Starship
starship / search / abandoned-cart-reminder

Audit report

Abandoned Cart Reminder

Broad accessReach : broad

by SpurIT · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Bring Back Your Store Visitors with Abandoned Cart Reminds

Key insights

  • Tab-switching detection app focused on cart abandonment popups; functionally narrow scope
  • Publisher SpurIT operates from spur-i-t.com on Apache 2.4.29 (Ubuntu) without HSTS/CSP
  • Privacy policy acknowledges GDPR but omits retention timeframe and SOC2/ISO27001 certs
  • Data transferred to Canada and United States; no EU residency option declared

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Bring Back Your Store Visitors with Abandoned Cart Reminds

Key insights
  • Tab-switching detection app focused on cart abandonment popups; functionally narrow scope
  • Publisher SpurIT operates from spur-i-t.com on Apache 2.4.29 (Ubuntu) without HSTS/CSP
  • Privacy policy acknowledges GDPR but omits retention timeframe and SOC2/ISO27001 certs
  • Data transferred to Canada and United States; no EU residency option declared
  • Sub-processors include Amplitude (analytics) and Inspectlet (session replay)
  • No 'Built for Shopify' badge; only 6 public reviews
  • No public breach, CVE, or incident history surfaced via web search
  • No LLM/AI processing disclosed

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_online_store_pages
Low

L'app doit lire le contexte de la vitrine pour détecter les changements d'onglet et personnaliser le titre affiché, induit de la fonction déclarée de l'app.

read_themes
Low

L'app doit accéder au thème pour intégrer le comportement d'affichage sur les pages de la boutique, induit de la fonction déclarée de l'app.

write_themes
Medium

L'app injecte un comportement dynamique dans la vitrine, ce qui nécessite de modifier le thème, induit de la fonction déclarée de l'app.

write_script_tags
Medium

Le suivi des changements d'onglet et l'effet de clignotement du titre requièrent l'insertion d'un script côté vitrine, induit de la fonction déclarée de l'app.

read_products
Low

L'app peut lire les produits liés aux paniers abandonnés pour contextualiser le rappel, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
spur-i-t.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS responds 200 with valid cert; no HSTS, no CSP; Access-Control-Allow-Origin: * set on root; Apache/2.4.29 version disclosed

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy references GDPR rights for EU residents but does not list SOC2, ISO27001, or PCI DSS certifications, and omits an explicit data retention period.

Privacy policy
Track record

Publisher reputation

Publisher
SpurIT
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.