Starship
starship / search / age-verification

Audit report

Age Verifier by OTG

TrustedReach : broad

by Open Think Group, Inc. · Trust and security · Shopify App Store

Trust and security
Risk level
Trusted
Executive summary

Customizable pop-up app to restrict access to your website.

Key insights

  • Age-verification app (legal/compliance category) by Open Think Group, Inc., launched 2017.
  • Privacy policy exists and discloses cross-border transfer to Canada and United States.
  • No declared use of AI/LLM providers; functionality is a customizable age-gate pop-up.
  • Publisher website on Shopify-hosted infrastructure with HSTS, X-Frame-Options DENY, basic CSP.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Customizable pop-up app to restrict access to your website.

Key insights
  • Age-verification app (legal/compliance category) by Open Think Group, Inc., launched 2017.
  • Privacy policy exists and discloses cross-border transfer to Canada and United States.
  • No declared use of AI/LLM providers; functionality is a customizable age-gate pop-up.
  • Publisher website on Shopify-hosted infrastructure with HSTS, X-Frame-Options DENY, basic CSP.
  • No public CVEs, breaches, or security incidents found for publisher or app.
  • Listing transparency is weak: scopes not enumerated, 0 reviews, no 'Built for Shopify' badge.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_themes
Low

L'application affiche un pop-up sur la vitrine, ce qui suppose la lecture du thème pour intégrer l'élément, induit de la fonction déclarée de l'app.

write_themes
Medium

La personnalisation et l'insertion du pop-up dans la vitrine impliquent la modification du thème, induit de la fonction déclarée de l'app.

write_script_tags
Medium

L'affichage d'un pop-up de restriction d'accès peut nécessiter l'injection d'un script dans la boutique, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
openthinkgroup.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age ~91 days; CSP present but minimal (block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests). X-Frame-Options DENY, X-Content-Type-Options nosniff, X-XSS-Protection enabled. Cloudflare-fronted Shopify-hosted site.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy present and addresses cross-border data transfers (Canada, US) but no certifications, sub-processors, or retention periods disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
Open Think Group, Inc.
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.