Starship
starship / search / ali-reviews

Audit report

Ali Reviews ‑ Product Reviews

Broad accessReach : broadSensitive Access

by FireApps - Premium Apps For Ecommerce. · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Import reviews from AliExpress, Photo & Site Reviews

Key insights

  • Built for Shopify-badged app with 4.8/5 rating across 1,276 reviews; published 2017 by FireApps (Vietnam).
  • Imports reviews from AliExpress/Amazon/Temu/Etsy and uses Google Gemini for AI translation - LLM use is not addressed in the privacy policy.
  • Privacy policy lists AWS, Google, Facebook, Crisp, Sentry as sub-processors; no compliance certifications stated; no data-residency region specified.
  • Publisher site alireviews.io uses Cloudflare with HSTS not enforced via header but solid baseline security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection).

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Import reviews from AliExpress, Photo & Site Reviews

Key insights
  • Built for Shopify-badged app with 4.8/5 rating across 1,276 reviews; published 2017 by FireApps (Vietnam).
  • Imports reviews from AliExpress/Amazon/Temu/Etsy and uses Google Gemini for AI translation - LLM use is not addressed in the privacy policy.
  • Privacy policy lists AWS, Google, Facebook, Crisp, Sentry as sub-processors; no compliance certifications stated; no data-residency region specified.
  • Publisher site alireviews.io uses Cloudflare with HSTS not enforced via header but solid baseline security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection).
  • No known security breaches, CVEs, or incidents found in public sources.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to attach reviews to products; inferred from review-importer functionality.

write_products
Medium

Inferred - likely needed to write review metafields or metaobjects to products.

read_orders
Medium

Inferred - automated post-purchase email collection of photo/video feedback requires order data.

read_customers
High

Inferred - email collection for review requests requires customer contact data.

read_themes
Low

Inferred - theme app extension for widget display.

write_themes
Medium

Inferred - widget injection or theme app block installation.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
alireviews.io
TLS grade
unknown
HSTS
Missing
CSP
Missing

HTTP/2 over Cloudflare; security headers include X-Frame-Options=SAMEORIGIN, X-Content-Type-Options=nosniff, X-XSS-Protection=1; mode=block. No HSTS or CSP header observed on root.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No compliance certifications stated in privacy policy. Vendor located in Vietnam.

Privacy policy
Track record

Publisher reputation

Publisher
FireApps - Premium Apps For Ecommerce.
Verified Shopify Partner
Yes
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
Google Gemini
Data shared with providers

Review text for translation

Retention policy

undisclosed