Audit report
AMP by Webkul
Broad accessReach : limitedby Webkul Software Pvt Ltd · Store design · Shopify App Store
Create AMP Pages for your Shopify Store
Key insights
- ◆Publisher Webkul has a credible but average privacy policy (GDPR mention, no certifications).
- ◆App scope appears narrow (store owner contact info) and does not request write_* scopes, keeping inherent blast radius low.
- ◆Publisher has a non-trivial CVE history across other products (Krayin CRM, Bagisto) - reputation flag rather than direct app evidence.
- ◆Publisher domain has HSTS and TLS but a permissive/empty CSP and only short HSTS max-age.
Top findingsview all
- HighMultiple CVEs in publisher's other products (Krayin CRM, Bagisto)
Analysis summary
Create AMP Pages for your Shopify Store
- ◆Publisher Webkul has a credible but average privacy policy (GDPR mention, no certifications).
- ◆App scope appears narrow (store owner contact info) and does not request write_* scopes, keeping inherent blast radius low.
- ◆Publisher has a non-trivial CVE history across other products (Krayin CRM, Bagisto) - reputation flag rather than direct app evidence.
- ◆Publisher domain has HSTS and TLS but a permissive/empty CSP and only short HSTS max-age.
- ◆Single 1-star review reports broken AMP output - quality/support concern more than security.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_store_owner_information | Medium | Access to merchant name/email/phone/address - PII but no customer or order data. Reasonable for billing/contact in a single-merchant SEO tool. |
read_store_owner_informationAccess to merchant name/email/phone/address - PII but no customer or order data. Reasonable for billing/contact in a single-merchant SEO tool.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- webkul.com
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Missing
CSP header present but only 'upgrade-insecure-requests' - no source restrictions. HSTS max-age=2592000 (~30 days), short and no preload.
Compliance & certifications
Privacy policy references GDPR legal basis but lists no third-party certifications and no concrete retention period.
Privacy policyPublisher reputation
- Publisher
- Webkul Software Pvt Ltd
- Verified Shopify Partner
- No
- Years active
- 8
- Other apps
- 0
- ●CVE-2026-38526 (Krayin CRM RCE)
- ●CVE-2026-38529 (Krayin CRM auth bypass)
- ●CVE-2026-38527 (Krayin CRM SSRF)
- ●CVE-2026-36341 (Krayin CRM XSS)
- ●CVE-2026-21448 / CVE-2026-21450 (Bagisto SSTI -> RCE)
- ●CVE-2026-21447 (Bagisto auth bypass)