Starship
starship / search / edit-cart

Audit report

Cart Pencil

Broad accessReach : broad

by MLveda · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Edit Variant from Cart & Reduce Abandoned Carts - Edit Order

Key insights

  • Cart Pencil is a small-footprint cart-editing utility by MLveda (legal entity Webloudspeaker Pvt Ltd), 4.8 stars / 36 reviews.
  • Privacy policy exists but is generic and missing residency, retention, and sub-processor disclosure.
  • Publisher marketing site is hosted on Webflow (us-east-1) behind Cloudflare with valid TLS but no HSTS.
  • No public breach/CVE history for the publisher or app.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Edit Variant from Cart & Reduce Abandoned Carts - Edit Order

Key insights
  • Cart Pencil is a small-footprint cart-editing utility by MLveda (legal entity Webloudspeaker Pvt Ltd), 4.8 stars / 36 reviews.
  • Privacy policy exists but is generic and missing residency, retention, and sub-processor disclosure.
  • Publisher marketing site is hosted on Webflow (us-east-1) behind Cloudflare with valid TLS but no HSTS.
  • No public breach/CVE history for the publisher or app.
  • OAuth scope list was not exposed in the App Store listing fetch; functional scope is consistent with cart/storefront variant editing (read/write theme + storefront).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_themes
High

Cart-page editing functionality requires modifying theme/cart template assets (storefront injection).

read_themes
Medium

Needed to detect cart template and embed app block.

read_products
Low

Needed to render product variant options on the cart page.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
mlveda.com
TLS grade
A
HSTS
Missing
CSP
Enabled

CSP header present but only sets frame-ancestors (Webflow default); no script-src/default-src restrictions. HSTS absent.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but does not name any compliance certifications, hosting region, retention period, or sub-processors.

Privacy policy
Track record

Publisher reputation

Publisher
MLveda
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.