Starship
starship / search / aegis

Audit report

Aegis

TrustedReach : broad

by Fuznet · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

Protects texts, images and best selling of your online store

Key insights

  • Anti-theft / content-protection app priced at $2.99/month with 7-day free trial
  • Built on Gadget.app platform (Gadget is a managed backend-as-a-service for Shopify apps)
  • Privacy policy on dev subdomain returned HTTP 402 - inaccessible at audit time
  • Only 2 reviews, 1.4-star rating - very limited adoption

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Protects texts, images and best selling of your online store

Key insights
  • Anti-theft / content-protection app priced at $2.99/month with 7-day free trial
  • Built on Gadget.app platform (Gadget is a managed backend-as-a-service for Shopify apps)
  • Privacy policy on dev subdomain returned HTTP 402 - inaccessible at audit time
  • Only 2 reviews, 1.4-star rating - very limited adoption
  • Not Built for Shopify certified
  • No publicly known breaches or CVEs associated with Fuznet or the Aegis app
  • Publisher domain fuznet.com is served via Cloudflare with HSTS enabled

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_script_tags
Medium

L'app injecte des scripts pour desactiver le clic droit et proteger textes et images, ce qui necessite l'ecriture de balises de script, induit de la fonction declaree de l'app.

read_themes
Low

Le fonctionnement de la protection de contenu implique la lecture du theme de la boutique, induit de la fonction declaree de l'app.

write_themes
Medium

L'application des mesures de protection et du blocage par pays peut requerir la modification du theme, induit de la fonction declaree de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
fuznet.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 with includeSubDomains; no CSP header present; X-Content-Type-Options nosniff set; served behind Cloudflare

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL declared but returned HTTP 402 Payment Required at audit time; no compliance certifications confirmable

Privacy policy
Track record

Publisher reputation

Publisher
Fuznet
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.