Starship
starship / search / accessibility-by-appifycommerce

Audit report

Accessibility Toolkit

TrustedReach : broad

by Appify Commerce · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

Help your customers with a unique and responsive toolkit

Key insights

  • Built for Shopify badge present, indicating Shopify-vetted
  • 5.0 rating with 18 reviews (small sample size)
  • Privacy policy mentions only Shopify and Google Analytics as third parties
  • Publisher domain protected by Cloudflare with HSTS preload enabled

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Help your customers with a unique and responsive toolkit

Key insights
  • Built for Shopify badge present, indicating Shopify-vetted
  • 5.0 rating with 18 reviews (small sample size)
  • Privacy policy mentions only Shopify and Google Analytics as third parties
  • Publisher domain protected by Cloudflare with HSTS preload enabled
  • No declared OAuth scopes visible from app store listing page
  • No known security breaches or CVEs found for Appify Commerce

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_themes
Low

L'app doit lire le thème pour intégrer les fonctionnalités d'accessibilité affichées sur la vitrine, induit de la fonction déclarée de l'app.

write_themes
Medium

L'ajout de fonctions comme la synthèse vocale ou l'inversion des couleurs nécessite de modifier les fichiers du thème, induit de la fonction déclarée de l'app.

write_script_tags
Medium

L'injection de scripts pour activer les outils d'accessibilité côté client requiert l'écriture de balises de script, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
appifycommerce.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS with includeSubDomains and preload enabled. Cloudflare-fronted. Strong baseline security headers (x-content-type-options, x-frame-options, referrer-policy, permissions-policy) but no Content-Security-Policy header observed.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not declare formal compliance certifications. Mentions GDPR data subject rights implicitly via data transfer disclosure but no SOC2/ISO27001/PCI claims.

Privacy policy
Track record

Publisher reputation

Publisher
Appify Commerce
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.