Audit report
Hello Announcements
Broad accessReach : limitedby Webyze · Store design · Shopify App Store
Welcome your customers, Give them offers and Get more sales.
Key insights
- ◆Hello Announcements is a UI-only announcement bar / banner app by Webyze (Laval, QC). Functionality (banners, countdowns, GDPR/cookie banners, email signup) does not inherently require sensitive Shopify scopes.
- ◆OAuth scopes are not declared on the public listing, Shopify's modern listing pages no longer show scopes pre-install.
- ◆Publisher domain (webyze.com) is served behind Cloudflare with TLS, but no HSTS, no CSP, and no Strict-Transport-Security headers were observed on the root response.
- ◆Privacy policy is a clearly incomplete template ('(add date)', truncated sections), which is a meaningful trust-and-transparency negative.
Top findings
Analysis summary
Welcome your customers, Give them offers and Get more sales.
- ◆Hello Announcements is a UI-only announcement bar / banner app by Webyze (Laval, QC). Functionality (banners, countdowns, GDPR/cookie banners, email signup) does not inherently require sensitive Shopify scopes.
- ◆OAuth scopes are not declared on the public listing, Shopify's modern listing pages no longer show scopes pre-install.
- ◆Publisher domain (webyze.com) is served behind Cloudflare with TLS, but no HSTS, no CSP, and no Strict-Transport-Security headers were observed on the root response.
- ◆Privacy policy is a clearly incomplete template ('(add date)', truncated sections), which is a meaningful trust-and-transparency negative.
- ◆No CVEs or breaches found for Webyze (the 'Wyze' results in search are an unrelated IoT camera company).
- ◆Webyze publishes 17 apps on the Shopify App Store, indicating an established but small ISV.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
undeclared | Info | App listing does not enumerate scopes pre-install. Based on functionality (banner injection via theme/script), likely read_themes and read_script_tags / write_script_tags, but unconfirmed. |
undeclaredApp listing does not enumerate scopes pre-install. Based on functionality (banner injection via theme/script), likely read_themes and read_script_tags / write_script_tags, but unconfirmed.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- webyze.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
webyze.com is fronted by Cloudflare (HTTP/1.1 200, server: cloudflare). No Strict-Transport-Security, Content-Security-Policy, X-Frame-Options, or X-Content-Type-Options headers observed on the root response.
Compliance & certifications
Privacy policy appears to be an unfinished template, placeholder effective date and truncated sections. No compliance certifications stated.
Privacy policyPublisher reputation
- Publisher
- Webyze
- Verified Shopify Partner
- No
- Years active
- 11
- Other apps
- 16