Starship
starship / search / affiliatly

Audit report

Affiliatly

Broad accessReach : broadSensitive Access

by overcode · Marketing · Shopify App Store

Marketing
Risk level
Broad access
Executive summary

Affiliate tracking app at great price

Key insights

  • Affiliate marketing app by Overcode, live on Shopify since 2014
  • Rating 4.4 with 71 reviews; no Built for Shopify badge
  • Privacy policy declares GDPR compliance; no other certifications named
  • Uses Cloudflare and Comodo as primary infrastructure/SSL providers

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Affiliate tracking app at great price

Key insights
  • Affiliate marketing app by Overcode, live on Shopify since 2014
  • Rating 4.4 with 71 reviews; no Built for Shopify badge
  • Privacy policy declares GDPR compliance; no other certifications named
  • Uses Cloudflare and Comodo as primary infrastructure/SSL providers
  • No known CVEs or breaches found for the publisher or app
  • TLS valid (HTTPS via Cloudflare), CSP frame-ancestors set, but no HSTS

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Likely required to track referred orders for affiliate commission attribution (inferred from app function; not explicitly listed on store page).

read_customers
High

Likely required to associate affiliates with customer accounts and tags (inferred).

read_products
Medium

Likely required to track SKU-based affiliate commissions (inferred).

write_script_tags
Medium

Typical for affiliate tracking apps that inject client-side referral attribution scripts (inferred).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
affiliatly.com
TLS grade
A
HSTS
Missing
CSP
Enabled

CSP limited to frame-ancestors 'none'; no HSTS; X-Frame-Options SAMEORIGIN and X-Content-Type-Options nosniff present. Server fronted by Cloudflare.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Only GDPR explicitly declared. No SOC2/ISO/PCI/HIPAA claims.

Privacy policy
Track record

Publisher reputation

Publisher
overcode
Verified Shopify Partner
No
Years active
12
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.