Audit report
SmartPop by Eggflow
WatchReach : broadby Eggflow · Store design · Shopify App Store
Discount Popup, Coupon and Exit Popup
Key insights
- ◆App has not been updated since February 2018 (8+ years stale).
- ◆Requests theme/script-tag write access enabling arbitrary storefront JS injection.
- ◆Requests customer-edit (write) scope; no SOC2/ISO/PCI/GDPR certifications declared.
- ◆EU-based hosting per privacy policy.
Top findingsview all
- HighApp abandoned / unmaintained
- HighTheme script injection scope without active maintenance
Analysis summary
Discount Popup, Coupon and Exit Popup
- ◆App has not been updated since February 2018 (8+ years stale).
- ◆Requests theme/script-tag write access enabling arbitrary storefront JS injection.
- ◆Requests customer-edit (write) scope; no SOC2/ISO/PCI/GDPR certifications declared.
- ◆EU-based hosting per privacy policy.
- ◆Sub-processors: Google Analytics, Facebook, Shopify.
- ◆No public breach, CVE, or incident found in OSINT.
- ◆Not a 'Built for Shopify' badged app.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_store_owner_pii | Medium | Store owner name, email, phone, address, admin PII. |
write_customers | High | Edit customer data, write access to PII; broader than needed for a popup app. |
read_products | Low | View products and collections, reasonable for popup targeting. |
write_themes | High | Edit Online Store script tags and theme, full storefront JS injection capability. |
write_price_rules | Medium | Edit price rules, discount creation; could be misused to alter pricing. |
read_store_owner_piiStore owner name, email, phone, address, admin PII.
write_customersEdit customer data, write access to PII; broader than needed for a popup app.
read_productsView products and collections, reasonable for popup targeting.
write_themesEdit Online Store script tags and theme, full storefront JS injection capability.
write_price_rulesEdit price rules, discount creation; could be misused to alter pricing.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- eggflow.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Missing
HSTS present (max-age=31536000, includeSubDomains); no CSP header observed on root.
Compliance & certifications
Privacy policy exists and mentions EU hosting and 25-month retention but does not assert formal GDPR/SOC2/ISO/PCI compliance.
Privacy policyPublisher reputation
- Publisher
- Eggflow
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0