Articles found for the tag : Prestashop

Comprehensive Guide to Zero-Downtime PrestaShop Deployment Using Laravel Envoy and Bitbucket Pipelines

2 months ago

Learn how to set up a zero-downtime deployment for your PrestaShop application using Laravel Envoy and Bitbucket Pipelines. This comprehensive guide covers directory structure, Envoy setup, dependency management, and automated deployment processes to ensure a seamless, efficient deployment strategy.

Maximizing Visibility: Advanced SEO Strategies for PrestaShop Success

10 months ago

Explore advanced SEO techniques tailored for PrestaShop users in this comprehensive guide. Learn how to optimize your online store with strategic content, technical enhancements, and effective off-page tactics to significantly boost your search engine ranking and drive traffic, ensuring your PrestaShop platform achieves its full potential.

What’s New in PrestaShop 8.0

2 years ago

PrestaShop 8 is a major update that brings an updated Symfony 4.4 version, compatibility with PHP 8.1, new password policy and session management features, support for WebP, and more.

Securing your module 4/4 - Protect your template against XSS vulnerabilities

2 years ago

If you don't know what an XSS (Cross-Site Scripting) flaw is, I recommend that you do a quick search on the Internet. The most common XSS error is using GET or POST values in templates.

Securing your module 3/4 - Protect your code against SQL injections

2 years ago

Even though PrestaShop has been using the PDO library since version 1.5, it still does not call some important methods, such as bindParam() or bindValue(), which are designed to protect SQL queries. So we have to protect them manually.

Securing your module 2/4 - Disallow direct file access

2 years ago

Of your PHP files that are in your modules, you should only have class definitions and no dots - except for Ajax scripts (and again, you should only go through front or admin controllers). It is still recommended to prohibit access to all subdirectories containing PHP files or templates.

Securing your module 1/4 - Protecting yourself against Directory listing

2 years ago

Directory listing functionality is enabled by default on many web servers. And, depending on your host, it will be more or less easy to deactivate it.



Subscribe to Newsletter