Key Benefits
- Reduction of server load: requests are filtered at the .htaccess level before PHP and database queries are executed.
- Stability with Safe Apply: automatic testing and rollback of changes in the event of an HTTP 5xx error detection.
- Protection against bots and scrapers: blocking of AI traffic, price-scraping tools, brute-force attacks, and exploitation attempts (SQLi, XSS, LFI/RFI).
- No core interference: the module exclusively edits its own section in the .htaccess file without modifying the PrestaShop core.
- Event monitoring: analysis of server logs and identification of 403 responses for rapid administrator reaction.
Module Applications
The module is designed for shops hosted on shared servers, VPS, or servers with CPU/RAM limits, where sudden bot traffic causes performance drops or account suspensions.
It is highly effective in B2B and B2C shops exposed to brute-force attacks, mass form scanning, automated stock level extraction, and competitor price monitoring.
Back Office Features
1. Safe Apply Engine
Safe implementation of changes in .htaccess with automatic validation testing.
- Automatic rollback – restoration of the previous file version upon detecting an HTTP 500 error.
- Background testing – deployment without interrupting shop operations.
2. Rule Profiles (ready-made configurations)
Sets of pre-defined security policies for quick deployment.
- Balanced profile – protection with minimal risk of blocking legitimate traffic.
- Specialised profiles – form protection, anti-hotlinking, and restrictions for specific endpoints.
3. IP Blacklist Manager
Manual blocking of IP addresses and ranges.
- IPv4 / IPv6 / CIDR support – utility for defining entire subnetworks.
- Quick deployment – instantaneous rule saving to .htaccess.
4. Backup Manager
Automated management of .htaccess file copies.
- Pre-change snapshot – saving a security version before any modification.
- Retention control – deletion of outdated copies to save storage space.
5. Log Tracking (Event Monitoring)
Built-in server access log reader directly within the administrative panel.
- Real-time analysis – preview of IP addresses and bots rejected by the firewall (403 Forbidden responses).
- Convenient diagnostics – comprehensive monitoring of malicious traffic from the Back Office, without the need for server console (SSH) usage.
Front Office Features
1. Strictly Server-Side Operation
No additional JavaScript and zero impact on page weight.
- Pre-PHP filtration – rejection of requests at the Apache/LiteSpeed level.
- CAPTCHA-free – genuine customers are not burdened with supplementary tests.
2. Form and Search Abuse Restriction
Blocking of mass queries that generate excessive load.
- Search/Filter Flooding control – restriction of automated queries and manipulated referrers.
Impact on Sales and SEO
Rejecting unwanted traffic prior to executing MySQL queries reduces server response time (TTFB) and stabilises shop performance during traffic spikes.
Blocking artificial crawling and resource scanning aids in recovering the crawl budget and improves the quality of analytical data by eliminating empty sessions.
Important Information
Best practices: Although the module is safe and creates its own snapshots, we encourage performing a standard backup of your firewall file (.htaccess) and the database before the first use. Furthermore, please note that the built-in access log reader is an optional and auxiliary feature – due to the varied configurations and restrictions of individual hosting providers, we cannot guarantee its operability on every server environment.
Disclaimer of Liability
Legal & SEO Notice: The software is provided "as-is". This module directly interacts with the server's network traffic filtration logic (application layer). The purchaser (administrator) assumes full responsibility for any unwarranted modifications, manual IP scope blocks, or misconfigured traffic restrictions. Incorrect configuration may result in blocking legitimate customers and strictly preventing vital search engine crawler operations (e.g., Googlebot), potentially leading to severe SEO ranking drops or Google de-indexing. Always verify your website's accessibility via external performance tools, such as the fetch validation in Google Search Console, immediately after deploying new rules. The module creators and authors bear no liability for consequential damages, loss of profits, administrative configuration errors, or decline in overall search engine visibility resulting from the use of this product.
Write your review