Starship
starship / search / eggflow-marketing-automation

Audit report

SmartPop by Eggflow

WatchReach : broad

by Eggflow · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

Discount Popup, Coupon and Exit Popup

Key insights

  • App has not been updated since February 2018 (8+ years stale).
  • Requests theme/script-tag write access enabling arbitrary storefront JS injection.
  • Requests customer-edit (write) scope; no SOC2/ISO/PCI/GDPR certifications declared.
  • EU-based hosting per privacy policy.

Top findingsview all

  • High
    App abandoned / unmaintained
  • High
    Theme script injection scope without active maintenance
Synthesis

Analysis summary

Discount Popup, Coupon and Exit Popup

Key insights
  • App has not been updated since February 2018 (8+ years stale).
  • Requests theme/script-tag write access enabling arbitrary storefront JS injection.
  • Requests customer-edit (write) scope; no SOC2/ISO/PCI/GDPR certifications declared.
  • EU-based hosting per privacy policy.
  • Sub-processors: Google Analytics, Facebook, Shopify.
  • No public breach, CVE, or incident found in OSINT.
  • Not a 'Built for Shopify' badged app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_store_owner_pii
Medium

Store owner name, email, phone, address, admin PII.

write_customers
High

Edit customer data, write access to PII; broader than needed for a popup app.

read_products
Low

View products and collections, reasonable for popup targeting.

write_themes
High

Edit Online Store script tags and theme, full storefront JS injection capability.

write_price_rules
Medium

Edit price rules, discount creation; could be misused to alter pricing.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
eggflow.com
TLS grade
A
HSTS
Enabled
CSP
Missing

HSTS present (max-age=31536000, includeSubDomains); no CSP header observed on root.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists and mentions EU hosting and 25-month retention but does not assert formal GDPR/SOC2/ISO/PCI compliance.

Privacy policy
Track record

Publisher reputation

Publisher
Eggflow
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.