Audit report
Carbon Checkout
WatchReach : broadby Carbon Checkout · Store design · Shopify App Store
Elevate your brand by aligning with a cause
Key insights
- ◆App listing has been rebranded from 'Carbon Checkout' to 'Shift - Cause in Commerce' under publisher Shift Global, while privacy contacts still point to carboncheckout.com.
- ◆Publisher domain shiftglobal.io is hosted on Shopify infrastructure with HSTS and a minimal CSP (block-all-mixed-content, frame-ancestors 'none').
- ◆Requested scopes are broad (theme + script tags + customer PII + orders) for what is essentially a checkout-donation widget, exceeding the principle of least privilege.
- ◆No SOC2 / ISO27001 / GDPR commitments in the privacy policy; only PCI-DSS via Shopify's payment pipeline.
Top findingsview all
- HighBroad write scopes on storefront, theme, products and orders
- HighAccess to sensitive customer PII including IP and geolocation
Analysis summary
Elevate your brand by aligning with a cause
- ◆App listing has been rebranded from 'Carbon Checkout' to 'Shift - Cause in Commerce' under publisher Shift Global, while privacy contacts still point to carboncheckout.com.
- ◆Publisher domain shiftglobal.io is hosted on Shopify infrastructure with HSTS and a minimal CSP (block-all-mixed-content, frame-ancestors 'none').
- ◆Requested scopes are broad (theme + script tags + customer PII + orders) for what is essentially a checkout-donation widget, exceeding the principle of least privilege.
- ◆No SOC2 / ISO27001 / GDPR commitments in the privacy policy; only PCI-DSS via Shopify's payment pipeline.
- ◆No CVEs or breaches found publicly attributable to Shift Global / Carbon Checkout.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
write_themes | High | Allows writing to theme files used by every storefront visitor; persistent XSS / data-exfil risk vector. |
write_script_tags | High | Allows injection of JavaScript on storefront pages; high impact if compromised. |
write_products | Medium | Edit catalog data; integrity risk on merchandising. |
write_orders | High | Can mutate order objects; financial/order integrity risk. |
read_customers | High | Access to sensitive PII including name, email, IP and geolocation. |
read_orders | Medium | Access to order history including customer-line-item data. |
write_themesAllows writing to theme files used by every storefront visitor; persistent XSS / data-exfil risk vector.
write_script_tagsAllows injection of JavaScript on storefront pages; high impact if compromised.
write_productsEdit catalog data; integrity risk on merchandising.
write_ordersCan mutate order objects; financial/order integrity risk.
read_customersAccess to sensitive PII including name, email, IP and geolocation.
read_ordersAccess to order history including customer-line-item data.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shiftglobal.io
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
Shopify-hosted domain with HSTS (max-age ~3 months), CSP limited to block-all-mixed-content and frame-ancestors 'none'; x-frame-options DENY; x-content-type-options nosniff. No application-level CSP customisation.
Compliance & certifications
PCI-DSS referenced only through Shopify's payment processing. No explicit GDPR rights, SOC2 or ISO27001 attestations. Sub-processor disclosure incomplete.
Privacy policyPublisher reputation
- Publisher
- Carbon Checkout
- Verified Shopify Partner
- No
- Years active
- 10
- Other apps
- 0