Starship
starship / search / erplain

Audit report

erplain Inventory

Broad accessReach : broadSensitive Access

by erplain · Inventory management · Shopify App Store

Inventory management
Risk level
Broad access
Executive summary

The trusted co-pilot for business owners

Key insights

  • Inventory/B2B sales automation app by erplain SAS
  • Requests edit access to customers, products, orders (write-level)
  • Publisher domain serves HTTPS with HSTS (max-age=31536000)
  • CSP only restricts frame-ancestors; no broader content protection

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

The trusted co-pilot for business owners

Key insights
  • Inventory/B2B sales automation app by erplain SAS
  • Requests edit access to customers, products, orders (write-level)
  • Publisher domain serves HTTPS with HSTS (max-age=31536000)
  • CSP only restricts frame-ancestors; no broader content protection
  • Privacy policy is minimal, no named sub-processors, retention, or residency
  • No AI/LLM usage disclosed
  • No public breach, CVE, or incident history found
  • Site fronted by Cloudflare; hosted in us-east-1 (Webflow infra)

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_customers
High

Edit access to customer PII (name, email, phone, address)

write_products
Medium

Required for inventory sync and product edits

write_orders
High

Edit access to orders is sensitive; could modify financial records

read_shopify_payments
High

Visibility into payments data

read_locations
Low

Needed for multi-location inventory tracking

read_customer_browser_data
Medium

App receives geolocation, IP, browser/OS data per Shopify scope block

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
erplain.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

CSP only sets frame-ancestors 'self'; no script-src/default-src restrictions. HSTS enabled with 1-year max-age. Cloudflare-fronted.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists (last updated May 2023) but does not assert specific certifications, name sub-processors, or specify retention/residency.

Privacy policy
Track record

Publisher reputation

Publisher
erplain
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.