Starship
starship / search / ac-advanced

Audit report

AC Advanced

WatchReach : broad

by AIM Shopify Apps · Marketing · Shopify App Store

First-partyMarketing
Risk level
Watch
Executive summary

Connects your store with Active Campaign effortlessly

Key insights

  • App connects Shopify stores to ActiveCampaign (email marketing), typically requires read_customers, read_orders, write_customers.
  • Publisher 'AIM Shopify Apps' / 'AIM Apps' operating under apexsuite.com brand.
  • Privacy policy is on plain HTTP, no TLS, significant trust signal failure.
  • Single 1-star review and reports of unsolicited installations and double-charging.

Top findingsview all

  • High
    Privacy policy served over plain HTTP (no TLS)
  • High
    Reports of unauthorized app installation and recurring charges
Synthesis

Analysis summary

Connects your store with Active Campaign effortlessly

Key insights
  • App connects Shopify stores to ActiveCampaign (email marketing), typically requires read_customers, read_orders, write_customers.
  • Publisher 'AIM Shopify Apps' / 'AIM Apps' operating under apexsuite.com brand.
  • Privacy policy is on plain HTTP, no TLS, significant trust signal failure.
  • Single 1-star review and reports of unsolicited installations and double-charging.
  • No 'Built for Shopify' badge, no compliance certifications mentioned, no AI/LLM usage disclosed.
  • No public CVEs or confirmed breaches tied to AIM/apexsuite, but reputation and hygiene are weak.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Implied by ActiveCampaign sync use case; not verified on listing

write_customers
High

Implied for bidirectional contact sync; not verified on listing

read_orders
High

Likely needed for order-based email automations; not verified on listing

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
apps.apexsuite.com
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS reachable but neither HSTS nor CSP headers present; privacy policy link itself uses plain HTTP.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but is generic; no certifications referenced; breach notification commitment of 7 business days only.

Privacy policy
Track record

Publisher reputation

Publisher
AIM Shopify Apps
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.