Starship
starship / search / add-to-cart

Audit report

Nice ‑ Add to cart button

TrustedReach : broad

by GoldenDev (Nice) · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

Get a sales boost with an add to cart button & buy button now!

Key insights

  • Cart customization utility (UI-only category) suggests low-sensitivity scope requirements typical for storefront/theme apps.
  • Rating 4.9 with 59 reviews indicates a small but well-reviewed app.
  • Publisher domain goldendev.win serves a near-empty page (13 bytes) on LiteSpeed; primary surface appears to be the subdirectories.
  • Privacy policy declares data residency in Canada and United States and addresses GDPR obligations.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Get a sales boost with an add to cart button & buy button now!

Key insights
  • Cart customization utility (UI-only category) suggests low-sensitivity scope requirements typical for storefront/theme apps.
  • Rating 4.9 with 59 reviews indicates a small but well-reviewed app.
  • Publisher domain goldendev.win serves a near-empty page (13 bytes) on LiteSpeed; primary surface appears to be the subdirectories.
  • Privacy policy declares data residency in Canada and United States and addresses GDPR obligations.
  • No public security incidents, CVEs, or breaches found for GoldenDev or the Nice add-to-cart app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

L'application doit lire les produits pour identifier les articles ajoutables au panier via le bouton, induit de la fonction déclarée de l'app.

read_themes
Low

L'application doit lire le thème pour repérer les emplacements où insérer le bouton d'ajout au panier, induit de la fonction déclarée de l'app.

write_themes
Medium

L'application modifie l'affichage de la boutique pour y intégrer un bouton d'ajout au panier, ce qui suppose une écriture sur le thème, induit de la fonction déclarée de l'app.

write_script_tags
Medium

L'application peut injecter un script sur la vitrine pour afficher et gérer le bouton d'ajout au panier, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
goldendev.win
TLS grade
A
HSTS
Missing
CSP
Missing

LiteSpeed server, HTTPS works cleanly, HTTP/3 advertised, but no HSTS or CSP headers observed on root.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR addressed in privacy policy; no SOC2/ISO27001/PCI/HIPAA mentions; data residency Canada and United States.

Privacy policy
Track record

Publisher reputation

Publisher
GoldenDev (Nice)
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.