MultiCmsManager

PrestaShop for agencies

PrestaShop store monitoring and security for web agencies

A compromised store loses money and customers' payment data. Our module for PrestaShop 1.7.6, 8 and 9 checks from inside what an external scanner cannot see.

The problem

Skimmers live in the templates.

In February 2026 PrestaShop warned stores about a JavaScript loader injected into the head.tpl template, which loaded code from a hidden address. In 2022 an SQL flaw let attackers run code on servers.

The store keeps working and pages look normal, so nobody notices until customers complain.

How it works

A module that reads the store from inside.

  1. 1

    Native module

    Upload it from the module manager and connect it with a one-time code. It works with the store in maintenance mode too.

  2. 2

    Inventory

    Modules, themes, administrators and the admin folder, even when renamed.

  3. 3

    Checks

    Core integrity against the official package, malware signatures in templates and PHP, suspicious files and backups.

In detail

What it checks on a PrestaShop store.

  • PrestaShop 1.7.6 to 9.2
  • JavaScript loaders in Smarty and Twig templates
  • Core integrity, renamed admin folder included
  • New administrators and installed modules
  • Core upgrades without false alarms
  • Encrypted backups of database and files

FAQ

Frequently asked questions

Do you check PrestaShop module vulnerabilities?

Yes. For core and the official modules we use OSV.dev, which collects the advisories published on GitHub. For third-party modules we use the Friends of Presta advisories. If two sources publish the same vulnerability you get one alert.

Can I log in with one click?

Not on PrestaShop for now. It works on WordPress, Joomla and Drupal.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.