Helps Magento 2 websites comply with GDPR by adding cookie consent, privacy policy links, and consent checkboxes. Allows customers to delete their accounts and manage personal data.
IronCart Security Scanner for Magento 2
ironcartlabs/magento-scan 60
Read-only Magento 2 security scanner that runs whitebox checks — version/patch status, MAGE_MODE, admin URL, 2FA coverage, env.php permissions, Composer advisories, core file integrity, and more — and emits a structured JSON report with severities and remediation links.
Allows administrators to change customer passwords directly from the customer edit page in the admin panel. Includes a command-line interface for password updates.
This extension is adjusting the Cookie SameSite attribute issue since Chrome 80.
Magento2 Cookie2
punchout-catalogs/magento2-cookie2 20
Enables cookie sharing between Magento and external punchout catalogs. Facilitates seamless user authentication and data transfer for integrated procurement processes.
Looking for contributors - Help fix build issues
CLI tool that inspects and reports the Content-Security-Policy headers generated for a given Magento URL and policy, making CSP values easier to review than digging through the browser.
CustomGento_Cookiebot
customgento/module-cookiebot-m2 75
A Magento 2 module that integrates Cookiebot into your store.
Displays a customizable cookie notice to inform visitors about your privacy policy. Helps comply with cookie laws by requiring users to accept before proceeding.
Withdrawal Button for Magento 2
run-as-root/module-withdrawal 66
Implements the EU right of withdrawal (Directive (EU) 2023/2673) with a clearly visible withdrawal button, letting customers withdraw from purchase contracts from their account or via a guest search form, with deadline calculation, confirmation emails, and a full admin overview of withdrawals.
Withdrawal Button — Hyva Compatibility
run-as-root/module-withdrawal-hyva 66
Provides Hyva-compatible frontend templates (Tailwind CSS and Alpine.js) for the Withdrawal Button module, replacing its Luma/Knockout/RequireJS templates so the EU right-of-withdrawal workflow renders correctly on Hyva storefronts.
Enables configurable CORS Headers on GraphQL and REST APIs