Starship
starship / search / edit-order

Audit report

Edit Order by Cleverific

Broad accessReach : broadSensitive Access

by Cleverific, Inc · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Edit customer orders & send payment requests in Shopify

Key insights

  • Vendor self-reports SOC 2 Type II certification (only SOC2 Type II certified order editing app on Shopify per vendor site)
  • 10+ years on Shopify App Store with no publicly documented breach or CVE
  • GDPR-aligned privacy policy with 90-day post-closure data deletion
  • Privacy policy lists no LLM/AI processing; app is rules-based order editing

Top findingsview all

  • High
    Write access to orders, customers, products and discounts
Synthesis

Analysis summary

Edit customer orders & send payment requests in Shopify

Key insights
  • Vendor self-reports SOC 2 Type II certification (only SOC2 Type II certified order editing app on Shopify per vendor site)
  • 10+ years on Shopify App Store with no publicly documented breach or CVE
  • GDPR-aligned privacy policy with 90-day post-closure data deletion
  • Privacy policy lists no LLM/AI processing; app is rules-based order editing
  • Publisher domain served via Cloudflare with HTTPS but no HSTS header observed
  • Rating 4.6 over 234 reviews; no Built for Shopify badge

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_orders
Critical

Required to modify line items, addresses, taxes; highest-impact scope

read_orders
High

Read order history & customer order details

write_customers
High

Update customer records as part of edits

read_customers
High

Access customer PII (name, email, phone, address, geo, IP)

write_products
High

Modify products/inventory tied to order edits

read_products
Medium

Read catalog/inventory state

write_discounts
High

Apply discount adjustments during edits

read_fulfillments
Medium

Determine fulfillment state before allowing edits

write_fulfillments
High

Adjust fulfillment when orders change

read_checkouts
Medium

Online Store checkout integration for self-serve flow

read_analytics
Low

Store analytics access declared

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
cleverific.com
TLS grade
A
HSTS
Missing
CSP
Missing

Served via Cloudflare with HTTP/2 200 and NEL reporting; HSTS and CSP headers not observed at root

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Pass
ISO 27001 Fail
PCI DSS Fail

Vendor claims SOC 2 Type II (only such order-editing app on Shopify per vendor security page). GDPR and CCPA addressed in privacy policy. Stripe verified partner. No ISO27001 or PCI DSS certifications referenced.

Privacy policy
Track record

Publisher reputation

Publisher
Cleverific, Inc
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.