Starship
starship / search / ecc-cloud-quickbooks-online-integration

Audit report

Ecommerce Accounting Software

Broad accessReach : broadSensitive Access

by Webgility, Inc. · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Automate ecommerce accounting for QuickBooks Online & Xero.

Key insights

  • Established multichannel ecommerce accounting vendor (Webgility, Inc.), 4.9 rating with 476 reviews on Shopify App Store
  • Scopes are broad (PII + write_inventory + write_fulfillment) but consistent with QuickBooks reconciliation use case
  • Privacy policy explicitly disclaims sharing with OpenAI; no LLM/AI processing of customer data declared
  • Publisher domain has HSTS + valid TLS via Cloudflare; CSP is minimal

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Automate ecommerce accounting for QuickBooks Online & Xero.

Key insights
  • Established multichannel ecommerce accounting vendor (Webgility, Inc.), 4.9 rating with 476 reviews on Shopify App Store
  • Scopes are broad (PII + write_inventory + write_fulfillment) but consistent with QuickBooks reconciliation use case
  • Privacy policy explicitly disclaims sharing with OpenAI; no LLM/AI processing of customer data declared
  • Publisher domain has HSTS + valid TLS via Cloudflare; CSP is minimal
  • One historical (2018) vulnerability disclosure, patched, no reported customer data exposure
  • Not 'Built for Shopify' badged

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII (name, email, phone, address) needed for accounting record matching

read_orders
High

Order data is core to accounting reconciliation

write_orders
High

Implied via fulfillment/returns sync; broader than read-only

read_products
Medium

Product catalog needed for inventory sync

write_products
High

Product listings/publications writes for inventory updates

read_inventory
Medium

Inventory sync to QuickBooks

write_inventory
High

Inventory level updates across channels

read_fulfillments
Medium

Order fulfillment tracking

write_fulfillments
High

Fulfillment + shipping updates

read_returns
Medium

Returns handling for accounting

read_discounts
Medium

Discount data for accurate ledger entries

read_gift_cards
High

Gift card data is financial and PII-adjacent

read_shipping
Low

Shipping info for cost reconciliation

read_publications
Low

Channel publication metadata

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webgility.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

HSTS max-age=31536000 enabled; CSP only sets 'upgrade-insecure-requests' (no script-src/frame-ancestors). Cloudflare-fronted.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy present (updated Oct 16, 2025) but does not enumerate certifications. Third-party sources mention GDPR/CCPA compliance and PEN testing, but not confirmed in policy text.

Privacy policy
Track record

Publisher reputation

Publisher
Webgility, Inc.
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
  • {"year":2018,"summary":"Store-connection module vulnerability patched; no customer data breach","evidence":"https://www.webgility.com/blog/security-vulnerability-update"}
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.