Starship
starship / search / activity-logs

Audit report

Logify

WatchReach : broad

by Tabgraf.com · Customer support · Shopify App Store

Customer support
Risk level
Watch
Executive summary

Track your shop's activities and admin logs

Key insights

  • Read-only logging product requests full write scope across the entire store, scope/function mismatch.
  • Privacy policy is gated behind a 403, preventing third-party verification of GDPR claims.
  • Very small install base (4 reviews) and no Built for Shopify badge.
  • Hosted on Next.js behind Cloudflare; TLS healthy but security headers absent.

Top findingsview all

  • High
    Broad write access to entire store data
  • High
    Access to sensitive customer data including device/activity data
Synthesis

Analysis summary

Track your shop's activities and admin logs

Key insights
  • Read-only logging product requests full write scope across the entire store, scope/function mismatch.
  • Privacy policy is gated behind a 403, preventing third-party verification of GDPR claims.
  • Very small install base (4 reviews) and no Built for Shopify badge.
  • Hosted on Next.js behind Cloudflare; TLS healthy but security headers absent.
  • No known CVEs, breaches, or public security incidents tied to Tabgraf or Logify.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Sensitive customer PII including device/activity data; not strictly required to log admin/staff actions.

read_users
Medium

Staff and contributor data, justifiable for staff action logging.

write_products
High

Write scope for products is unnecessary for a logging tool.

write_orders
Critical

Write access to orders is highly sensitive and unjustified for an audit log app.

write_customers
Critical

Write access to customer records is unnecessary for read-only activity logging.

write_discounts
High

Unnecessary write scope; financial impact if abused.

write_gift_cards
Critical

Gift card write access has direct monetary value; unjustified for logging.

write_marketing_events
Medium

Not needed to read audit data.

write_payment_terms
High

Payment-related write scope unnecessary.

write_online_store_pages
Medium

Could be abused for storefront tampering.

write_analytics
Medium

Unnecessary for a logging product.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
tabgraf.com
TLS grade
A
HSTS
Missing
CSP
Missing

Served via Cloudflare with valid TLS; Next.js / OpenNext stack. No Strict-Transport-Security or Content-Security-Policy headers observed on root.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL exists but returned HTTP 403 to automated fetch, so claims (including publisher's stated GDPR adherence) cannot be independently verified.

Privacy policy
Track record

Publisher reputation

Publisher
Tabgraf.com
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.