Starship
starship / search / facebook-messenger-live-chat

Audit report

Facebook Live Chat

Broad accessReach : broad

by Zotabox · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Free Customer Support via Facebook Live Chat

Key insights

  • Chat widget app with relatively low data exposure scope (no orders/customers write).
  • Publisher Zotabox previously had a critical XSS in their WordPress plugin variant, promptly patched but a reputation signal.
  • Privacy policy is decent for a small vendor (90-day customer retention, 30-day backup deletion) but lacks SOC2/ISO27001 attestation.
  • Data residency is undisclosed, merchants in EU may need DPA review.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Free Customer Support via Facebook Live Chat

Key insights
  • Chat widget app with relatively low data exposure scope (no orders/customers write).
  • Publisher Zotabox previously had a critical XSS in their WordPress plugin variant, promptly patched but a reputation signal.
  • Privacy policy is decent for a small vendor (90-day customer retention, 30-day backup deletion) but lacks SOC2/ISO27001 attestation.
  • Data residency is undisclosed, merchants in EU may need DPA review.
  • Sub-processor list is minimal (only FastSpring as payment processor), reducing supply-chain risk surface.
  • No declared OAuth scopes visible on listing page (chat widgets typically inject a script via theme app extension).

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_themes
Low

L'application ajoute un widget de chat sur la vitrine, ce qui suppose la lecture du thème pour identifier l'emplacement d'insertion, induit de la fonction déclarée de l'app.

write_themes
Medium

L'intégration sans code du bouton de messagerie sur la boutique nécessite la modification des fichiers de thème, induit de la fonction déclarée de l'app.

write_script_tags
Medium

L'affichage du widget Messenger et WhatsApp en temps réel repose généralement sur l'injection d'un script dans les pages de la vitrine, induit de la fonction déclarée de l'app.

read_content
Low

L'application peut consulter les pages et contenus de la boutique pour y positionner le widget de chat, induit de la fonction déclarée de l'app.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
info.zotabox.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

Cloudflare-fronted WordPress site (PHP/8.2.9). No HSTS / CSP headers observed; PHPSESSID cookie set without explicit Secure/HttpOnly flags in response headers.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR self-attested. PCI compliance only via payment processor (FastSpring). 90-day customer data retention; 30-day backup retention; inactive accounts removed after 6 months.

Privacy policy
Track record

Publisher reputation

Publisher
Zotabox
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
  • 2019 critical persistent XSS in Zotabox 'Live Chat with Facebook Messenger' WordPress plugin (>30k installs), patched same-day after disclosure.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.