Starship
starship / search / carbon-checkout-1

Audit report

Carbon Checkout

WatchReach : broad

by Carbon Checkout · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

Elevate your brand by aligning with a cause

Key insights

  • App listing has been rebranded from 'Carbon Checkout' to 'Shift - Cause in Commerce' under publisher Shift Global, while privacy contacts still point to carboncheckout.com.
  • Publisher domain shiftglobal.io is hosted on Shopify infrastructure with HSTS and a minimal CSP (block-all-mixed-content, frame-ancestors 'none').
  • Requested scopes are broad (theme + script tags + customer PII + orders) for what is essentially a checkout-donation widget, exceeding the principle of least privilege.
  • No SOC2 / ISO27001 / GDPR commitments in the privacy policy; only PCI-DSS via Shopify's payment pipeline.

Top findingsview all

  • High
    Broad write scopes on storefront, theme, products and orders
  • High
    Access to sensitive customer PII including IP and geolocation
Synthesis

Analysis summary

Elevate your brand by aligning with a cause

Key insights
  • App listing has been rebranded from 'Carbon Checkout' to 'Shift - Cause in Commerce' under publisher Shift Global, while privacy contacts still point to carboncheckout.com.
  • Publisher domain shiftglobal.io is hosted on Shopify infrastructure with HSTS and a minimal CSP (block-all-mixed-content, frame-ancestors 'none').
  • Requested scopes are broad (theme + script tags + customer PII + orders) for what is essentially a checkout-donation widget, exceeding the principle of least privilege.
  • No SOC2 / ISO27001 / GDPR commitments in the privacy policy; only PCI-DSS via Shopify's payment pipeline.
  • No CVEs or breaches found publicly attributable to Shift Global / Carbon Checkout.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_themes
High

Allows writing to theme files used by every storefront visitor; persistent XSS / data-exfil risk vector.

write_script_tags
High

Allows injection of JavaScript on storefront pages; high impact if compromised.

write_products
Medium

Edit catalog data; integrity risk on merchandising.

write_orders
High

Can mutate order objects; financial/order integrity risk.

read_customers
High

Access to sensitive PII including name, email, IP and geolocation.

read_orders
Medium

Access to order history including customer-line-item data.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shiftglobal.io
TLS grade
A
HSTS
Enabled
CSP
Enabled

Shopify-hosted domain with HSTS (max-age ~3 months), CSP limited to block-all-mixed-content and frame-ancestors 'none'; x-frame-options DENY; x-content-type-options nosniff. No application-level CSP customisation.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Pass

PCI-DSS referenced only through Shopify's payment processing. No explicit GDPR rights, SOC2 or ISO27001 attestations. Sub-processor disclosure incomplete.

Privacy policy
Track record

Publisher reputation

Publisher
Carbon Checkout
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.