Audit report
Calculated Prices by Holest
WatchReach : broadby Holest Engineering · Sales and conversion optimization · Shopify App Store
Product conditional price parameters, text inputs and uploads
Key insights
- ◆Publisher Holest Engineering has a documented history of vulnerabilities in sibling products (multiple 2025 CVEs in WooCommerce plugins, including a critical CVSS 9.8), raising SDLC concerns.
- ◆App is hosted/processed in Germany, favorable EU data residency for EU merchants.
- ◆Privacy policy claims customer data is processed only transiently in RAM and not persisted, reducing breach blast radius if accurate.
- ◆Shop metadata retention is indefinite-by-default, which conflicts with GDPR right-to-erasure expectations.
Top findingsview all
- HighPublisher has multiple CVEs in sibling products
Analysis summary
Product conditional price parameters, text inputs and uploads
- ◆Publisher Holest Engineering has a documented history of vulnerabilities in sibling products (multiple 2025 CVEs in WooCommerce plugins, including a critical CVSS 9.8), raising SDLC concerns.
- ◆App is hosted/processed in Germany, favorable EU data residency for EU merchants.
- ◆Privacy policy claims customer data is processed only transiently in RAM and not persisted, reducing breach blast radius if accurate.
- ◆Shop metadata retention is indefinite-by-default, which conflicts with GDPR right-to-erasure expectations.
- ◆No 'Built for Shopify' badge, 0 reviews, low Shopify-side trust signal.
- ◆Publisher domain holest.com lacks basic web hardening (no HSTS, no CSP, older nginx 1.18.0).
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Access to customer name, email, phone, address, geolocation, PII with notification obligations under GDPR/CCPA. |
read_users | Medium | Staff data including store owner information. |
write_products | Medium | Edit products, inventory, collections, needed for pricing logic but can be abused to alter catalog. |
write_draft_orders | High | Edit draft orders, financial side effects; necessary for cart-side custom pricing. |
write_online_store_pages | Medium | Edit Online Store content, can inject scripts or modify storefront. |
write_price_rules | Medium | Edit price rules, core to pricing functionality, abuse could distort merchandising. |
read_customersAccess to customer name, email, phone, address, geolocation, PII with notification obligations under GDPR/CCPA.
read_usersStaff data including store owner information.
write_productsEdit products, inventory, collections, needed for pricing logic but can be abused to alter catalog.
write_draft_ordersEdit draft orders, financial side effects; necessary for cart-side custom pricing.
write_online_store_pagesEdit Online Store content, can inject scripts or modify storefront.
write_price_rulesEdit price rules, core to pricing functionality, abuse could distort merchandising.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- holest.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
nginx/1.18.0 (Ubuntu), HTTPS works but no HSTS, no CSP, P3P present (legacy/deprecated header). Cache-Control no-store on root.
Compliance & certifications
Privacy policy exists but discloses no formal compliance certifications. EU-based hosting may give de facto GDPR alignment but no DPA referenced.
Privacy policyPublisher reputation
- Publisher
- Holest Engineering
- Verified Shopify Partner
- No
- Years active
- 8
- Other apps
- 0
- ●CVE-2025-60243 (CVSS 9.8 Critical) Selling Commander for WooCommerce, privilege escalation
- ●CVE-2025-48129 Spreadsheet Price Changer for WooCommerce, privilege escalation
- ●CVE-2025-48124 Spreadsheet Price Changer for WooCommerce, path traversal
- ●SQL injection in Spreadsheet Price Changer for WooCommerce