Audit report
Facebook Comments
Broad accessReach : limitedby Architechpro OÜ · Customer support · Shopify App Store
Add fb discussions to products and blogs
Key insights
- ◆Tiny social-proof widget app (last update 2018, 3 reviews) by Estonian publisher Architechpro OÜ, very small installed base and effectively unmaintained.
- ◆Publisher's own corporate site is a Shopify-hosted storefront fronted by Cloudflare with HSTS enabled and a minimal CSP, basic web hygiene present.
- ◆No public security incidents, CVEs, or breach disclosures found for Architechpro or this specific app.
- ◆Privacy posture is generic Shopify-app boilerplate: no sub-processor register, no retention schedule, no certifications.
Top findings
Analysis summary
Add fb discussions to products and blogs
- ◆Tiny social-proof widget app (last update 2018, 3 reviews) by Estonian publisher Architechpro OÜ, very small installed base and effectively unmaintained.
- ◆Publisher's own corporate site is a Shopify-hosted storefront fronted by Cloudflare with HSTS enabled and a minimal CSP, basic web hygiene present.
- ◆No public security incidents, CVEs, or breach disclosures found for Architechpro or this specific app.
- ◆Privacy posture is generic Shopify-app boilerplate: no sub-processor register, no retention schedule, no certifications.
- ◆Functionality requires embedding Meta's Facebook Comments SDK on the storefront, adds a Meta data-flow surface independent of the app itself.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
unknown | Info | Shopify listing page does not expose granular OAuth scopes publicly; for a Facebook comments embed widget, expected scopes are limited to read_themes/write_themes and possibly read_products for placement, but this cannot be confirmed without merchant install flow inspection. |
unknownShopify listing page does not expose granular OAuth scopes publicly; for a Facebook comments embed widget, expected scopes are limited to read_themes/write_themes and possibly read_products for placement, but this cannot be confirmed without merchant install flow inspection.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- architechpro.com
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Enabled
Publisher site is a Shopify-hosted store on Cloudflare. HSTS present (max-age=7889238, ~91 days). CSP minimal: block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests, no explicit script-src/default-src lockdown. X-Frame-Options DENY, X-Content-Type-Options nosniff, X-XSS-Protection enabled.
Compliance & certifications
GDPR referenced via DPA; no SOC 2 / ISO 27001 / PCI DSS / HIPAA disclosures. No sub-processor register, no retention schedule, no SCCs published.
Privacy policyPublisher reputation
- Publisher
- Architechpro OÜ
- Verified Shopify Partner
- No
- Years active
- 8
- Other apps
- 0