Audit report
Multichannel Management
Broad accessReach : moderateSensitive Accessby Webgility, Inc. · Orders and shipping · Shopify App Store
Automate Ecommerce Operation for QuickBooks Desktop & NetSuite
Key insights
- ◆Established publisher (Webgility, Inc.) with multiple Shopify apps and 878 reviews / 4.9 rating on this listing.
- ◆Not 'Built for Shopify' certified.
- ◆Broad scope set consistent with accounting/multichannel sync (QuickBooks, Xero, 30+ marketplaces).
- ◆Privacy policy explicitly states data is NOT shared with OpenAI.
Top findingsview all
- HighBroad write-level access to commerce and customer data
Analysis summary
Automate Ecommerce Operation for QuickBooks Desktop & NetSuite
- ◆Established publisher (Webgility, Inc.) with multiple Shopify apps and 878 reviews / 4.9 rating on this listing.
- ◆Not 'Built for Shopify' certified.
- ◆Broad scope set consistent with accounting/multichannel sync (QuickBooks, Xero, 30+ marketplaces).
- ◆Privacy policy explicitly states data is NOT shared with OpenAI.
- ◆One historic vulnerability disclosure (Nov 2018), patched, no confirmed breach.
- ◆TLS healthy with HSTS; CSP effectively absent on marketing site.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Customer PII (name, email, phone, address, geolocation, IP), required to sync customer records to QuickBooks/Xero. |
read_orders | High | Order data including line items, totals, taxes, core to accounting sync. |
read_products | Medium | Product catalog needed for inventory sync. |
read_discounts | Medium | Discount data needed to reconcile order totals. |
read_gift_cards | High | Gift card balances are financial instruments, sensitive. |
read_store_credit | High | Store credit balances are financial liabilities, sensitive. |
read_analytics | Medium | Analytics aggregates, moderate sensitivity. |
read_companies | Medium | B2B company records for accounting. |
read_shopify_payments_payouts | High | Payout / settlement data, financial reconciliation. |
read_files | Medium | File access, moderate sensitivity if invoices/attachments. |
read_price_rules | Low | Price rule definitions, low sensitivity. |
read_locations | Low | Location/warehouse data. |
read_payment_terms | Medium | B2B payment terms metadata. |
read_customersCustomer PII (name, email, phone, address, geolocation, IP), required to sync customer records to QuickBooks/Xero.
read_ordersOrder data including line items, totals, taxes, core to accounting sync.
read_productsProduct catalog needed for inventory sync.
read_discountsDiscount data needed to reconcile order totals.
read_gift_cardsGift card balances are financial instruments, sensitive.
read_store_creditStore credit balances are financial liabilities, sensitive.
read_analyticsAnalytics aggregates, moderate sensitivity.
read_companiesB2B company records for accounting.
read_shopify_payments_payoutsPayout / settlement data, financial reconciliation.
read_filesFile access, moderate sensitivity if invoices/attachments.
read_price_rulesPrice rule definitions, low sensitivity.
read_locationsLocation/warehouse data.
read_payment_termsB2B payment terms metadata.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- webgility.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS enforced (max-age=31536000). CSP header only contains 'upgrade-insecure-requests', no source restrictions. Cloudflare-fronted with x-frame-options SAMEORIGIN and referrer-policy set.
Compliance & certifications
Privacy policy exists but does not assert formal certifications (SOC2/ISO27001/PCI DSS/HIPAA) and does not specify retention period or data residency. Policy explicitly states no data sharing with OpenAI.
Privacy policyPublisher reputation
- Publisher
- Webgility, Inc.
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 3
- ●2018-11 · security_vulnerability_patched (https://www.webgility.com/blog/security-vulnerability-update)