Starship
starship / search / announcement-bar-maker-by-apphero

Audit report

Announcement Bar Maker

Broad accessReach : broadSensitive Access

by AppHero · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Easily Display Announcements, Offers and Special Events

Key insights

  • Built for Shopify certified app, Shopify has reviewed for performance and quality (not a security certification).
  • Strong consumer signal: 5.0 rating across 948 reviews suggests stable operation, low complaint volume.
  • Privacy policy is thin: no sub-processors, no residency, no compliance certs, last updated Dec 2021.
  • Write scopes (theme + discounts) elevate baseline risk versus read-only apps.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Easily Display Announcements, Offers and Special Events

Key insights
  • Built for Shopify certified app, Shopify has reviewed for performance and quality (not a security certification).
  • Strong consumer signal: 5.0 rating across 948 reviews suggests stable operation, low complaint volume.
  • Privacy policy is thin: no sub-processors, no residency, no compliance certs, last updated Dec 2021.
  • Write scopes (theme + discounts) elevate baseline risk versus read-only apps.
  • Publisher domain (attrac.io) fronted by Cloudflare with HSTS; no public CSP, no known breach or CVE.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII (name, email, phone, address), high value if breached.

read_orders
High

Order data is sensitive commercial information.

read_products
Low

Product catalog is generally non-sensitive.

write_discounts
High

Discount code editing can be abused for fraud (free codes, gift card draining) if compromised.

write_themes
Critical

Theme write access permits arbitrary JS injection in storefront, primary supply-chain attack vector.

read_online_store_pages
Medium

Required to render announcement bars; moderate exposure.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
attrac.io
TLS grade
A
HSTS
Enabled
CSP
Missing

Cloudflare-fronted with HSTS max-age=31536000. No Content-Security-Policy header observed on root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Policy acknowledges EU resident rights (access/correct/delete) but does not claim formal GDPR controllership terms, DPA, or any compliance certifications. Last update Dec 2021.

Privacy policy
Track record

Publisher reputation

Publisher
AppHero
Verified Shopify Partner
Yes
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.