Starship
starship / search / amp-by-webkul

Audit report

AMP by Webkul

Broad accessReach : limited

by Webkul Software Pvt Ltd · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Create AMP Pages for your Shopify Store

Key insights

  • Publisher Webkul has a credible but average privacy policy (GDPR mention, no certifications).
  • App scope appears narrow (store owner contact info) and does not request write_* scopes, keeping inherent blast radius low.
  • Publisher has a non-trivial CVE history across other products (Krayin CRM, Bagisto) - reputation flag rather than direct app evidence.
  • Publisher domain has HSTS and TLS but a permissive/empty CSP and only short HSTS max-age.

Top findingsview all

  • High
    Multiple CVEs in publisher's other products (Krayin CRM, Bagisto)
Synthesis

Analysis summary

Create AMP Pages for your Shopify Store

Key insights
  • Publisher Webkul has a credible but average privacy policy (GDPR mention, no certifications).
  • App scope appears narrow (store owner contact info) and does not request write_* scopes, keeping inherent blast radius low.
  • Publisher has a non-trivial CVE history across other products (Krayin CRM, Bagisto) - reputation flag rather than direct app evidence.
  • Publisher domain has HSTS and TLS but a permissive/empty CSP and only short HSTS max-age.
  • Single 1-star review reports broken AMP output - quality/support concern more than security.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_store_owner_information
Medium

Access to merchant name/email/phone/address - PII but no customer or order data. Reasonable for billing/contact in a single-merchant SEO tool.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webkul.com
TLS grade
unknown
HSTS
Enabled
CSP
Missing

CSP header present but only 'upgrade-insecure-requests' - no source restrictions. HSTS max-age=2592000 (~30 days), short and no preload.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy references GDPR legal basis but lists no third-party certifications and no concrete retention period.

Privacy policy
Track record

Publisher reputation

Publisher
Webkul Software Pvt Ltd
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
  • CVE-2026-38526 (Krayin CRM RCE)
  • CVE-2026-38529 (Krayin CRM auth bypass)
  • CVE-2026-38527 (Krayin CRM SSRF)
  • CVE-2026-36341 (Krayin CRM XSS)
  • CVE-2026-21448 / CVE-2026-21450 (Bagisto SSTI -> RCE)
  • CVE-2026-21447 (Bagisto auth bypass)
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.