Securantis

PrestaShop

PrestaShop Scanner: scheduled scans, limits, false-positive accuracy and report delivery

How the Securantis module's scheduled scans for PrestaShop work, what their limits are, how to reduce false positives and how to receive the report.

← Back to help center

Securantis how-to guide

Purpose : This document explains how the Securantis scanner for PrestaShop works: frequency and duration of scheduled scans, technical limits (number of files, time budget), settings that influence accuracy, and report generation/sending. It also describes best practices to minimize false positives and follow-up actions after receiving a report.

Intended audience :

  • PrestaShop administrators who want to enable or adjust automatic scans.
  • Security managers who must interpret reports and define quarantine/restoration procedures.

Technical prerequisites :

  • Securantis module installed and activated in PrestaShop.
  • Securantis license activated for report sending (if you wish to receive centralized reports).
  • Administrator access to the PrestaShop back office to modify the module settings.
  • Compatible server (PrestaShop and PHP versions are reported in the report).
  1. Understanding limits and the scan budget
  • Maximum number of files scanned: the module uses a configurable limit. The typical default behavior corresponds to a setting equivalent to 500 files, but the effective value is bounded between 120 and 10,000 files. If you increase the limit, the module will automatically constrain it within this range to avoid scans that cannot be completed on constrained environments.
  • Time budget per run: the time allocated to a scan pass is adjusted according to the file limit. The time calculation starts from a short base and increases gradually with the number of files, but remains capped (value within a range from a few seconds to several tens of seconds). The objective is to avoid blocking the frontend or web tasks during a scan.
  • Scans limited by areas: to reduce impact, the scanner performs partial checks on sensitive directories (limited extensions such as .php, .tpl, .js, etc.) and can limit the number of items traversed per directory. This means a single scan does not necessarily cover 100% of files if your shop is very large.

Practical consequence: on large installations, plan several successive executions or increase the scheduled scan window rather than expecting a single exhaustive scan.

  1. Scan frequencies and scheduled scans
  • The module offers appropriate execution frequencies (e.g. several times a day or hourly depending on settings). Choose the frequency based on risk: shops with frequent batches of theme/module updates or high commercial activity may require more regular scans.
  • If you change the file limit, monitor execution time for the first few hours: a higher budget lengthens execution and may require slightly spacing out the frequency.
  1. Accuracy and reducing false positives
  • Accuracy modes: the scanner applies rules distributed by severity level. A stricter mode will raise the alert level for certain so-called 'legacy' items (e.g. older versions of PrestaShop or PHP) which, in permissive mode, are merely reported as informational.
  • Baseline (reference): the module can create and use a baseline (known state) to distinguish known files from new files. When the baseline is enabled, files already recorded are treated as known, which greatly reduces false positives for legitimately rarely modified files.
  • Scoring and deduplication: alerts are deduplicated before report generation to avoid duplicates. The final report includes a security score and indicators (e.g. number of hashed files, modules scanned, files flagged as new).

Best practices to limit false positives:

  • Initialize the baseline on a clean and validated state of your shop (e.g. immediately after a stable production release).
  • Enable an intermediate accuracy level at the start (default mode) then switch to strict mode only if you accept more informational alerts.
  • Explicitly exclude large non-critical folders (if the module offers this option) or gradually increase the file limit when putting the scanner into service.
  1. Report generation and sending
  • Content: the report contains the overall status (good/warning/critical), scan date and time, PrestaShop and PHP versions, module version, and a set of technical checks (SSL enabled/disabled, debug mode, number of hashed files, modules scanned, etc.). It also lists categorized alerts and provides contextual guidance.
  • Sending: centralized sending of reports and events is an activatable option. If enabled and the license is validated, the module transmits scan data to the Securantis service for centralization and viewing in the SaaS. You can also export/view the report locally in the back office.

Important: Securantis does not automatically delete suspicious files. Any quarantine, deletion or restoration action requires a human decision. The module can offer a manual quarantine option: review and validate before any deletion.

  1. Prudent settings to apply
  • Do not immediately set strict mode on a production shop without a validation step: this can generate numerous alerts (false positives) and unnecessarily alarm teams.
  • Create a baseline after an initial manual verification: back up your files, validate the state, then create the baseline to reduce recurring alerts.
  • If you increase the maximum number of files scanned, also slightly increase the interval between scans to avoid overloading the server.
  1. Common errors and how to fix them
  • Incomplete report (few items scanned): check the configured file limit and execution time; reduce the limit or increase the frequency to distribute the work.
  • Reports not being sent: check that the license is activated and that the report sending option is enabled. Also verify the server's outbound connectivity to Securantis services.
  • Repeated alerts on known files: if you have not created a baseline, wait for a baseline to be generated or create it manually after validation.
  • Alert about SSL not enabled: the scanner reports the absence of SSL in PrestaShop settings. Enable SSL in PrestaShop and, if necessary, configure your web server to force HTTPS.
  1. Step-by-step troubleshooting
  • Step 1: check the module configuration (license, report sending enabled, scan frequency).
  • Step 2: run a manual execution (if available) and note the duration and number of files scanned in the report. Compare them with the desired limit.
  • Step 3: if the number of files scanned is lower than the limit, check whether permissions or directory reads prevent file access (system rights, open_basedir, etc.).
  • Step 4: for persistent false positives, export the list of flagged files, verify their history (legitimate modifications by theme/module), then mark them as known via the baseline or perform a manual repair.
  1. Precautions and security rules
  • Never delete a flagged file without a prior backup and manual verification: keep an offline copy before any action.
  • Never share passwords by email or chat with correspondents, including support. Access for any paid intervention is provided only in the secure client area after payment.
  • Treat critical alerts as a priority but follow your internal validation process before making any production changes.
  1. When to contact Securantis support Contact support if:
  • The module no longer scans at all despite checking configuration and filesystem rights.
  • Report sending fails despite an active license and valid network connectivity.
  • You observe massive, simultaneous alerts after abnormal site behavior (e.g. injections or unidentified new files) and you want assisted intervention.

When to request a paid intervention:

  • If you want our engineers to examine and act on suspicious files or restore a clean state, a thorough and secure intervention is offered as a paid service. Access for this operation is provided in the secure client area after payment completion.

Expected result after implementation

  • Regular scheduled scans adapted to the shop size, with a balanced compromise between coverage and server impact.
  • Fewer false positives thanks to a correctly initialized baseline and appropriate accuracy configuration.
  • Actionable reports containing a score and technical checks useful for prioritizing actions.

Quick appendix (reminders)

  • The scanner reports but does not remove: quarantine and deletion require a human decision.
  • Check SSL, PrestaShop and PHP versions reported in the report to address risks related to outdated versions.

If you need assistance configuring accuracy, creating the baseline, or interpreting a critical report, contact Securantis support via the secure client area; provide the report ID and the scan date/time to speed up the analysis.

Cookies

We use cookies necessary for the operation of the site. With your consent, we can also use analytics and personalization cookies. Learn more.

Necessary

Essential for the site and the client area.

Active