How to Disable Right-Click on Shopify (and Its Limits)
Can you disable right-click on Shopify?
Yes. You can add a short script to your Shopify theme that cancels the right-click menu, copying and image dragging, or use an app that does the same without editing code. Either way it only slows casual copying: screenshots, phone cameras and anyone reading your public product data still get through.
Note: The Shopify settings, labels and theme behaviour on this page were checked against Shopify’s documentation on 26 September 2026.
The Shopify admin has no setting for this, so the choice is between a few lines of theme code and an app. The code costs nothing but lives in one theme’s files. An app is easier to switch off and stays in place when you update your theme, but it adds its own script to every page. Both rely on JavaScript running in the shopper’s browser, so both share the limits described in what right-click protection can’t stop.
How do I do it with code?
Paste the script below into layout/theme.liquid. Shopify requires that file in every theme and uses it for the markup repeated across page types, so one paste covers your storefront (Shopify’s layout documentation).
<script>
(function () {
// Form fields keep working: shoppers can still right-click to paste or spell-check.
function inField(target) {
return target instanceof Element && target.closest('input, textarea') !== null;
}
// Cancel the right-click menu (and the keyboard's menu key) outside form fields.
document.addEventListener('contextmenu', function (event) {
if (!inField(event.target)) event.preventDefault();
});
// Stop page text being copied. Text typed into a field can still be copied.
document.addEventListener('copy', function (event) {
if (!inField(event.target)) event.preventDefault();
});
// Stop images being dragged out of the page.
document.addEventListener('dragstart', function (event) {
if (event.target instanceof HTMLImageElement) event.preventDefault();
});
})();
</script>
Add the script to your theme
- In your Shopify admin, go to Online Store.
- Make a backup first, as Shopify recommends: click ⋯ next to your current theme, then Duplicate. The copy appears on your Themes page.
- On your current theme, click ⋯, then Edit code. The code editor opens.
- In the layout folder, open
theme.liquid. - Find the closing
</body>tag near the end of the file and paste the script on the line just above it. - Click Save.
- Open your store in a private window and right-click a product image. No menu appears. Right-click inside a search or email field: the menu still works there.
What each part does
contextmenucancels the browser menu that opens on a right-click or on the keyboard’s menu key, which is where Save image as and Copy live. Form fields keep theirs.copystops selected page text reaching the clipboard, whether the shopper uses the keyboard or the browser’s Edit menu.dragstartstops a product photo being dragged to the desktop.
The script leaves text selection alone on purpose. People select text to translate it, look a word up or have it read aloud, and blocking selection breaks all three.
If you only care about photos, make it gentler: in the contextmenu handler, replace !inField(event.target) with event.target instanceof HTMLImageElement, and delete the copy handler. Text and links then behave normally, and only images lose their menu.
Important: Test any “copy discount code” button on your store after saving. Some are built on the browser’s copy command, which this script now cancels.
Keep it through theme updates
When you update your theme to a new version, Shopify carries your code edits across only if they don’t conflict with the update. If they’re missing, you copy them into the new version yourself, and Shopify advises saving a copy of customised code before any update (Updating themes). If you switch to a different theme, paste the script into that theme too. To remove it, delete the lines and click Save.
How do I do it with an app?
Install a content-protection app and switch on only the behaviours you need. An app that loads through a theme app embed needs nothing pasted, and Shopify copies app embed settings across when you update your theme.
X Shield, which we build, has a separate switch for each behaviour, all included on its Free plan (X Shield’s plans). Every protection starts off, and nothing runs until its app embed is on:
- Install X Shield and open it once.
- On the Overview, click Enable in theme. Your theme editor opens with the X Shield app embed switched on. Click Save.
- Back on the Overview, under Content & media, switch on Right-click on media. A toast says Feature enabled. This is the gentlest option: images can’t be saved with a right-click, and the menu keeps working on text and links.
- Switch on anything else from the table below only if you need it.
- To change or hide the small message visitors see when an action is refused, go to Blocked page → Protection alerts.
- Check the result in a private window.
| Switch | What it stops | What it costs your visitors |
|---|---|---|
| Right-click on media | Saving images and videos with a right-click | Little: the menu still works everywhere else |
| Media protection | Dragging or downloading images and videos | Can stop image zoom and video controls working in some themes |
| Right-click protection | The browser menu anywhere on the page | Opening links in a new tab, translating, spell-checking |
| Copy protection | Copying selected text | Copying an order number, your address or a discount code |
| Cut protection | Cutting selected text | Editing text in your own forms |
| Text selection protection | Selecting text at all | Translation and reading aids |
| Paste protection | Pasting into forms and fields | Pasting an address or email into your own forms: leave it off |
| Keyboard shortcut protection (under Browser tools) | Shortcuts that open developer tools and view source | Find, print and copy shortcuts, for every visitor |
For what each switch does in detail, see how to disable right-click with X Shield. Like the snippet, these switches need JavaScript, so the limits below apply to them too. The app also adds its own script to every page, so check your speed scores after you install it.
Tip: If copying is part of a wider scraping problem, X Shield, a free country and bot blocker for Shopify, also blocks countries, IP addresses and bots from the same admin.
What can’t right-click protection stop?
Anything that doesn’t go through the page’s own menu or clipboard. Treat it as friction for casual visitors, not copy-proofing:
- Screenshots and phone cameras. A web page can’t reliably prevent either.
- The browser’s own tools. View source, Save page as and developer tools all open from the browser’s menu, which a page script can’t reach. Turning JavaScript off removes the protection entirely.
- Firefox users holding Shift. In Firefox, Shift and right-click opens the menu without firing the event the script cancels (MDN: contextmenu event).
- iPhones and iPads. Safari on iOS doesn’t fire the right-click event at all (MDN’s compatibility data lists it as unsupported), so its long-press menu is unaffected by this script.
- Your image files. Every product photo has a public address that sits in your page source.
- Scrapers and spy tools. They request your catalogue as data, for example from Shopify’s product JSON, and never run your script. See what Shopify spy tools can see.
When someone does copy your photos or descriptions onto another Shopify store, the remedy that works is a copyright complaint. Shopify responds to claims of copyright infringement using DMCA procedures and takes notices through an online form (Reporting copyright infringement). Your own photography, with the originals kept, makes that claim easy to prove.
Does it hurt SEO or accessibility?
Not SEO. Search engines read your HTML and never right-click or copy, so neither the script nor an app changes what gets crawled or indexed, and your product photos can still appear in image search. Accessibility is the real cost, and it falls on your customers.
- Keyboard users. The keyboard’s menu key fires the same event as a right-click, so blocking one blocks both.
- Everyday tools. People use the right-click menu to open links in new tabs, translate a page, check spelling and look up words.
- Copying. Shoppers copy text into translation and reading tools, and copy details they need: an order number, your address, a discount code.
- Selecting. Some readers highlight text as they go. Blocking selection takes that away, which is why the snippet above leaves it alone.
- Pasting. Blocking paste stops people pasting an address or an email into your forms. It protects nothing, because pasting doesn’t copy anything from your store.
If you do protect content, protect images rather than text: block the menu on images only, leave copying and selection alone, and never block paste.