Starship
starship / search / also-bought

Audit report

Also Bought • Recommendations

Broad accessReach : moderateSensitive Access

by Code Black Belt · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Amazon-like 'Customers Who Bought This Also Bought' cross-sell

Key insights

  • Built for Shopify certified app from Code Black Belt, 4.8/5 rating (357 reviews) - strong merchant trust signal
  • Read-only scope profile (products, orders, themes, customer activity) with no write_* permissions declared
  • Privacy policy asserts no third-party data sharing and 30-day deletion after uninstall - positive
  • Publisher site is on Shopify infrastructure (Cloudflare + HSTS + CSP block-all-mixed-content + frame-ancestors none) - healthy network surface

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Amazon-like 'Customers Who Bought This Also Bought' cross-sell

Key insights
  • Built for Shopify certified app from Code Black Belt, 4.8/5 rating (357 reviews) - strong merchant trust signal
  • Read-only scope profile (products, orders, themes, customer activity) with no write_* permissions declared
  • Privacy policy asserts no third-party data sharing and 30-day deletion after uninstall - positive
  • Publisher site is on Shopify infrastructure (Cloudflare + HSTS + CSP block-all-mixed-content + frame-ancestors none) - healthy network surface
  • No public CVEs, breaches, or incidents found tied to Code Black Belt or Also Bought
  • Compliance gap: policy denies GDPR/CCPA applicability despite collecting IP/geolocation/contact data

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to surface product recommendations

read_orders
High

Full order history is sensitive; needed to compute co-purchase signals

read_themes
Medium

Required to inject the recommendation widget into theme

read_online_store_pages
Low

Storefront context for widget placement

read_customers
High

Implied by customer activity/contact data access in listing

read_locales
Info

Supports multi-language widget rendering

read_markets
Info

Supports multi-market storefronts

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
codeblackbelt.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age=7889238, CSP with block-all-mixed-content + frame-ancestors 'none' + upgrade-insecure-requests, X-Frame-Options DENY, X-Content-Type-Options nosniff; site hosted on Shopify/Cloudflare

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy claims non-applicability to GDPR/CCPA; no SOC2/ISO27001/PCI/HIPAA mentioned. States 30-day deletion after uninstall and no proactive third-party sharing.

Privacy policy
Track record

Publisher reputation

Publisher
Code Black Belt
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.