Audit report
Algolia Search & Discovery
Broad accessReach : moderateSensitive Accessby Algolia · Store design · Shopify App Store
Product search & discovery that increases conversions at scale
Key insights
- ◆Mature, well-known vendor (Algolia, founded 2012) with SOC2, ISO 27001, and ISO 27017 certifications and a public bug bounty program.
- ◆Real past incident in 2020 (Salt vulnerability) with public postmortem; no reported customer data exfiltration.
- ◆Main residual risk is misuse of API keys by merchants in theme/client code, not Algolia's core platform.
- ◆Strong network surface: HSTS preload, comprehensive CSP, TLS via Cloudflare, X-Content-Type-Options, X-Frame-Options SAMEORIGIN.
Top findingsview all
- HighHistoric server compromise via Salt vulnerability (CVE-2020-11651)
Analysis summary
Product search & discovery that increases conversions at scale
- ◆Mature, well-known vendor (Algolia, founded 2012) with SOC2, ISO 27001, and ISO 27017 certifications and a public bug bounty program.
- ◆Real past incident in 2020 (Salt vulnerability) with public postmortem; no reported customer data exfiltration.
- ◆Main residual risk is misuse of API keys by merchants in theme/client code, not Algolia's core platform.
- ◆Strong network surface: HSTS preload, comprehensive CSP, TLS via Cloudflare, X-Content-Type-Options, X-Frame-Options SAMEORIGIN.
- ◆Privacy policy explicitly authorizes use of LLMs and AI tools but does not list providers; chatbot present on site.
- ◆Modest review score (3.6/5, 45 reviews) and no 'Built for Shopify' badge.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to index catalog for search. |
read_customers | High | Customer PII pulled into search/personalization context. |
read_orders | High | Order history used for personalization and recommendations; sensitive purchase data. |
write_online_store_pages | High | Theme/page write capability is high blast radius if token compromised. |
write_pixels | High | Web pixel write access enables tracking script injection on storefront. |
read_browsing_behavior | Medium | Device/geolocation/browsing telemetry feeds personalization. |
read_productsRequired to index catalog for search.
read_customersCustomer PII pulled into search/personalization context.
read_ordersOrder history used for personalization and recommendations; sensitive purchase data.
write_online_store_pagesTheme/page write capability is high blast radius if token compromised.
write_pixelsWeb pixel write access enables tracking script injection on storefront.
read_browsing_behaviorDevice/geolocation/browsing telemetry feeds personalization.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- algolia.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
HSTS with preload + includeSubDomains; comprehensive CSP enforced (frame-src, script-src, connect-src) and a separate CSP-Report-Only header; X-Content-Type-Options nosniff; X-Frame-Options SAMEORIGIN; served via Cloudflare.
Compliance & certifications
SOC 2 and ISO 27001/27017 certified; TRUSTe certified; uses SCCs for EU data transfers. HIPAA not supported.
Privacy policyPublisher reputation
- Publisher
- Algolia
- Verified Shopify Partner
- Yes
- Years active
- 14
- Other apps
- 0
- ●2020-05-03 · infrastructure_compromise
AI / LLM usage
Privacy policy authorizes use of LLMs and AI tools on personal information for product features and a website chatbot; specific providers not disclosed.
unknown