Starship
starship / search / all-in-one-product-zoom

Audit report

All In One Product Zoom

TrustedReach : broad

by Nulls.Net · Store design · Shopify App Store

Store design
Risk level
Trusted
Executive summary

You can choose from 3 of the Zoom Types

Key insights

  • Minimal scope footprint: only theme/script-tag write + store owner contact info, appropriate for a product image zoom widget.
  • Built for Shopify badge + 4.9 rating across 17 reviews suggests vetted quality.
  • Privacy policy is reasonably complete with a 90-day retention cap and GDPR/CCPA references, but no SOC2/ISO27001 certifications claimed.
  • Publisher domain nulls.net runs WordPress/LiteSpeed without HSTS/CSP headers, minor hygiene gap but not on the app data path.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

You can choose from 3 of the Zoom Types

Key insights
  • Minimal scope footprint: only theme/script-tag write + store owner contact info, appropriate for a product image zoom widget.
  • Built for Shopify badge + 4.9 rating across 17 reviews suggests vetted quality.
  • Privacy policy is reasonably complete with a 90-day retention cap and GDPR/CCPA references, but no SOC2/ISO27001 certifications claimed.
  • Publisher domain nulls.net runs WordPress/LiteSpeed without HSTS/CSP headers, minor hygiene gap but not on the app data path.
  • No public breach, CVE, or incident history linked to Nulls.Net or this app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_themes
Medium

Required to inject the zoom widget into the storefront theme; allows arbitrary JS in the storefront.

write_script_tags
Medium

Allows registering remote scripts that execute on storefront pages.

read_shop
Low

Store owner name, email, phone, physical address, standard for billing/support.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
nulls.net
TLS grade
unknown
HSTS
Missing
CSP
Missing

HTTP/2 on LiteSpeed, HTTP/3 advertised via alt-svc; no HSTS or CSP headers observed on root.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Policy references GDPR, UK GDPR, CCPA, Canadian privacy laws. 90-day retention cap. No formal third-party certifications claimed.

Privacy policy
Track record

Publisher reputation

Publisher
Nulls.Net
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.