Starship
starship / search / alert-me-restock-alerts

Audit report

Alert Me! Restock Alerts

Broad accessReach : broadSensitive Access

by Dibble Development · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Automated restock notifications for customers

Key insights

  • Built for Shopify badge present; app listed on Shopify App Store since 2017.
  • Publisher (Dibble Development / DibLabs) operates 2 apps on the store; small-shop publisher, US-based (Watkinsville, GA).
  • No public security incidents, CVEs, or breach reports found for Dibble Development or the Alert Me app.
  • Scope set is justifiable for restock-alert functionality but includes sensitive write scopes (themes, script tags) plus shopper PII.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Automated restock notifications for customers

Key insights
  • Built for Shopify badge present; app listed on Shopify App Store since 2017.
  • Publisher (Dibble Development / DibLabs) operates 2 apps on the store; small-shop publisher, US-based (Watkinsville, GA).
  • No public security incidents, CVEs, or breach reports found for Dibble Development or the Alert Me app.
  • Scope set is justifiable for restock-alert functionality but includes sensitive write scopes (themes, script tags) plus shopper PII.
  • Marketing/policy site hosted on Heroku behind Next.js; lacks HSTS/CSP hardening.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to enumerate products/variants and detect restock events.

read_inventory
Low

Needed to monitor inventory levels and trigger alerts on restock.

read_customers
Medium

Used to attach subscriptions to customer records; exposes shopper PII.

write_customers
High

Implied by ability to create/update customer subscription metadata; can mutate customer records.

read_orders
Medium

60-day order history accessed for analytics on conversion from alerts.

write_script_tags
High

Injects storefront JS; abuse surface for client-side code on every page.

write_themes
High

Edits theme to embed signup form; broad write access to storefront code.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
dibbledevelopment.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

Heroku-hosted Next.js app; HTTP/2 + valid TLS confirmed via curl, but no Strict-Transport-Security or Content-Security-Policy headers observed on root domain.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy page is client-side rendered; static fetch returned only navigation shell, so specific GDPR/SOC2/sub-processor disclosures could not be verified.

Privacy policy
Track record

Publisher reputation

Publisher
Dibble Development
Verified Shopify Partner
No
Years active
9
Other apps
1
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.