Starship
starship / search / amazonify

Audit report

Zonify

Broad accessReach : broad

by importify · Finding and adding products · Shopify App Store

Finding and adding products
Risk level
Broad access
Executive summary

Amazon Dropshipping

Key insights

  • Long-tenured app (launched Oct 2016) with small review base (~15 reviews) but high rating (4.9).
  • Publisher 'importify limited' operates a sibling WooCommerce product that had a public CVE in 2023 (CVE-2023-49194, low severity).
  • Privacy policy is behind a bot-challenge wall - reduces verifiability of GDPR/compliance claims.
  • Publisher origin returns no security headers (no HSTS/CSP) on basic probe.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Amazon Dropshipping

Key insights
  • Long-tenured app (launched Oct 2016) with small review base (~15 reviews) but high rating (4.9).
  • Publisher 'importify limited' operates a sibling WooCommerce product that had a public CVE in 2023 (CVE-2023-49194, low severity).
  • Privacy policy is behind a bot-challenge wall - reduces verifiability of GDPR/compliance claims.
  • Publisher origin returns no security headers (no HSTS/CSP) on basic probe.
  • App advertises AI features (product optimization, multi-language translation) without disclosing LLM providers, data flow, or retention.
  • No 'Built for Shopify' badge observed. No public security incident tied to Zonify specifically.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_products
High

Required to import Amazon products into Shopify catalog - core advertised function. Allows creation/modification of product data.

read_products
Medium

Likely needed to manage already-imported listings and pricing rules.

write_themes
High

Possible but not confirmed - affiliate link injection may need theme/script access.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
zonify.app
TLS grade
unknown
HSTS
Missing
CSP
Missing

Root probe returned HTTP/2 415 with only server/date/content-type. No HSTS, CSP, X-Content-Type-Options, or Referrer-Policy headers observed.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL exists but returns bot-protection interstitial to automated fetchers - could not verify GDPR/SOC2/ISO27001/PCI/HIPAA claims or retention policy.

Privacy policy
Track record

Publisher reputation

Publisher
importify
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
  • CVE-2023-49194 - Sensitive Data Exposure in Importify WooCommerce plugin <=1.0.4 (CVSS 5.3, fixed in 1.0.5)
LLM exposure

AI / LLM usage

LLM providers
Data shared with providers

Product titles/descriptions sent for AI-powered optimization and 20+ language translation. Specific providers not disclosed.

Retention policy

unknown