Starship
starship / search / business-listing-with-contact-form

Audit report

Business Listing with Contact

Broad accessReach : limited

by TechInfini Solutions · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Let your customers find your all store locations in no time

Key insights

  • App appears effectively abandoned: last update Oct 2015, no reviews, no BFS badge.
  • Collects customer contact form submissions (PII) but routes through a publisher with weak privacy posture and India-based processing without DPA detail.
  • Publisher domain is a WordPress site on Hostinger behind Cloudflare; no HSTS, minimal CSP, exposes PHP version.
  • No public breaches or CVEs found tied to TechInfini Solutions or this specific app.

Top findingsview all

  • High
    App not updated in over a decade
Synthesis

Analysis summary

Let your customers find your all store locations in no time

Key insights
  • App appears effectively abandoned: last update Oct 2015, no reviews, no BFS badge.
  • Collects customer contact form submissions (PII) but routes through a publisher with weak privacy posture and India-based processing without DPA detail.
  • Publisher domain is a WordPress site on Hostinger behind Cloudflare; no HSTS, minimal CSP, exposes PHP version.
  • No public breaches or CVEs found tied to TechInfini Solutions or this specific app.
  • Primary risk vector is staleness + PII collection: unmaintained code path handling customer data is a latent supply-chain risk.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

unknown
Info

OAuth scopes are not declared on the public Shopify App Store listing for this app. Cannot be confirmed without install.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
techinfini.in
TLS grade
unknown
HSTS
Missing
CSP
Enabled

CSP header present but only sets 'upgrade-insecure-requests' (no source restrictions). No HSTS. Behind Cloudflare with HTTP/2. Server discloses PHP 8.3.30 and WordPress.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but mentions no formal compliance certifications, no specific sub-processors, and uses vague retention language.

Privacy policy
Track record

Publisher reputation

Publisher
TechInfini Solutions
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.