Audit report
FireAMP
WatchReach : moderateby MLveda · Store design · Shopify App Store
AMP - Accelerate Mobile Page Speed & Google Search Ranking!
Key insights
- ◆MLveda is a known Shopify/BigCommerce eCommerce agency; FireAMP is a legacy AMP page generator (since 2017).
- ◆No public CVE, breach, or security incident found for MLveda or FireAMP in web/news searches.
- ◆Privacy policy is materially incomplete (placeholders, mismatched template), significant compliance/trust gap.
- ◆Scopes are moderate (read product/page/theme/blog + edit discounts + read store owner contact), not minimal but no write_orders or customer PII bulk access disclosed.
Top findingsview all
- HighIncomplete/templated privacy policy
Analysis summary
AMP - Accelerate Mobile Page Speed & Google Search Ranking!
- ◆MLveda is a known Shopify/BigCommerce eCommerce agency; FireAMP is a legacy AMP page generator (since 2017).
- ◆No public CVE, breach, or security incident found for MLveda or FireAMP in web/news searches.
- ◆Privacy policy is materially incomplete (placeholders, mismatched template), significant compliance/trust gap.
- ◆Scopes are moderate (read product/page/theme/blog + edit discounts + read store owner contact), not minimal but no write_orders or customer PII bulk access disclosed.
- ◆Publisher marketing site is hosted on Webflow (us-east-1); no enterprise security signaling, no certifications declared.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Needed to render AMP product pages. |
read_content | Low | Needed to render AMP blog/pages. |
read_themes | Medium | Theme code visibility; could expose Liquid templates and storefront customizations. |
read_shop_owner_info | Medium | Store owner contact details, PII; broader than required for AMP rendering. |
write_discounts | High | Ability to edit discount codes, not required for AMP generation; compromise risk = fraudulent discounts. |
read_productsNeeded to render AMP product pages.
read_contentNeeded to render AMP blog/pages.
read_themesTheme code visibility; could expose Liquid templates and storefront customizations.
read_shop_owner_infoStore owner contact details, PII; broader than required for AMP rendering.
write_discountsAbility to edit discount codes, not required for AMP generation; compromise risk = fraudulent discounts.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- mlveda.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
Webflow-hosted; CSP header only contains frame-ancestors directive; no HSTS observed in response headers.
Compliance & certifications
Privacy policy is templated/incomplete with placeholder text and references unrelated marketplace verbiage; no certifications declared.
Privacy policyPublisher reputation
- Publisher
- MLveda
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0