Starship
starship / search / all-in-one-notification-bar

Audit report

Country Based Announcement Bar

Broad accessReach : broad

by Metizsoft Solutions Pvt Ltd · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Easy way to make notification bar based on country

Key insights

  • Publisher Metizsoft Solutions is an India-headquartered IT services firm with offices in US/UK/Singapore; privacy policy is unusually detailed for a small Shopify app.
  • Privacy policy declares ISO 27001:2022 certification and SOC 2-aligned controls plus GDPR/DPDP Act alignment.
  • Data residency spans AWS Mumbai, Frankfurt, and Virginia with Cloudflare CDN, multi-region, no EU-only guarantee.
  • App requests script tag write capability, legitimate for storefront injection but a sensitive scope merchants should weigh.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Easy way to make notification bar based on country

Key insights
  • Publisher Metizsoft Solutions is an India-headquartered IT services firm with offices in US/UK/Singapore; privacy policy is unusually detailed for a small Shopify app.
  • Privacy policy declares ISO 27001:2022 certification and SOC 2-aligned controls plus GDPR/DPDP Act alignment.
  • Data residency spans AWS Mumbai, Frankfurt, and Virginia with Cloudflare CDN, multi-region, no EU-only guarantee.
  • App requests script tag write capability, legitimate for storefront injection but a sensitive scope merchants should weigh.
  • Publisher website returns HSTS but no Content-Security-Policy header.
  • No public CVEs, breach reports, or security incidents found via web search.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_shop_owner_info
Medium

Reads owner name, email, phone, physical address, PII broader than announcement-bar function requires.

read_blog_contributors
Medium

Email, IP address, and browser/OS info on blog contributors, PII not clearly tied to the announcement-bar feature.

read_products
Low

View products and collections, low risk, plausible for targeting bar content.

write_script_tags
High

Editing Online Store script tags permits arbitrary JS injection into the storefront, high-impact scope.

write_online_store_pages
Medium

Edit Online Store pages, content manipulation risk if misused or compromised.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
metizsoft.com
TLS grade
unknown
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 includeSubDomains; X-Frame-Options SAMEORIGIN; X-Content-Type-Options nosniff; Referrer-Policy strict-origin-when-cross-origin; no Content-Security-Policy header observed.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Pass
PCI DSS Fail

Privacy policy claims ISO 27001:2022 (annually audited) and 'SOC 2-aligned controls' (not certified). GDPR and India DPDP Act referenced. No PCI DSS or HIPAA. Retention: active accounts contract + 7 years, sales inquiries 24 months, analytics 14 months. Explicitly states 'We do not use your data to train third-party models.'

Privacy policy
Track record

Publisher reputation

Publisher
Metizsoft Solutions Pvt Ltd
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.