Starship
starship / search / algolia-search

Audit report

Algolia Search & Discovery

Broad accessReach : moderateSensitive Access

by Algolia · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Product search & discovery that increases conversions at scale

Key insights

  • Mature, well-known vendor (Algolia, founded 2012) with SOC2, ISO 27001, and ISO 27017 certifications and a public bug bounty program.
  • Real past incident in 2020 (Salt vulnerability) with public postmortem; no reported customer data exfiltration.
  • Main residual risk is misuse of API keys by merchants in theme/client code, not Algolia's core platform.
  • Strong network surface: HSTS preload, comprehensive CSP, TLS via Cloudflare, X-Content-Type-Options, X-Frame-Options SAMEORIGIN.

Top findingsview all

  • High
    Historic server compromise via Salt vulnerability (CVE-2020-11651)
Synthesis

Analysis summary

Product search & discovery that increases conversions at scale

Key insights
  • Mature, well-known vendor (Algolia, founded 2012) with SOC2, ISO 27001, and ISO 27017 certifications and a public bug bounty program.
  • Real past incident in 2020 (Salt vulnerability) with public postmortem; no reported customer data exfiltration.
  • Main residual risk is misuse of API keys by merchants in theme/client code, not Algolia's core platform.
  • Strong network surface: HSTS preload, comprehensive CSP, TLS via Cloudflare, X-Content-Type-Options, X-Frame-Options SAMEORIGIN.
  • Privacy policy explicitly authorizes use of LLMs and AI tools but does not list providers; chatbot present on site.
  • Modest review score (3.6/5, 45 reviews) and no 'Built for Shopify' badge.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to index catalog for search.

read_customers
High

Customer PII pulled into search/personalization context.

read_orders
High

Order history used for personalization and recommendations; sensitive purchase data.

write_online_store_pages
High

Theme/page write capability is high blast radius if token compromised.

write_pixels
High

Web pixel write access enables tracking script injection on storefront.

read_browsing_behavior
Medium

Device/geolocation/browsing telemetry feeds personalization.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
algolia.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS with preload + includeSubDomains; comprehensive CSP enforced (frame-src, script-src, connect-src) and a separate CSP-Report-Only header; X-Content-Type-Options nosniff; X-Frame-Options SAMEORIGIN; served via Cloudflare.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Pass
PCI DSS Fail

SOC 2 and ISO 27001/27017 certified; TRUSTe certified; uses SCCs for EU data transfers. HIPAA not supported.

Privacy policy
Track record

Publisher reputation

Publisher
Algolia
Verified Shopify Partner
Yes
Years active
14
Other apps
0
Past incidents
  • 2020-05-03 · infrastructure_compromise
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Privacy policy authorizes use of LLMs and AI tools on personal information for product features and a website chatbot; specific providers not disclosed.

Retention policy

unknown