Starship
starship / search / announcement-bar

Audit report

Hello Announcements

Broad accessReach : limited

by Webyze · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Welcome your customers, Give them offers and Get more sales.

Key insights

  • Hello Announcements is a UI-only announcement bar / banner app by Webyze (Laval, QC). Functionality (banners, countdowns, GDPR/cookie banners, email signup) does not inherently require sensitive Shopify scopes.
  • OAuth scopes are not declared on the public listing, Shopify's modern listing pages no longer show scopes pre-install.
  • Publisher domain (webyze.com) is served behind Cloudflare with TLS, but no HSTS, no CSP, and no Strict-Transport-Security headers were observed on the root response.
  • Privacy policy is a clearly incomplete template ('(add date)', truncated sections), which is a meaningful trust-and-transparency negative.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Welcome your customers, Give them offers and Get more sales.

Key insights
  • Hello Announcements is a UI-only announcement bar / banner app by Webyze (Laval, QC). Functionality (banners, countdowns, GDPR/cookie banners, email signup) does not inherently require sensitive Shopify scopes.
  • OAuth scopes are not declared on the public listing, Shopify's modern listing pages no longer show scopes pre-install.
  • Publisher domain (webyze.com) is served behind Cloudflare with TLS, but no HSTS, no CSP, and no Strict-Transport-Security headers were observed on the root response.
  • Privacy policy is a clearly incomplete template ('(add date)', truncated sections), which is a meaningful trust-and-transparency negative.
  • No CVEs or breaches found for Webyze (the 'Wyze' results in search are an unrelated IoT camera company).
  • Webyze publishes 17 apps on the Shopify App Store, indicating an established but small ISV.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

undeclared
Info

App listing does not enumerate scopes pre-install. Based on functionality (banner injection via theme/script), likely read_themes and read_script_tags / write_script_tags, but unconfirmed.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webyze.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

webyze.com is fronted by Cloudflare (HTTP/1.1 200, server: cloudflare). No Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, or X-Content-Type-Options headers observed on the root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy appears to be an unfinished template, placeholder effective date and truncated sections. No compliance certifications stated.

Privacy policy
Track record

Publisher reputation

Publisher
Webyze
Verified Shopify Partner
No
Years active
11
Other apps
16
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.