Starship
starship / search / amp-google

Audit report

AMP

Broad accessReach : broad

by Shop Sheriff · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

AMP (Google AMP, Amped pages, Speed & SEO with the AMP cache)

Key insights

  • AMP/PWA theme-extension app by Shop Sheriff, Built for Shopify, 4.9 rating, last updated July 2025.
  • Publisher TLS terminates on Cloudflare/Heroku stack but lacks HSTS and CSP headers.
  • Privacy policy exists but does not publicly disclose sub-processors, residency or retention.
  • No CVEs or public breach history tied to Shop Sheriff identified in OSINT.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

AMP (Google AMP, Amped pages, Speed & SEO with the AMP cache)

Key insights
  • AMP/PWA theme-extension app by Shop Sheriff, Built for Shopify, 4.9 rating, last updated July 2025.
  • Publisher TLS terminates on Cloudflare/Heroku stack but lacks HSTS and CSP headers.
  • Privacy policy exists but does not publicly disclose sub-processors, residency or retention.
  • No CVEs or public breach history tied to Shop Sheriff identified in OSINT.
  • Scope set is theme-extension and storefront content oriented; no admin write_* scopes observable from listing.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to render AMP product pages.

read_themes
Medium

Theme-extension app likely needs to read theme to inject AMP templates.

write_themes
High

AMP/PWA theme injection plausibly requires theme write access; sensitive as it touches storefront markup.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shopsheriff.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

Cloudflare-fronted Heroku origin (Express); no HSTS, no CSP, NEL/Report-To enabled.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL exists but no compliance certifications or sub-processor list are publicly disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
Shop Sheriff
Verified Shopify Partner
Yes
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.