Starship
starship / search / ecc-quickbooks-integration-for-shopify

Audit report

Multichannel Management

Broad accessReach : moderateSensitive Access

by Webgility, Inc. · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Automate Ecommerce Operation for QuickBooks Desktop & NetSuite

Key insights

  • Established publisher (Webgility, Inc.) with multiple Shopify apps and 878 reviews / 4.9 rating on this listing.
  • Not 'Built for Shopify' certified.
  • Broad scope set consistent with accounting/multichannel sync (QuickBooks, Xero, 30+ marketplaces).
  • Privacy policy explicitly states data is NOT shared with OpenAI.

Top findingsview all

  • High
    Broad write-level access to commerce and customer data
Synthesis

Analysis summary

Automate Ecommerce Operation for QuickBooks Desktop & NetSuite

Key insights
  • Established publisher (Webgility, Inc.) with multiple Shopify apps and 878 reviews / 4.9 rating on this listing.
  • Not 'Built for Shopify' certified.
  • Broad scope set consistent with accounting/multichannel sync (QuickBooks, Xero, 30+ marketplaces).
  • Privacy policy explicitly states data is NOT shared with OpenAI.
  • One historic vulnerability disclosure (Nov 2018), patched, no confirmed breach.
  • TLS healthy with HSTS; CSP effectively absent on marketing site.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII (name, email, phone, address, geolocation, IP), required to sync customer records to QuickBooks/Xero.

read_orders
High

Order data including line items, totals, taxes, core to accounting sync.

read_products
Medium

Product catalog needed for inventory sync.

read_discounts
Medium

Discount data needed to reconcile order totals.

read_gift_cards
High

Gift card balances are financial instruments, sensitive.

read_store_credit
High

Store credit balances are financial liabilities, sensitive.

read_analytics
Medium

Analytics aggregates, moderate sensitivity.

read_companies
Medium

B2B company records for accounting.

read_shopify_payments_payouts
High

Payout / settlement data, financial reconciliation.

read_files
Medium

File access, moderate sensitivity if invoices/attachments.

read_price_rules
Low

Price rule definitions, low sensitivity.

read_locations
Low

Location/warehouse data.

read_payment_terms
Medium

B2B payment terms metadata.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webgility.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS enforced (max-age=31536000). CSP header only contains 'upgrade-insecure-requests', no source restrictions. Cloudflare-fronted with x-frame-options SAMEORIGIN and referrer-policy set.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not assert formal certifications (SOC2/ISO27001/PCI DSS/HIPAA) and does not specify retention period or data residency. Policy explicitly states no data sharing with OpenAI.

Privacy policy
Track record

Publisher reputation

Publisher
Webgility, Inc.
Verified Shopify Partner
No
Years active
0
Other apps
3
Past incidents
  • 2018-11 · security_vulnerability_patched (https://www.webgility.com/blog/security-vulnerability-update)
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.