Starship
starship / search / coming-soon-products

Audit report

Coming Soon Products Preorders

WatchReach : limited

by Gravity Software Ltd · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

Create PreOrder and Coming Soon products.

Key insights

  • Single-developer SaaS from Konstantynów Łódzki, Poland; data is stored/processed in Poland (EU residency).
  • Publisher web stack is severely outdated (nginx 1.10.3, EoL since 2017) with no HSTS and no CSP, basic web hygiene gaps suggest weak security posture.
  • Privacy policy is legally stale (cites Data Protection Act 1998) and lacks sub-processors, retention, and any compliance certifications.
  • Built for Shopify badge present and app live since 2017 with ~58 reviews / 3.7 stars; not a high-volume, high-revenue publisher.

Top findingsview all

  • High
    No HSTS enforced on publisher domain
  • High
    No Content-Security-Policy header on publisher domain
  • High
    Outdated webserver (nginx/1.10.3 on Ubuntu)
Synthesis

Analysis summary

Create PreOrder and Coming Soon products.

Key insights
  • Single-developer SaaS from Konstantynów Łódzki, Poland; data is stored/processed in Poland (EU residency).
  • Publisher web stack is severely outdated (nginx 1.10.3, EoL since 2017) with no HSTS and no CSP, basic web hygiene gaps suggest weak security posture.
  • Privacy policy is legally stale (cites Data Protection Act 1998) and lacks sub-processors, retention, and any compliance certifications.
  • Built for Shopify badge present and app live since 2017 with ~58 reviews / 3.7 stars; not a high-volume, high-revenue publisher.
  • No CVEs, breaches, or security incidents tied to Gravity Software Ltd surfaced in public searches.
  • No AI/LLM processing disclosed; functionality is straightforward preorder/coming-soon merchandising.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

unknown
Info

App Store listing page did not expose declared OAuth scopes via the public listing fetch; scopes typically require initiating OAuth to enumerate. Pre-order functionality plausibly needs read/write_products and read/write_orders, but this is not confirmed from public evidence.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
gravity-software.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

nginx/1.10.3 (EoL 2017); no HSTS; no CSP; permissive ACAO:* with ACAC:true (invalid combo); HTTP/2 served.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy references obsolete UK Data Protection Act 1998; no certifications claimed; data transferred to and stored in Poland; no sub-processors or retention disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
Gravity Software Ltd
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.