Audit report
erplain Inventory
Broad accessReach : broadSensitive Accessby erplain · Inventory management · Shopify App Store
The trusted co-pilot for business owners
Key insights
- ◆Inventory/B2B sales automation app by erplain SAS
- ◆Requests edit access to customers, products, orders (write-level)
- ◆Publisher domain serves HTTPS with HSTS (max-age=31536000)
- ◆CSP only restricts frame-ancestors; no broader content protection
Top findings
Analysis summary
The trusted co-pilot for business owners
- ◆Inventory/B2B sales automation app by erplain SAS
- ◆Requests edit access to customers, products, orders (write-level)
- ◆Publisher domain serves HTTPS with HSTS (max-age=31536000)
- ◆CSP only restricts frame-ancestors; no broader content protection
- ◆Privacy policy is minimal, no named sub-processors, retention, or residency
- ◆No AI/LLM usage disclosed
- ◆No public breach, CVE, or incident history found
- ◆Site fronted by Cloudflare; hosted in us-east-1 (Webflow infra)
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
write_customers | High | Edit access to customer PII (name, email, phone, address) |
write_products | Medium | Required for inventory sync and product edits |
write_orders | High | Edit access to orders is sensitive; could modify financial records |
read_shopify_payments | High | Visibility into payments data |
read_locations | Low | Needed for multi-location inventory tracking |
read_customer_browser_data | Medium | App receives geolocation, IP, browser/OS data per Shopify scope block |
write_customersEdit access to customer PII (name, email, phone, address)
write_productsRequired for inventory sync and product edits
write_ordersEdit access to orders is sensitive; could modify financial records
read_shopify_paymentsVisibility into payments data
read_locationsNeeded for multi-location inventory tracking
read_customer_browser_dataApp receives geolocation, IP, browser/OS data per Shopify scope block
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- erplain.com
- TLS grade
- A
- HSTS
- Enabled
- CSP
- Enabled
CSP only sets frame-ancestors 'self'; no script-src/default-src restrictions. HSTS enabled with 1-year max-age. Cloudflare-fronted.
Compliance & certifications
Privacy policy exists (last updated May 2023) but does not assert specific certifications, name sub-processors, or specify retention/residency.
Privacy policyPublisher reputation
- Publisher
- erplain
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0