Starship
starship / search / abandon-aid

Audit report

Abandon Aid

Broad accessReach : moderateSensitive Access

by Coolence · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Prevent cart abandonment! Simple, powerful and smart!

Key insights

  • Built for Shopify badge present, indicating adherence to Shopify performance and quality standards
  • Privacy policy is published and accessible at publisher's own domain
  • Publisher infrastructure hosted on Heroku (US/EU regions)
  • No documented breaches, CVEs, or security incidents for Coolence or Abandon Aid

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Prevent cart abandonment! Simple, powerful and smart!

Key insights
  • Built for Shopify badge present, indicating adherence to Shopify performance and quality standards
  • Privacy policy is published and accessible at publisher's own domain
  • Publisher infrastructure hosted on Heroku (US/EU regions)
  • No documented breaches, CVEs, or security incidents for Coolence or Abandon Aid
  • Indefinite data retention raises GDPR concern but acknowledges deletion-on-request
  • App scope is narrow (cart abandonment recovery) - limited attack surface

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_checkouts
High

Inferred from app purpose - required to detect abandoned carts and customer contact info

read_customers
High

Inferred - needed to send recovery notifications to identified customers

read_orders
High

Inferred - to detect order completion and stop recovery messages

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
abandonaid.coolence.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS works (HTTP/2 200), but no HSTS or CSP headers present. Hosted on Heroku.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy present but no explicit compliance certifications declared. Mentions cross-border transfer to Canada/US.

Privacy policy
Track record

Publisher reputation

Publisher
Coolence
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.