Audit report
Announcement Bar Maker
Broad accessReach : broadSensitive Accessby AppHero · Store design · Shopify App Store
Easily Display Announcements, Offers and Special Events
Key insights
- ◆Built for Shopify certified app, Shopify has reviewed for performance and quality (not a security certification).
- ◆Strong consumer signal: 5.0 rating across 948 reviews suggests stable operation, low complaint volume.
- ◆Privacy policy is thin: no sub-processors, no residency, no compliance certs, last updated Dec 2021.
- ◆Write scopes (theme + discounts) elevate baseline risk versus read-only apps.
Top findings
Analysis summary
Easily Display Announcements, Offers and Special Events
- ◆Built for Shopify certified app, Shopify has reviewed for performance and quality (not a security certification).
- ◆Strong consumer signal: 5.0 rating across 948 reviews suggests stable operation, low complaint volume.
- ◆Privacy policy is thin: no sub-processors, no residency, no compliance certs, last updated Dec 2021.
- ◆Write scopes (theme + discounts) elevate baseline risk versus read-only apps.
- ◆Publisher domain (attrac.io) fronted by Cloudflare with HSTS; no public CSP, no known breach or CVE.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Customer PII (name, email, phone, address), high value if breached. |
read_orders | High | Order data is sensitive commercial information. |
read_products | Low | Product catalog is generally non-sensitive. |
write_discounts | High | Discount code editing can be abused for fraud (free codes, gift card draining) if compromised. |
write_themes | Critical | Theme write access permits arbitrary JS injection in storefront, primary supply-chain attack vector. |
read_online_store_pages | Medium | Required to render announcement bars; moderate exposure. |
read_customersCustomer PII (name, email, phone, address), high value if breached.
read_ordersOrder data is sensitive commercial information.
read_productsProduct catalog is generally non-sensitive.
write_discountsDiscount code editing can be abused for fraud (free codes, gift card draining) if compromised.
write_themesTheme write access permits arbitrary JS injection in storefront, primary supply-chain attack vector.
read_online_store_pagesRequired to render announcement bars; moderate exposure.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- attrac.io
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
Cloudflare-fronted with HSTS max-age=31536000. No Content-Security-Policy header observed on root response.
Compliance & certifications
Policy acknowledges EU resident rights (access/correct/delete) but does not claim formal GDPR controllership terms, DPA, or any compliance certifications. Last update Dec 2021.
Privacy policyPublisher reputation
- Publisher
- AppHero
- Verified Shopify Partner
- Yes
- Years active
- 8
- Other apps
- 0