# How to Disable Right-Click on Shopify (and Its Limits) {#post-title}

[X Shield](/blog/#blog-x-shield)

By [B2B Gold](/about/#how-we-write) Published 24 September 2026 Updated 26 September 2026

## Can you disable right-click on Shopify? {#can-you-disable-right-click-on-shopify}

Yes. You can add a short script to your Shopify theme that cancels the right-click menu, copying and image dragging, or use an app that does the same without editing code. Either way it only slows casual copying: screenshots, phone cameras and anyone reading your public product data still get through.

> **Note:** The Shopify settings, labels and theme behaviour on this page were checked against Shopify’s documentation on 26 September 2026.

The Shopify admin has no setting for this, so the choice is between a few lines of theme code and an app. The code costs nothing but lives in one theme’s files. An app is easier to switch off and stays in place when you update your theme, but it adds its own script to every page. Both rely on JavaScript running in the shopper’s browser, so both share the limits described in [what right-click protection can’t stop](#what-cant-right-click-protection-stop).

## How do I do it with code? {#how-do-i-do-it-with-code}

Paste the script below into `layout/theme.liquid`. Shopify requires that file in every theme and uses it for the markup repeated across page types, so one paste covers your storefront ([Shopify’s layout documentation](https://shopify.dev/docs/storefronts/themes/architecture/layouts)).

```
<script>
  (function () {
    // Form fields keep working: shoppers can still right-click to paste or spell-check.
    function inField(target) {
      return target instanceof Element && target.closest('input, textarea') !== null;
    }

    // Cancel the right-click menu (and the keyboard's menu key) outside form fields.
    document.addEventListener('contextmenu', function (event) {
      if (!inField(event.target)) event.preventDefault();
    });

    // Stop page text being copied. Text typed into a field can still be copied.
    document.addEventListener('copy', function (event) {
      if (!inField(event.target)) event.preventDefault();
    });

    // Stop images being dragged out of the page.
    document.addEventListener('dragstart', function (event) {
      if (event.target instanceof HTMLImageElement) event.preventDefault();
    });
  })();
</script>
```

### Add the script to your theme {#add-the-script-to-your-theme}

1. In your Shopify admin, go to **Online Store**.
2. Make a backup first, as Shopify [recommends](https://help.shopify.com/en/manual/online-store/themes/theme-structure/extend/edit-theme-code): click **⋯** next to your current theme, then **Duplicate**. The copy appears on your **Themes** page.
3. On your current theme, click **⋯**, then **Edit code**. The code editor opens.
4. In the **layout** folder, open `theme.liquid`.
5. Find the closing `</body>` tag near the end of the file and paste the script on the line just above it.
6. Click **Save**.
7. Open your store in a private window and right-click a product image. No menu appears. Right-click inside a search or email field: the menu still works there.

### What each part does {#what-each-part-does}

- `contextmenu` cancels the browser menu that opens on a right-click or on the keyboard’s menu key, which is where **Save image as** and **Copy** live. Form fields keep theirs.
- `copy` stops selected page text reaching the clipboard, whether the shopper uses the keyboard or the browser’s **Edit** menu.
- `dragstart` stops a product photo being dragged to the desktop.

The script leaves text selection alone on purpose. People select text to translate it, look a word up or have it read aloud, and blocking selection breaks all three.

If you only care about photos, make it gentler: in the `contextmenu` handler, replace `!inField(event.target)` with `event.target instanceof HTMLImageElement`, and delete the `copy` handler. Text and links then behave normally, and only images lose their menu.

> **Important:** Test any “copy discount code” button on your store after saving. Some are built on the browser’s copy command, which this script now cancels.

### Keep it through theme updates {#keep-it-through-theme-updates}

When you update your theme to a new version, Shopify carries your code edits across only if they don’t conflict with the update. If they’re missing, you copy them into the new version yourself, and Shopify advises saving a copy of customised code before any update ([Updating themes](https://help.shopify.com/en/manual/online-store/themes/managing-themes/updating-themes)). If you switch to a different theme, paste the script into that theme too. To remove it, delete the lines and click **Save**.

## How do I do it with an app? {#how-do-i-do-it-with-an-app}

Install a content-protection app and switch on only the behaviours you need. An app that loads through a theme app embed needs nothing pasted, and Shopify copies app embed settings across when you [update your theme](https://help.shopify.com/en/manual/online-store/themes/managing-themes/updating-themes).

X Shield, which we build, has a separate switch for each behaviour, all included on its Free plan ([X Shield’s plans](/shopify/x-shield/#pricing)). Every protection starts off, and nothing runs until its app embed is on:

1. Install X Shield and open it once.
2. On the **Overview**, click **Enable in theme**. Your theme editor opens with the X Shield app embed switched on. Click **Save**.
3. Back on the **Overview**, under **Content & media**, switch on **Right-click on media**. A toast says **Feature enabled**. This is the gentlest option: images can’t be saved with a right-click, and the menu keeps working on text and links.
4. Switch on anything else from the table below only if you need it.
5. To change or hide the small message visitors see when an action is refused, go to **Blocked page** → **Protection alerts**.
6. Check the result in a private window.

| Switch | What it stops | What it costs your visitors |
| --- | --- | --- |
| **Right-click on media** | Saving images and videos with a right-click | Little: the menu still works everywhere else |
| **Media protection** | Dragging or downloading images and videos | Can stop image zoom and video controls working in some themes |
| **Right-click protection** | The browser menu anywhere on the page | Opening links in a new tab, translating, spell-checking |
| **Copy protection** | Copying selected text | Copying an order number, your address or a discount code |
| **Cut protection** | Cutting selected text | Editing text in your own forms |
| **Text selection protection** | Selecting text at all | Translation and reading aids |
| **Paste protection** | Pasting into forms and fields | Pasting an address or email into your own forms: leave it off |
| **Keyboard shortcut protection** (under **Browser tools**) | Shortcuts that open developer tools and view source | Find, print and copy shortcuts, for every visitor |

For what each switch does in detail, see how to [disable right-click with X Shield](/docs/x-shield/content-protection/). Like the snippet, these switches need JavaScript, so the limits below apply to them too. The app also adds its own script to every page, so check your speed scores after you install it.

> **Tip:** If copying is part of a wider scraping problem, [X Shield, a free country and bot blocker for Shopify](/shopify/x-shield/), also blocks countries, IP addresses and bots from the same admin.

## What can’t right-click protection stop? {#what-cant-right-click-protection-stop}

Anything that doesn’t go through the page’s own menu or clipboard. Treat it as friction for casual visitors, not copy-proofing:

- **Screenshots and phone cameras.** A web page can’t reliably prevent either.
- **The browser’s own tools.** View source, **Save page as** and developer tools all open from the browser’s menu, which a page script can’t reach. Turning JavaScript off removes the protection entirely.
- **Firefox users holding Shift.** In Firefox, Shift and right-click opens the menu without firing the event the script cancels ([MDN: contextmenu event](https://developer.mozilla.org/en-US/docs/Web/API/Element/contextmenu_event)).
- **iPhones and iPads.** Safari on iOS doesn’t fire the right-click event at all (MDN’s compatibility data lists it as unsupported), so its long-press menu is unaffected by this script.
- **Your image files.** Every product photo has a public address that sits in your page source.
- **Scrapers and spy tools.** They request your catalogue as data, for example from Shopify’s product JSON, and never run your script. See [what Shopify spy tools can see](/blog/shopify-spy-tools/).

When someone does copy your photos or descriptions onto another Shopify store, the remedy that works is a copyright complaint. Shopify responds to claims of copyright infringement using DMCA procedures and takes notices through an online form ([Reporting copyright infringement](https://help.shopify.com/en/manual/compliance/intellectual-property/copyright-policy)). Your own photography, with the originals kept, makes that claim easy to prove.

## Does it hurt SEO or accessibility? {#does-it-hurt-seo-or-accessibility}

Not SEO. Search engines read your HTML and never right-click or copy, so neither the script nor an app changes what gets crawled or indexed, and your product photos can still appear in image search. Accessibility is the real cost, and it falls on your customers.

- **Keyboard users.** The keyboard’s menu key fires the same event as a right-click, so blocking one blocks both.
- **Everyday tools.** People use the right-click menu to open links in new tabs, translate a page, check spelling and look up words.
- **Copying.** Shoppers copy text into translation and reading tools, and copy details they need: an order number, your address, a discount code.
- **Selecting.** Some readers highlight text as they go. Blocking selection takes that away, which is why the snippet above leaves it alone.
- **Pasting.** Blocking paste stops people pasting an address or an email into your forms. It protects nothing, because pasting doesn’t copy anything from your store.

If you do protect content, protect images rather than text: block the menu on images only, leave copying and selection alone, and never block paste.

[X Shield: IP Country Blocker](/shopify/x-shield/)

X Shield is a Shopify app that blocks visitors by country, IP address or network, and turns away the bots, VPNs and spy extensions it detects, showing them a blocked page instead of your store. Googlebot and Bingbot, checked against their published IP ranges, still get in, and dry run lets you test every rule before it blocks anyone.

[Install free on the Shopify App Store](https://apps.shopify.com/x-shield-store-guard?utm_source=b2bgold.app&utm_medium=referral&utm_campaign=blog&utm_content=blog/disable-right-click-shopify&utm_term=post-cta) [Plans and pricing](/shopify/x-shield/#pricing) [X Shield docs](/docs/x-shield/) [How X Shield compares with Blockify](/compare/x-shield-vs-blockify/)

Need help with X Shield? Email [support@b2bgold.app](mailto:support@b2bgold.app).

## More on X Shield {#related-heading}

- 24 September 2026 **[What Shopify Spy Tools Can See and How to Limit It](/blog/shopify-spy-tools/)** PPSPY and Koala Inspector estimate your sales from public store data. What Shopify spy tools really see, what you can hide, and what blocking can't stop.
- 24 September 2026 **[John Doe Abandoned Checkouts on Shopify: How to Stop Them](/blog/shopify-fake-abandoned-checkouts/)** Hundreds of John Doe abandoned checkouts usually mean card testing. The Shopify settings that stop it, what a storefront blocker can't do, and how to clean up.
- 24 September 2026 **[Shopify High Risk of Fraud Detected: What to Do](/blog/shopify-high-risk-orders/)** What Shopify's high-risk flag means, how to verify an order before it ships, when to hold or cancel it, and how storefront signals like VPN visits help decide.
