Audit report
Accentuate Custom Fields
Broad accessReach : broadSensitive Accessby Accentuate · Productivity · Shopify App Store
Unlimited fields for every aspect of your Shopify store
Key insights
- ◆Built for Shopify badge present, has passed Shopify's BFS quality bar
- ◆4.8 rating across 158 reviews, mature app
- ◆Publisher website is hosted on Shopify infrastructure (Cloudflare/GCP europe-west1), strong HTTPS posture with HSTS and CSP
- ◆No CVEs, breaches, or public security incidents found for Accentuate / Accentuate Digital
Top findingsview all
- HighBroad write scopes across multiple Shopify resources
Analysis summary
Unlimited fields for every aspect of your Shopify store
- ◆Built for Shopify badge present, has passed Shopify's BFS quality bar
- ◆4.8 rating across 158 reviews, mature app
- ◆Publisher website is hosted on Shopify infrastructure (Cloudflare/GCP europe-west1), strong HTTPS posture with HSTS and CSP
- ◆No CVEs, breaches, or public security incidents found for Accentuate / Accentuate Digital
- ◆Privacy policy is thin on specifics: no named sub-processors, no certifications, no defined retention period
- ◆Scope surface is broad for a metafields app (write to customers/orders/online store/admin)
- ◆No evidence of LLM/AI usage
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Includes sensitive customer data, device and activity data per app listing |
write_customers | High | Allows mutation of customer records |
read_users | Medium | Staff/contributor data exposure |
write_products | Medium | Core to metafield/custom-field functionality but enables product mutation |
write_orders | High | Order modification capability not strictly needed for a custom-fields app |
write_themes | High | Online Store edit access enables theme code modification and storefront injection |
write_metaobjects | Medium | Custom data edit, primary purpose of the app |
read_customersIncludes sensitive customer data, device and activity data per app listing
write_customersAllows mutation of customer records
read_usersStaff/contributor data exposure
write_productsCore to metafield/custom-field functionality but enables product mutation
write_ordersOrder modification capability not strictly needed for a custom-fields app
write_themesOnline Store edit access enables theme code modification and storefront injection
write_metaobjectsCustom data edit, primary purpose of the app
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- accentuate.io
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
Publisher marketing site is hosted on Shopify (Cloudflare edge, GCP europe-west1 origin). Strong headers: HSTS max-age ~91 days, CSP with frame-ancestors 'none' and upgrade-insecure-requests, x-frame-options DENY, x-content-type-options nosniff. Note: these headers reflect the marketing site, not necessarily the app backend.
Compliance & certifications
No formal certifications declared in privacy policy. Policy is generic and does not commit to GDPR/CCPA-specific procedures, named sub-processors, or defined retention windows.
Privacy policyPublisher reputation
- Publisher
- Accentuate
- Verified Shopify Partner
- Yes
- Years active
- 0
- Other apps
- 0