Starship
starship / search / amp

Audit report

FireAMP

WatchReach : moderate

by MLveda · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

AMP - Accelerate Mobile Page Speed & Google Search Ranking!

Key insights

  • MLveda is a known Shopify/BigCommerce eCommerce agency; FireAMP is a legacy AMP page generator (since 2017).
  • No public CVE, breach, or security incident found for MLveda or FireAMP in web/news searches.
  • Privacy policy is materially incomplete (placeholders, mismatched template), significant compliance/trust gap.
  • Scopes are moderate (read product/page/theme/blog + edit discounts + read store owner contact), not minimal but no write_orders or customer PII bulk access disclosed.

Top findingsview all

  • High
    Incomplete/templated privacy policy
Synthesis

Analysis summary

AMP - Accelerate Mobile Page Speed & Google Search Ranking!

Key insights
  • MLveda is a known Shopify/BigCommerce eCommerce agency; FireAMP is a legacy AMP page generator (since 2017).
  • No public CVE, breach, or security incident found for MLveda or FireAMP in web/news searches.
  • Privacy policy is materially incomplete (placeholders, mismatched template), significant compliance/trust gap.
  • Scopes are moderate (read product/page/theme/blog + edit discounts + read store owner contact), not minimal but no write_orders or customer PII bulk access disclosed.
  • Publisher marketing site is hosted on Webflow (us-east-1); no enterprise security signaling, no certifications declared.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Needed to render AMP product pages.

read_content
Low

Needed to render AMP blog/pages.

read_themes
Medium

Theme code visibility; could expose Liquid templates and storefront customizations.

read_shop_owner_info
Medium

Store owner contact details, PII; broader than required for AMP rendering.

write_discounts
High

Ability to edit discount codes, not required for AMP generation; compromise risk = fraudulent discounts.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
mlveda.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

Webflow-hosted; CSP header only contains frame-ancestors directive; no HSTS observed in response headers.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy is templated/incomplete with placeholder text and references unrelated marketplace verbiage; no certifications declared.

Privacy policy
Track record

Publisher reputation

Publisher
MLveda
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.