whats-best.ai

E-Commerce Platforms & Shop Systems

PrestaShop

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by PrestaShop SA · www.prestashop.com

Compare with OXID eSales → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

PrestaShop is an open-source shop system from PrestaShop SA, Paris. Its highest scores are extensibility at 6-8 and data control and exit at 7-8; the lowest are catalog and checkout at 2-4, sovereignty at 2-3 and pricing transparency at 0-2. What the pages show is a developer platform: an Admin API on API Platform version 3 with OAuth2 and Swagger documentation, CQRS extension points, native modules on Composer with source on GitHub, and managed hosting with Git integration and dev, staging and production environments. Exit is documented at the database level — full backups of files and database through mysqldump or PhpMyAdmin, automated by the Update Assistant module. The low areas reflect what we found no public information on: payment methods, variants and bundles at checkout, anything beyond hand-configured taxes, hosting location and subprocessors. The judges spread on catalog and checkout, 2-4 — those crediting the native One Page Checkout bundled in 9.2 score high, those weighing missing merchandising evidence score low — and on pricing transparency, 0-2. The vendor publishes no prices.

Report an error

Speaks for it

  • Native One Page Checkout module included in the PrestaShop 9.2 bundle, with documentation for keeping modules and themes compatible with it.
  • Admin API on API Platform version 3 with OAuth2, Swagger documentation, and new endpoints creatable via CQRS.
  • Modules install, uninstall and upgrade from the back office, with native modules managed by Composer and source code on the GitHub PrestaShop organization.
  • Managed hosting developed by PrestaShop adds Git integration with dev, staging and production environments.
  • Documented full backup of files and database — mysqldump, PhpMyAdmin, ZIP/TAR archives over FTP, SSH, RDP, scp or rsync — automated by the Update Assistant module.

Report an error

Held against it

  • No public information on payment methods, guest checkout, variants, bundles or tiered pricing in the captured checkout pages.
  • Taxes are configured by hand through rates and rules-group commands, with no public information on VAT-ID validation, reverse charge, OSS or e-invoicing.
  • The captured tax documentation warns it covers the outdated version 8 while the product is on 9, and the vendor's German-language site is no longer available.
  • Managed hosting is offered by PrestaShop with no stated location, and no subprocessor list appears on the captured pages.
  • No public information on multi-warehouse stock, carrier label printing, or maintained ERP and accounting interfaces.

Report an error

Best for

  • You have in-house developers who want an open-source core, a Swagger-documented OAuth2 Admin API and module source on GitHub to build on.
  • You want to self-host and hold a documented exit path — full files-and-database backups with your own tools on infrastructure you control.
  • You take phone orders or sell on account and need a back office that creates orders from carts, records payments and issues returns.
  • You are willing to configure taxes yourself and build carrier and ERP connections through custom modules.

Report an error

Avoid if

  • You need destination-based VAT, VAT-ID validation with reverse charge, OSS reporting or e-invoicing handled by the platform rather than configured by hand.
  • Your operation depends on multi-warehouse stock, carrier label printing or maintained ERP and accounting interfaces.
  • You buy the managed hosting and need a stated data location or a subprocessor list you can hand a lawyer.
  • You need published prices to budget an annual cost before contacting the vendor.

Report an error

The scores

Catalogue & checkout

Show reasoning
How this is scored

Products, variants, pricing rules and the path to payment — the part that either converts or does not.

0 — Flat product list with one price and no variants; checkout is a form and one payment method.

3 — Variants and categories with a standard checkout and two or three payment methods, but no bundles, no tiered pricing and no guest checkout worth the name.

5 — Full variant matrix, product bundles, tiered and customer-group pricing, guest checkout, and the payment methods a German shop needs including invoice and direct debit.

8 — Configurable products, per-channel pricing, promotions and vouchers with rules, a checkout that can be customised without a rebuild, and payment via the major providers plus buy-now-pay-later where offered.

10 — Merchandising and checkout are the product: rule-driven pricing and promotions, A/B-testable checkout, multi-currency and multi-language as standard, and conversion features (abandoned cart, one-page checkout) shipped rather than bolted on.

Report an error

The Merchant

The 9.2 release ships a native one-page checkout that pulls the whole purchase onto a single page, with developer documentation for adapting modules and themes to it — a checkout I can reshape without a rebuild. But we found no public information on the payment methods German shoppers expect such as invoice and direct debit, nor on variants, bundles, tiered pricing or promotions with rules, so I cannot credit conversion machinery beyond that. 4

Report an error

The B2B Seller

The captured pages show a native one-page checkout bundled with version 9.2 plus developer guidance for making modules and themes compatible with it — a real conversion feature. Beyond that we found no public information on variants, bundles, tiered or customer-group pricing, payment methods, or net-price display for trade customers, so I cannot confirm this shop meets a business buyer at checkout. 4

Report an error

The Developer

The captured pages do show a native One Page Checkout shipped in the 9.2 bundle, with documentation telling module and theme developers how to keep their solutions compatible — a real conversion feature and a checkout I can customise without a rebuild. Beyond that I found no public information on variants, bundles, tiered pricing, payment methods, promotions, or multi-currency, so the merchandising side of this criterion rests on nothing visible here. 4

Report an error

The Operations Lead

PrestaShop 9.2 ships a native one-page checkout with developer documentation for making modules and themes compatible with it, which is a genuine conversion feature. Beyond that I found no public information on variants, bundles, tiered or customer-group pricing, guest checkout, or which payment methods sit inside that checkout. A checkout I can see on one page but cannot price or pay through on paper sits in the low band. 4

Report an error

The Data Protection Officer

A native one-page checkout shipped in the 9.2 bundle is the strongest captured fact here, with cart-rule commands that let vouchers act on orders; we found no public information on payment provider coverage, guest checkout, variants, bundles or tiered pricing on the captured pages. 4 10

Report an error

The Skeptic

One bright spot in the evidence: PrestaShop 9.2 ships a native One Page Checkout module in the bundle, with developer documentation for making modules and themes checkout-compatible, and payments attach through payment modules in the order commands. Beyond that we found no public information on variants, bundles, tiered pricing, or which payment methods a merchant actually gets at the till. 4 10

Report an error

Extensibility & developer surface

Show reasoning
How this is scored

Themes, apps, APIs and headless — whether the shop can be shaped to the business, and at what cost in lock-in.

0 — Fixed templates, no app ecosystem, no API.

3 — Theme editing within limits and a small app store; a read-mostly API and no local development story.

5 — Custom themes with a template language, an app or plugin ecosystem, a documented REST API, and webhooks for the core order events.

8 — Full storefront API for headless builds, an extension framework with its own lifecycle, staging environments, version control for themes, and documented rate limits.

10 — A platform a team can own: headless-first APIs, open-source or source-available core, plugin architecture with a real dependency model, local development and CI supported, and upgrade paths that do not orphan customisations.

Report an error

The Merchant

This is the part I care about: a module ecosystem with native module source code on the GitHub organization, install and upgrade from the back office, and an Admin API on API Platform 3 with OAuth2, Swagger documentation and new endpoints creatable via CQRS — plus Git integration and dev, staging and production environments in the hosted offering. We found no public information on a storefront API for headless builds, webhooks or documented rate limits, which keeps it below the top band. 7 8 2

Report an error

The B2B Seller

This is a genuine developer surface: an Admin API on API Platform 3 with OAuth2, Swagger documentation, CQRS endpoints and multi-shop context, a module ecosystem with install, uninstall and upgrade through a distribution API, Composer-managed native modules with source on GitHub, and a managed hosting tier with Git integration and separate dev, staging and production environments. We found no public information on a storefront API for headless builds or documented rate limits, which is what separates this from the top band. 7 8 2

Report an error

The Developer

This is what I judge a platform on, and it holds up: open-source core, native modules managed by Composer with per-version compatibility listings served through a Distribution API client I can replace, and an Admin API on API Platform 3 with OAuth2, Swagger documentation and CQRS so I can build my own endpoints. The managed hosting tier adds Git integration with dev, staging and production environments, which is the closest thing to theme version control in this capture. I found no public information on a headless storefront API, documented rate limits, or a local-development and CI story, which is what keeps it from the top band. 7 8 2

Report an error

The Operations Lead

This is a real developer platform: modules install, uninstall and upgrade from the back office, native modules are Composer-managed with source on GitHub, the Admin API is documented with Swagger, OAuth2 and multi-shop context, developers can add endpoints through CQRS, and the cloud offering has Git integration with dev, staging and production environments. I found no public information on a storefront API for headless builds, webhooks for core order events, or documented rate limits — precisely the surface an ERP connection lives on. 7 8 2

Report an error

The Data Protection Officer

An OAuth2, Swagger-documented Admin API with CQRS extension points, a module ecosystem installable from the back office with native module source on GitHub, and Git-integrated dev, staging and production environments make a credible developer surface; we found no public information on a storefront or headless API, webhooks, or documented rate limits. 7 8 2

Report an error

The Skeptic

The strongest ground in the file: an Admin API on API Platform with Swagger documentation and OAuth2, endpoints developers can extend through CQRS, a module lifecycle of install, uninstall and upgrade in the back office, native modules on Composer with source on GitHub, and Git with dev, staging and production environments on the managed hosting. We found no public information on a storefront API for headless builds, version control for themes, or documented rate limits. 8 7 2

Report an error

Order operations & back office

Show reasoning
How this is scored

What happens after checkout: order management, stock, returns, shipping, and the link to ERP or accounting.

0 — An order list and an email; stock is a number nobody trusts, returns are manual.

3 — Order statuses and basic stock, one shipping integration, and returns handled by hand.

5 — Order workflow with partial shipments, multi-warehouse stock, named carrier integrations with label printing, and a returns process in the system.

8 — Multi-channel order intake, automated fulfilment routing, supplier and dropshipping flows, and maintained interfaces to named ERP and accounting systems.

10 — The shop is the front of an operation: real-time stock across channels and warehouses, returns and refunds fully worked including partials, ERP integration the vendor maintains, and operational reporting a merchant runs the business from.

Report an error

The Merchant

The order back office is genuinely worked: I can create an order from a cart, add payments and products afterwards, change statuses in bulk, issue a merchandise return, update carrier and tracking number and keep internal notes, with prices tracked both tax-included and tax-excluded. We found no public information on multi-warehouse stock, carrier label printing or maintained links to ERP and accounting systems, which is what separates a shop from an operation. 10 9

Report an error

The B2B Seller

The back office can create an order from an existing cart, record a payment with method, amount and transaction id, add products priced both tax-included and tax-excluded, change statuses in bulk, set internal notes, issue a merchandise return and update carrier and tracking number — enough for phone orders and payment on account. We found no public information on stock and warehouse handling, carrier label printing, or maintained interfaces to ERP and accounting systems. 9 10

Report an error

The Developer

The order domain is genuinely deep — back-office order creation, added payments, product-level edits carrying both tax-included and tax-excluded values, bulk status changes, internal notes, return issuance, and shipping updates with carrier and tracking — so order workflow and returns live in the system rather than in a mailbox. I found no public information on multi-warehouse stock, named carrier integrations with label printing, or maintained ERP and accounting interfaces, which is what the upper band demands. 10 9

Report an error

The Operations Lead

The order domain is worked, not decorative: orders can be created from the back office, payments added, products added with tax-included and tax-excluded prices, individual products cancelled, returns issued, carrier and tracking number updated, internal notes set and statuses changed in bulk. But December is made of the rest, and I found no public information on stock across warehouses or channels, partial shipments, carrier label printing, refunds including partials, or maintained interfaces to named ERP and accounting systems. Order machinery yes; a fulfilfulment operation not evidenced. 9 10

Report an error

The Data Protection Officer

The order domain is genuinely built out — orders can be created in the back office, products added or cancelled individually, statuses changed in bulk, returns issued, shipping and tracking numbers updated, and internal notes kept out of the storefront; we found no public information on stock or warehouse management, carrier integrations with label printing, or ERP and accounting interfaces. 9 10

Report an error

The Skeptic

The order back office is real work, not an order list and an email: back-office order creation, adding products and payments to existing orders, cancelling individual products, bulk status changes, issuing returns, updating carrier and tracking number, and internal notes visible only in the back office. Around it we found no public information on stock across warehouses, named carrier integrations, label printing, or interfaces to ERP and accounting systems. 9 10

Report an error

Data ownership & exit

Show reasoning
How this is scored

Whether the catalogue, customers and order history remain the merchant's: export completeness, hosting choice, and what leaving actually costs.

0 — Export is a partial CSV; order history and customer records cannot leave intact, and hosting is the vendor's alone.

3 — CSV export of products and customers, order history partial, no self-hosting, no documented migration path.

5 — Complete export of catalogue, customers and orders via API or dump, documented deletion, and a stated data-return commitment.

8 — Full-fidelity export including media and order documents, self-hosting or a choice of hosting partner, and no metering that prices a migration out of reach.

10 — Ownership is structural rather than promised: open-source or source-available platform the merchant can run anywhere, database-level access, documented migration in both directions, and contractual data return.

Report an error

The Merchant

The backup documentation assumes my server and walks through a full dump of files and database with standard tools — mysqldump, phpMyAdmin, SSH, rsync — plus automated backup via the Update Assistant module, so catalogue, customers and order history leave with me at the database level, with a CSV export component documented on top. We found no public information on a documented migration path in both directions or a contractual data-return commitment, so I stop short of the top. 12 11

Report an error

The B2B Seller

Leaving is well documented: back up files and database, with mysqldump or phpMyAdmin for a full dump, ZIP or TAR archives moved over FTP, SSH, RDP, scp or rsync, and an Update Assistant module that automates the backup from the back office or CLI — on a platform whose source is public and which also offers managed hosting. We found no public information on documented deletion, a stated data-return commitment, or a migration path in either direction. 12 11 2

Report an error

The Developer

Ownership is structural rather than promised: open-source software, a documented full backup of files and database through mysqldump or standard hosting tools, automated by the Update Assistant, so catalogue, orders and media can leave intact on my schedule. The only export component documented is a CSV response at framework level, and I found no public information on a documented migration path back in or a contractual data-return commitment, which caps it below the top. 12 11 2

Report an error

The Operations Lead

Exit is credible: the documentation spells out backing up files and database, with mysqldump, PhpMyAdmin, several MySQL clients, compressed archives over FTP, SSH or rsync, and backup automation through the Update Assistant module from the back office or CLI. Releases are published with download links and module source sits on GitHub, so the merchant can run the shop on their own infrastructure, and an export component with CSV response handling is part of the core reference. That is full-fidelity export at the database level rather than a promised CSV. 12 11 7

Report an error

The Data Protection Officer

Exit is structural rather than promised — the core is open source with module source published, and the documented backup covers the complete files plus a full database dump via mysqldump or phpMyAdmin, so catalogue, customers and order history can leave intact; we found no public information on a documented deletion routine for order history or a contractual data-return commitment. 7 11 12

Report an error

The Skeptic

Leaving looks cheap, which is rare: the backup documentation walks a merchant through taking the entire files and database with their own tools — mysqldump, PhpMyAdmin, SSH, scp, rsync, ZIP or TAR archives — on a server their hosting provider controls, with an Update Assistant module to automate it, and a CSV export component exists at framework level. We found no public information on contractual data-return commitments or a documented migration path in both directions. 12 11

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where customer and order data live, who the contracting entity is, and which subprocessors sit in the checkout path. Independently sourced by the sovereignty pipeline.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — CDN, analytics, payment routing, support tooling — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that puts the shop entirely under the merchant's control.

Report an error

The Merchant

PrestaShop S.A appears as the data controller in the newsletter consent and the hosting is a managed service developed by PrestaShop, but there the trail ends: we found no public information on where that hosting runs, on data-residency guarantees, or on any subprocessor list for the checkout path that I could hand a lawyer. The published subprocessor information is absent, and the vendor publishes no sovereignty statement for its own services. 1 2

Report an error

The B2B Seller

The company presents as Paris-based and names PrestaShop S.A as the controller for its own newsletter, and managed hosting is offered — but we found no public information on where shop and checkout data are hosted, the jurisdiction of the contracting entity, ownership, or any named subprocessor. For a trade customer's order data I want more on the page than that. 1 2

Report an error

The Developer

The controller named in the consent text is PrestaShop S.A and the provenance places the vendor in Paris under Italian majority ownership, but the managed hosting pages state no data-residency location, and I found no public information on subprocessors anywhere in the checkout path. An absent subprocessor list plus unstated hosting location leaves the hosted chain unverifiable from these pages; only the self-hosted, open-source route would put it under my own control. 1 2

Report an error

The Operations Lead

The captured pages give me PrestaShop S.A named as newsletter controller and a managed hosting service developed by PrestaShop that adds resources on demand — but I found no public information on where that hosted data resides, which infrastructure carries it, or any subprocessor list. Where my customers' and orders' data physically sits and who processes it is unanswered on these pages. 1 2

Report an error

The Data Protection Officer

The captured pages publish no subprocessor list, no data-residency statement and nothing on where CDN, analytics or payment routing sit, and the only consent artifact captured names PrestaShop S.A as controller for the vendor's own newsletter; managed hosting is offered by PrestaShop with no stated location, and although the open-source platform can run on the merchant's own server, nothing captured evidences EU-standard hosting or named infrastructure. 1 2 12

Report an error

The Skeptic

An EU entity is on the record — the homepage's newsletter consent names PrestaShop S.A as controller — but that is where the trail ends, with the managed hosting described as developed by PrestaShop and no location stated. We found no public information on where shop and order data reside, or on any subprocessor sitting in the checkout path. 1 2

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a merchant can compute the real annual cost — licence, transaction fees, apps, hosting — from public pages alone. The category where the headline price is least often the invoice.

0 — No public prices at all; every tier is a sales conversation.

3 — A monthly headline exists, but transaction fees, mandatory apps or hosting costs are unstated — the invoice is unknowable from the page.

5 — Tier prices public with billing period stated and transaction fees given, but at least one commonly needed piece (a required app, hosting, payment gateway rate) is unpriced.

8 — Every tier priced publicly including transaction or revenue-share rates, order or GMV limits, and the cost of the extensions most shops need; VAT treatment and minimum term stated.

10 — Complete price computability: annual cost derivable for a given order volume and GMV including licence, transaction fees, hosting and typical extensions — and for open-source platforms, an honest statement that the licence is free and where the money actually goes.

Report an error

The Merchant

The platform is open source, so the licence itself carries no fee — and that is the only cost fact I have: the captured hosting page describes managed hosting, on-demand resources and development environments without a single price, and we found no public information on transaction fees, marketplace module costs, order limits or term and VAT conditions. A merchant trying to compute a real annual cost from these pages cannot. 2 7

Report an error

The B2B Seller

No captured page states a price of any kind — not for managed hosting, not for modules, not a transaction fee — so a merchant cannot compute an annual cost from public pages alone. The open-source distribution implies the licence itself is free, but we found no public statement of what the hosting or the extensions a real shop needs actually cost. 2 7

Report an error

The Developer

None of the captured pages states a price — no licence tiers, no hosting cost, no transaction fees, no module pricing — so a real annual cost cannot be computed from what is public here. The hosting page describes scalability and tooling without a single figure, and even for an open-source licence I found no captured statement of where the money actually goes. 2 1

Report an error

The Operations Lead

I found no public pricing information at all: the captured hosting page describes managed hosting, cache systems and scalability in detail without stating a price, billing period, transaction fee or VAT treatment, and no other captured page carries a figure. A merchant cannot compute even the licence line of an annual cost from these pages. 1 2

Report an error

The Data Protection Officer

The captured pages contain no prices at all — not for managed hosting, not for modules — so a merchant cannot compute an annual cost from anything public; the downloadable releases and GitHub-hosted modules show the licence itself is free, but we found no public statement of where the money actually goes. 2 7

Report an error

The Skeptic

We found no public information on prices of any kind — not a licence figure, not a hosting price for the managed service, not a module cost, not a transaction fee — so a merchant cannot begin to compute the real invoice from these pages. The captured hosting page describes on-demand resources and staging environments without stating what any of it costs. 2 1

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (12)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.prestashop.com Checked 15 Sep 2026 Details →
  2. 2 Security / trust page prestashop.com Checked 30 Sep 2026 Details →
  3. 3 Catalogue & checkout — found from sitemap prestashop.com Checked 1 Oct 2026 Details →
  4. 4 Catalogue & checkout — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  5. 5 Tax & German legal correctness — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  6. 6 Tax & German legal correctness — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  7. 7 Extensibility & developer surface — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  8. 8 Extensibility & developer surface — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  9. 9 Order operations & back office — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  10. 10 Order operations & back office — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  11. 11 Data ownership & exit — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →
  12. 12 Data ownership & exit — found from sitemap devdocs.prestashop-project.org Checked 1 Oct 2026 Details →