Starship
starship / search / advance-gift-registry

Audit report

Gift Registry ‑ Share Registry

Broad accessReach : broadSensitive Access

by AAAeCommerce Inc · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Create & Share Gift Registry for Wedding, Birthday & Event

Key insights

  • Small wishlist/gift-registry app, 4.4 rating with only 22 reviews, limited install base signal
  • Publisher AAAeCommerce Inc is India-based (Indore) with cross-border processing to Canada/US
  • Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
  • No 'Built for Shopify' badge

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Create & Share Gift Registry for Wedding, Birthday & Event

Key insights
  • Small wishlist/gift-registry app, 4.4 rating with only 22 reviews, limited install base signal
  • Publisher AAAeCommerce Inc is India-based (Indore) with cross-border processing to Canada/US
  • Privacy policy explicitly disclaims PCI DSS and HIPAA compliance
  • No 'Built for Shopify' badge
  • No known CVEs or public breaches for AAAeCommerce Inc
  • Publisher marketing site runs on outdated PHP 7.4 on Hostinger/LiteSpeed
  • No mention of LLM/AI usage in privacy policy

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Required to associate registries with customer accounts; PII access

read_products
Low

Required to populate registry with catalog items

read_orders
High

Required for duplicate-purchase prevention; exposes purchase data

write_themes
High

Typical for storefront wishlist apps to inject registry UI; theme write access is sensitive

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
aaaecommerce.com
TLS grade
A
HSTS
Missing
CSP
Enabled

CSP present but minimal (upgrade-insecure-requests only); no HSTS; server reveals PHP 7.4 EOL

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR mentioned for EEA residents. PCI DSS and HIPAA explicitly disclaimed. No SOC2/ISO27001 claims.

Privacy policy
Track record

Publisher reputation

Publisher
AAAeCommerce Inc
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.