google, and ALTCHA Sentinel
ALTCHA in local MIT mode is an interesting anti-spam solution for those managing a PrestaShop ecommerce and wanting to protect forms while reducing dependence on external services. In this article, we compare it with Cloudflare Turnstile, Google reCAPTCHA, and ALTCHA Sentinel.
Read moreSecurity update for ps_facetedsearch: what PrestaShop e-commerce sites need to do
The PrestaShop project has released a security update for the ps_facetedsearch module. Let's see what this means for those managing an ecommerce, what checks to perform immediately, and how to reduce the risk associated with bots, scrapers, and unusual requests on faceted search.
Read morePrestaShop Login: Complete Guide to Security and Session Management in PrestaShop 9
The PrestaShop login system starting from version 8 introduces numerous innovations in terms of security, password management, and user session control. Discover how to best protect your e-commerce and which modules can help you enhance the security of your online store.
Read moreAbuseIPDB: What it is, what it's for, and how it works
AbuseIPDB is an essential tool for online security: it monitors, reports, and blocks malicious IP addresses. Discover how it works and how it can protect your PrestaShop store from cyber risks!
Read moreThe operational challenges of 2FA in modern enterprise systems: analysis and pragmatic solutions for PrestaShop
2FA is now a security standard in corporate systems, but it has practical limitations that are often underestimated, especially in multi-shop PrestaShop environments, agencies, and contexts with distributed teams. In this article, we deeply analyze the real issues and introduce pragmatic solutions to balance security and productivity.
Read moreProtect PrestaShop from bots and attacks: strategies and modules
The security of your PrestaShop store is essential to protect customers, orders, and online reputation. In recent years, there has been an increase in attack attempts through bots, scraping, and cyber fraud that can jeopardize sensitive data and sales. In this article, discover how to defend yourself effectively: practical strategies, mistakes to avoid, a security checklist, and a selection of the best PrestaShop modules – including the latest solutions from TecnoAcquisti.com – to secure your platform. Strengthen your ecommerce protection now and enhance customer trust!
Read moreXSS Vulnerability in PrestaShop Customer Service: What It Is, How Dangerous It Is, and How to Protect Yourself
We have analyzed the Stored XSS vulnerability in PrestaShop's Customer Service (GHSA-w9f3-qc75-qgx9, severity 9.3/10) affecting versions 1.7, 8.x, and 9.x. Discover the practical limits of this attack - already mitigated in many shops by PrestaShop itself and reCAPTCHA modules - and download our free open-source hotfix module to protect your stores before the official update.
Read moreMeta AI Bot: the meta-webindexer crawler is hammering websites with thousands of requests per day
The meta-webindexer crawler from Meta Platforms is generating abnormal traffic on web servers worldwide, with peaks of 180 requests per minute per single domain. Unlike Googlebot, this bot does not respect the directives of robots.txt and does not apply any progressive back-off. In this article, we explain how to detect it in Plesk logs and block it permanently with Fail2ban.
Read moreXML error on PrestaShop 1.7.x: Addons under maintenance, corrupted files, and blocked BO access
In recent days, several stores based on PrestaShop 1.7.x have started showing errors such as: StartTag: invalid element name, Extra content at the end of the document, ERR_TOO_MANY_REDIRECTS in the backend. The problem is not local to the server, nor a PHP configuration error, but is related to an external condition: PrestaShop Addons under maintenance, with a non-XML response from Cloudflare.
Read moreAttention to "silent login": critical vulnerability in the PrestaShop Checkout module (CVE-2025-61922)
In the world of e-commerce, payment and checkout modules represent a sensitive target for cyber attacks. Recently, the vulnerability CVE-2025-61922 was made public, which affects the official PrestaShop Checkout module, developed in collaboration with PayPal.
Read moreHow to block Anthropic’s ClaudeBot
ClaudeBot by Anthropic is a web crawler used by Anthropic to collect publicly available data on the internet, in order to develop their artificial intelligence models. ClaudeBot identifies itself with the User Agent token "ClaudeBot" and follows industry standards for data collection, including adherence to directives in robots.txt files, such as "Disallow" and "Crawl-delay." This is according to the documentation of the Web Crawler, but in reality, it often ignores robots.txt.
Read moreProtecting your ecommerce from fake registrations and spam becomes more expensive.
Google reCAPTCHA in April 2024 revises its offering, becoming practically paid for the majority of websites. The free usage limit drops from 1,000,000 uses per month to just 10,000, 100 times less. The limit of the free tier will therefore be reduced from 1 million free evaluations per month to only 10,000. This represents a substantial decrease in the number of free evaluations available to users.
Read moreMajor Security Vulnerability: Let's Clarify
On July 22, 2022, a notice from PrestaShop arrived regarding a vulnerability that allows a malicious actor to take control of your ecommerce based on this CMS; as of now, not all the dynamics of this newly discovered exploit are clear.
Read moreZstandard: Compressed Plesk backups .tzst (Facebook algorithm)
Without prior notice, Plesk has switched to Zstandard for Backups, this algorithm was developed by Facebook to manage a large amount of data on a daily basis, it is a lossless compression algorithm, so it operates without causing data loss. Zstd allows for real-time data compression, offering a trade-off between compression speed and compression ratio, thus enabling the compression of large amounts of data in a short time. It is therefore understandable why Plesk decided to switch to this algorithm for backups, the advantages are numerous, however ...
Read morePerforming Backup with Plesk Panel
The backup of PrestaShop via Plesk is a simple and secure operation that can be performed independently even on remote resources: FTP, DropBox, or Google Drive. Performing a backup on remote devices protects not only against hardware failure of the server but also from potential incidents within the Web Farm, such as a fire like the one that occurred at OVH in 2021.
Read moreGeneral guide to safety and comfort
The use of a computer, notebook, tablet, or video terminals involves a set of decisions that can affect both comfort and health and productivity. It is therefore important to pay attention to posture and, in any case, to adjust the position of the body according to the device. There is no "correct" position suitable for everyone and for all activities.
Read moreHow to defend Prestashop from spam and bots?
Any site on the WEB must sooner or later deal with "malicious" bots and spam, if not also with attempts to attack in order to infect or compromise the site itself. The enormous speculation surrounding cryptocurrencies since 2016 has made the problem notably concerning, even just for the continuous attempts to infect websites in order to distribute to unsuspecting visitors malicious programs and scripts aimed at mining cryptocurrencies.
Read moreSSL Certificates: The padlock for a secure site and protection against data theft
Starting from January 2017, Google Chrome (ver. 56 or later) will mark pages that collect passwords, emails, or credit card data as "Not secure" if they are not served over the HTTPS protocol (green lock). The new Chrome warning is just the first phase of a long-term plan to mark all pages served via the unencrypted HTTP protocol as "Not secure."
Read more