Starship
starship / search / care-cart

Audit report

Care Cart Abandoned Recovery

Broad accessReach : broadSensitive Access

by Care Cart · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Recover Abandon Cart Orders by Sales & Marketing Automation

Key insights

  • Established cart-recovery app (launched Oct 2017) with strong rating (4.8/240 reviews) but no Built for Shopify badge.
  • Privacy policy is GDPR-aware but light on concrete commitments: no named sub-processors, no specific retention windows, no third-party security attestations.
  • Data is stated to be stored in US or EU hosting facilities, while Care Cart apps run on Canadian hosting per the policy, split residency.
  • No public CVEs, breaches, or security incidents tied to Care Cart / carecart.io were found in open sources.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Recover Abandon Cart Orders by Sales & Marketing Automation

Key insights
  • Established cart-recovery app (launched Oct 2017) with strong rating (4.8/240 reviews) but no Built for Shopify badge.
  • Privacy policy is GDPR-aware but light on concrete commitments: no named sub-processors, no specific retention windows, no third-party security attestations.
  • Data is stated to be stored in US or EU hosting facilities, while Care Cart apps run on Canadian hosting per the policy, split residency.
  • No public CVEs, breaches, or security incidents tied to Care Cart / carecart.io were found in open sources.
  • Scope set (customers, orders, checkouts, themes, price rules) is consistent with the abandoned-cart use case; broadest concern is the breadth of customer PII (IP, geo, browser) collected for marketing.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII (name, email, address, geo, IP) needed to target recovery emails; high impact on compromise.

write_customers
High

Implied to update customer marketing-consent/subscriber state; write access to PII is sensitive.

read_orders
High

60-day order history used for follow-up campaigns; reveals revenue and buyer behavior.

read_checkouts
High

Abandoned-checkout data including line items and contact details is core to the product.

write_checkouts
High

Needed to trigger/modify recovery flows; can influence storefront conversion path.

read_products
Medium

Product catalog used to render recovery emails/popups.

read_themes
Medium

Theme read access to inject web-push and on-site widgets.

write_themes
High

Theme write needed for asset/snippet injection; widely abused vector if compromised.

read_price_rules
Medium

Discount/spin-wheel feature uses price rules.

write_price_rules
High

Creating discount codes for recovery campaigns; financial impact if abused.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
carecart.io
TLS grade
unknown
HSTS
Enabled
CSP
Missing

HSTS enabled (max-age=31536000; includeSubDomains). No CSP header observed on landing page. Server discloses PHP 8.2.29 via X-Powered-By and exposes WordPress wp-json endpoint.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Only GDPR explicitly referenced. Payment data not stored by Care Cart (handled by Shopify). No SOC 2 / ISO 27001 / PCI DSS / HIPAA attestations disclosed publicly.

Privacy policy
Track record

Publisher reputation

Publisher
Care Cart
Verified Shopify Partner
No
Years active
9
Other apps
7
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.