Critical PrestaShop flaw: your /install/ folder can hand your store to hackers
PrestaShop security alert. Over 200 stores currently vulnerable. Check yours in 30 seconds (dedicated section...
Creating a ticket rings our phone straight away. Across 683 tickets opened in 2026, half get their first reply within 5 minutes, and six in ten within a quarter of an hour.
What our customers say How we workIf you are on this page, you suspect your website has been hacked. A redirect you did not set up, a Google warning, a message from your host, or a payment form that no longer looks like yours.
At this point, two questions come up: is it really a hack, and how far does it go.
We answer both, then we put the site back in order.
You receive a detailed report of what happened: every file cleaned, every backdoor removed, and the vulnerability fixed. If the site is reinfected within 7 days, we step in again free of charge.
If you are here, you suspect a hack. We look, we clean, we close the way in. 329 sites back online since 2018.
€69 excl. VAT off your first job with us
What are you seeing on your site?
Several answers possible. Only tick what you have seen yourself.
A hacked site looks normal when you are the one looking at it. The code fires for everyone else. Here are the four screens we find most often.
They only show up in Google, never while you browse your own site. The attacker creates thousands of pages under your domain to sell counterfeits, riding on the authority you spent years building. Your rankings work for someone else, and your real pages fall back by the same amount.
What we do: we remove the scripts generating those pages, delete any Search Console property the attacker may have added to steer your rankings, then identify the way in that let them run their code. The review request to Google comes only afterwards, once the site is clean: sent too early it is refused. Processing then takes a few days.
Two forms, and the quieter one is worse. In the first, the attacker simply copies your customers' card numbers as they are typed. The payment goes through, you get paid as usual, nothing shows, sometimes without the form even looking different. It can run for months. In the second, they replace your form with their own and collect the orders in your place for as long as nobody notices: you lose your customers' card numbers, the revenue, and you still have to ship the orders.
What we do: we remove the code from the checkout, pin down exactly how long it ran so we know which customers are affected, and support you on your notification obligations if data leaked.
This screen does not appear on day one. It means Google itself has confirmed the compromise and is now protecting your visitors from your site: the infection has been in place and indexed for a while. Traffic drops the same day, regulars included, and your paid campaigns stop while the warning stands.
What we do: we clean, check that nothing infected is still indexed, then follow the warning through until your site comes back normally in the results.
This one often arrives before the others: the host sees the mass sending or the abnormal load before Google reacts. That is lucky, except the shop is already cut off, orders in progress interrupted, and you can no longer fix anything yourself because access is closed. Every hour counts.
What we do: we get in touch with the host, clean from the rescue access, and get the service restored.
Not an exhaustive list: these are the four situations we meet most often, there are others.
It happens. In April 2026 an attacker took control of a server we were not yet managing, deleted the files and databases of two shops, then left a bitcoin ransom note claiming to hold a copy.
We did not pay. Nothing guaranteed he really held the data, nor that he would return it. We rebuilt the server, then reconstructed the catalogue from public web archives. Both shops are back.
Archives never return a catalogue in full. They were enough to put these two shops back online.
Four questions, thirty seconds. 329 sites back online since 2018.
Millions of cyber attacks are recorded every day. As one of the top targets of hackers, unprotected websites are exposed to daily exploits of vulnerabilities, which allow attackers to set up scripts, which allow a whole bunch of actions that will harm your visitors and your website.
As soon as a site is hacked, your business is immediately impacted, the financial consequences can be very heavy.
Disinfecting a website from viruses is a complex task, requiring several steps or breaking down into several subtasks. No matter what security situation your website is facing, we deploy a multitude of skills to restore a normal situation.
No serious work can be done without a good analysis of the situation, we determine the type of virus, the objective of the attacker (information theft, visitor hijacking, phishing, SEO ...) and the scope of the attack.
Files may have been installed, allowing the hacker to steal information, add tools offering a range of features, or infect your visitors. We proceed to the cleaning of these.
One of the most critical points consists in the research of the flaw, indeed the attacker could penetrate your site only by exploiting a security flaw, we search in your logs and your files to determine the original entry point.
Once the flaw is found, it must be patched, either by updating one of your scripts, CMS, if available, or we implement ourselves a solution to prevent the flaw from being exploited again.
Four questions, thirty seconds, and you will know where you stand. The assessment costs nothing and commits you to nothing.
Check my siteWhat our customers say Emergency call-outs, sites put back online, and access handed to strangers. Here is what they took away from it.
Every hour that passes increases the damage. Contact us for a free diagnosis and rapid intervention.
Request a free diagnosisRunning a PrestaShop store?
A cleaned site gets hacked again if the way in is still open. That is why we built PrestaSecure, our service dedicated to PrestaShop store security: continuous monitoring, real-time attack blocking, and an alert as soon as one of your modules is hit by a known flaw.
Serenity plan — €575 excl. VAT per year
Antivirus, firewall and, above all, unlimited clean-ups by our experts. No commitment, one domain. For comparison, a one-off clean-up alone is billed €345 excl. VAT: the second incident already pays for itself.
PrestaSecure only covers PrestaShop. On any other technology, order the clean-up from this page.
Our analyses of real infections: how attackers get in, what they leave behind, and how we clean it up.
PrestaShop security alert. Over 200 stores currently vulnerable. Check yours in 30 seconds (dedicated section...
After 590 security interventions on hacked stores and 8 years in the field, we launch PrestaSecure: antivirus,...
261 bot and spam interventions analyzed: credit card testers, order spam, registration spam, analytics polluti...