Starship
starship / search / calculated-prices

Audit report

Calculated Prices by Holest

WatchReach : broad

by Holest Engineering · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Watch
Executive summary

Product conditional price parameters, text inputs and uploads

Key insights

  • Publisher Holest Engineering has a documented history of vulnerabilities in sibling products (multiple 2025 CVEs in WooCommerce plugins, including a critical CVSS 9.8), raising SDLC concerns.
  • App is hosted/processed in Germany, favorable EU data residency for EU merchants.
  • Privacy policy claims customer data is processed only transiently in RAM and not persisted, reducing breach blast radius if accurate.
  • Shop metadata retention is indefinite-by-default, which conflicts with GDPR right-to-erasure expectations.

Top findingsview all

  • High
    Publisher has multiple CVEs in sibling products
Synthesis

Analysis summary

Product conditional price parameters, text inputs and uploads

Key insights
  • Publisher Holest Engineering has a documented history of vulnerabilities in sibling products (multiple 2025 CVEs in WooCommerce plugins, including a critical CVSS 9.8), raising SDLC concerns.
  • App is hosted/processed in Germany, favorable EU data residency for EU merchants.
  • Privacy policy claims customer data is processed only transiently in RAM and not persisted, reducing breach blast radius if accurate.
  • Shop metadata retention is indefinite-by-default, which conflicts with GDPR right-to-erasure expectations.
  • No 'Built for Shopify' badge, 0 reviews, low Shopify-side trust signal.
  • Publisher domain holest.com lacks basic web hardening (no HSTS, no CSP, older nginx 1.18.0).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Access to customer name, email, phone, address, geolocation, PII with notification obligations under GDPR/CCPA.

read_users
Medium

Staff data including store owner information.

write_products
Medium

Edit products, inventory, collections, needed for pricing logic but can be abused to alter catalog.

write_draft_orders
High

Edit draft orders, financial side effects; necessary for cart-side custom pricing.

write_online_store_pages
Medium

Edit Online Store content, can inject scripts or modify storefront.

write_price_rules
Medium

Edit price rules, core to pricing functionality, abuse could distort merchandising.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
holest.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

nginx/1.18.0 (Ubuntu), HTTPS works but no HSTS, no CSP, P3P present (legacy/deprecated header). Cache-Control no-store on root.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but discloses no formal compliance certifications. EU-based hosting may give de facto GDPR alignment but no DPA referenced.

Privacy policy
Track record

Publisher reputation

Publisher
Holest Engineering
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
  • CVE-2025-60243 (CVSS 9.8 Critical) Selling Commander for WooCommerce, privilege escalation
  • CVE-2025-48129 Spreadsheet Price Changer for WooCommerce, privilege escalation
  • CVE-2025-48124 Spreadsheet Price Changer for WooCommerce, path traversal
  • SQL injection in Spreadsheet Price Changer for WooCommerce
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.