How to disable right-click on your Shopify store (but you probably shouldn’t)

Right-click disabling is a deterrent, not real security. Here’s the JavaScript snippet, how to add it, and better approaches to protecting your digital files.

Beka Rice Avatar

Author

Published

Category

Display

If you sell digital products on Shopify, you’ve probably wondered whether you can stop visitors from right-clicking and saving your files. It’s one of the most common questions we see — and the short answer is: you can, but it won’t actually protect your content.

Right-click disabling is a visual deterrent, not a security measure. We don’t recommend it as a protection strategy, and we’ll explain why below. But if you still want to add it as a lightweight deterrent, we’ll walk you through the code and how to install it on your Shopify store.

Why disabling right-click isn’t real protection

Right-click disabling stops casual users from opening the browser context menu. That’s all it does. Anyone with basic browser knowledge can bypass it in seconds — opening DevTools with F12, viewing page source with Ctrl+U, or using a browser extension that re-enables context menus. On mobile, long-press behavior varies by browser and can’t be reliably blocked either.

More importantly, disabling the context menu breaks legitimate functionality your visitors rely on: opening links in new tabs, using password managers, accessing accessibility tools, and basic text selection. It frustrates people and makes your site feel hostile — which is the opposite of what you want when you’re trying to sell something.

If you’re selling digital files — PDFs, audio, video, images — client-side JavaScript can’t prevent a determined user from downloading them. The file has to reach the browser for the user to view or play it. Once it’s there, it can be saved. No amount of right-click blocking changes that.

That said, if you still want a lightweight deterrent for casual visitors who don’t know their way around DevTools, here’s how to do it properly.

The JavaScript snippet

If you’ve seen older tutorials on this topic, they probably used window.oncontextmenu = function() { return false; }. That approach works, but it overwrites any other context menu handlers on the page — which can break theme functionality or other apps. Here’s a cleaner modern version using addEventListener:

document.addEventListener('contextmenu', function(e) {
  e.preventDefault();
});

This prevents the right-click context menu from appearing anywhere on the page.

If you’d rather be more targeted — for example, only disabling right-click on images so visitors can still use the context menu everywhere else — you can scope it to specific elements:

document.querySelectorAll('img').forEach(function(img) {
  img.addEventListener('contextmenu', function(e) {
    e.preventDefault();
  });
});

This second approach is better for most stores because it doesn’t interfere with normal right-click behavior on the rest of your site — links, text, and form fields all work as expected.

How to add this to your Shopify theme

To add either snippet to your Shopify store, you’ll create a snippet file in your theme and include it in your layout. Here’s the step-by-step:

  1. In your Shopify admin, go to Online Store → Themes.
  2. On your active theme, click the ⋯ menu and select Edit code.
  3. In the sidebar under Snippets, click Add a new snippet. Name it disable-right-click.
  4. Paste the following into the new snippet file:
<script>
  document.addEventListener('contextmenu', function(e) {
    e.preventDefault();
  });
</script>

Or, if you only want to target images:

<script>
  document.addEventListener('DOMContentLoaded', function() {
    document.querySelectorAll('img').forEach(function(img) {
      img.addEventListener('contextmenu', function(e) {
        e.preventDefault();
      });
    });
  });
</script>
  1. Open your theme’s layout/theme.liquid file.
  2. Add {% render 'disable-right-click' %} just before the closing </body> tag.
  3. Click Save.

The snippet will now load on every page of your store. If you ever want to remove it, just delete the {% render 'disable-right-click' %} line from your layout file.

A better approach to protecting digital files

If you’re selling digital products on Shopify, disabling right-click is treating a symptom, not the cause. The real question is how your files are delivered — and whether customers can access them outside of controlled conditions.

That’s the problem Fileflare solves. Instead of client-side workarounds that any browser can bypass, Fileflare handles file protection at the infrastructure level:

  • Streaming-only mode lets customers view video, audio, and PDF files directly in the browser without a download button — so the file is never offered as a download in the first place.
  • Expiring download links ensure that shared URLs stop working after a set number of downloads or days, so a leaked link can’t be used indefinitely.
  • IP address restrictions limit downloads to a set number of unique IP addresses per order, preventing a single link from being shared widely.
  • PDF watermarking automatically stamps each downloaded PDF with the buyer’s name, email, or order number at download time — a strong deterrent against redistribution even if someone does save the file.

None of these require editing your theme or adding JavaScript. They work automatically for every order, and they’re meaningfully more effective than blocking a context menu. If protecting your digital content matters to your business, you can start with Fileflare for free.