Starship
starship / search / eggviews

Audit report

Product Reviews + Q&A EggViews

Broad accessReach : broadSensitive Access

by Gowebbaby · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Advance Product Reviews, Site Reviews, and Photo Review, Q&A

Key insights

  • Reviews/Q&A app published as 'Gowebbaby' but operates under aitrillion.com infrastructure
  • Publisher infrastructure runs end-of-life PHP 7.4.33 on shared Hostinger hosting
  • No HSTS and only minimal CSP on primary publisher domain
  • Data transferred to Canada, US and India without named SCC safeguards

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Advance Product Reviews, Site Reviews, and Photo Review, Q&A

Key insights
  • Reviews/Q&A app published as 'Gowebbaby' but operates under aitrillion.com infrastructure
  • Publisher infrastructure runs end-of-life PHP 7.4.33 on shared Hostinger hosting
  • No HSTS and only minimal CSP on primary publisher domain
  • Data transferred to Canada, US and India without named SCC safeguards
  • Privacy policy mentions automated decision-making and AI features but does not name specific LLM providers
  • Very low review count (2) and modest 3.0 rating
  • No public breach or CVE records linked to publisher

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to attach reviews/Q&A to products (inferred; not explicitly declared on listing page)

read_customers
Medium

Typical for review-collection apps to email customers post-purchase (inferred)

read_orders
High

Likely needed to trigger post-purchase review requests (inferred)

write_script_tags
Medium

Common for review widgets to inject storefront scripts (inferred)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
aitrillion.com
TLS grade
A
HSTS
Missing
CSP
Enabled

Only 'upgrade-insecure-requests' directive; no script-src/frame-ancestors hardening. No HSTS. Server header reveals LiteSpeed on Hostinger shared hosting with PHP/7.4.33 (end-of-life).

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No certifications declared. Privacy policy addresses general data subject rights but does not name SOC2/ISO/PCI.

Privacy policy
Track record

Publisher reputation

Publisher
Gowebbaby
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.