Audit report
Business Listing with Contact
Broad accessReach : limitedby TechInfini Solutions · Store design · Shopify App Store
Let your customers find your all store locations in no time
Key insights
- ◆App appears effectively abandoned: last update Oct 2015, no reviews, no BFS badge.
- ◆Collects customer contact form submissions (PII) but routes through a publisher with weak privacy posture and India-based processing without DPA detail.
- ◆Publisher domain is a WordPress site on Hostinger behind Cloudflare; no HSTS, minimal CSP, exposes PHP version.
- ◆No public breaches or CVEs found tied to TechInfini Solutions or this specific app.
Top findingsview all
- HighApp not updated in over a decade
Analysis summary
Let your customers find your all store locations in no time
- ◆App appears effectively abandoned: last update Oct 2015, no reviews, no BFS badge.
- ◆Collects customer contact form submissions (PII) but routes through a publisher with weak privacy posture and India-based processing without DPA detail.
- ◆Publisher domain is a WordPress site on Hostinger behind Cloudflare; no HSTS, minimal CSP, exposes PHP version.
- ◆No public breaches or CVEs found tied to TechInfini Solutions or this specific app.
- ◆Primary risk vector is staleness + PII collection: unmaintained code path handling customer data is a latent supply-chain risk.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
unknown | Info | OAuth scopes are not declared on the public Shopify App Store listing for this app. Cannot be confirmed without install. |
unknownOAuth scopes are not declared on the public Shopify App Store listing for this app. Cannot be confirmed without install.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- techinfini.in
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Enabled
CSP header present but only sets 'upgrade-insecure-requests' (no source restrictions). No HSTS. Behind Cloudflare with HTTP/2. Server discloses PHP 8.3.30 and WordPress.
Compliance & certifications
Privacy policy exists but mentions no formal compliance certifications, no specific sub-processors, and uses vague retention language.
Privacy policyPublisher reputation
- Publisher
- TechInfini Solutions
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0