Starship
starship / search / facebook-product-comments

Audit report

Facebook Comments

Broad accessReach : limited

by Architechpro OÜ · Customer support · Shopify App Store

Customer support
Risk level
Broad access
Executive summary

Add fb discussions to products and blogs

Key insights

  • Tiny social-proof widget app (last update 2018, 3 reviews) by Estonian publisher Architechpro OÜ, very small installed base and effectively unmaintained.
  • Publisher's own corporate site is a Shopify-hosted storefront fronted by Cloudflare with HSTS enabled and a minimal CSP, basic web hygiene present.
  • No public security incidents, CVEs, or breach disclosures found for Architechpro or this specific app.
  • Privacy posture is generic Shopify-app boilerplate: no sub-processor register, no retention schedule, no certifications.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Add fb discussions to products and blogs

Key insights
  • Tiny social-proof widget app (last update 2018, 3 reviews) by Estonian publisher Architechpro OÜ, very small installed base and effectively unmaintained.
  • Publisher's own corporate site is a Shopify-hosted storefront fronted by Cloudflare with HSTS enabled and a minimal CSP, basic web hygiene present.
  • No public security incidents, CVEs, or breach disclosures found for Architechpro or this specific app.
  • Privacy posture is generic Shopify-app boilerplate: no sub-processor register, no retention schedule, no certifications.
  • Functionality requires embedding Meta's Facebook Comments SDK on the storefront, adds a Meta data-flow surface independent of the app itself.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

unknown
Info

Shopify listing page does not expose granular OAuth scopes publicly; for a Facebook comments embed widget, expected scopes are limited to read_themes/write_themes and possibly read_products for placement, but this cannot be confirmed without merchant install flow inspection.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
architechpro.com
TLS grade
unknown
HSTS
Enabled
CSP
Enabled

Publisher site is a Shopify-hosted store on Cloudflare. HSTS present (max-age=7889238, ~91 days). CSP minimal: block-all-mixed-content; frame-ancestors 'none'; upgrade-insecure-requests, no explicit script-src/default-src lockdown. X-Frame-Options DENY, X-Content-Type-Options nosniff, X-XSS-Protection enabled.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR referenced via DPA; no SOC 2 / ISO 27001 / PCI DSS / HIPAA disclosures. No sub-processor register, no retention schedule, no SCCs published.

Privacy policy
Track record

Publisher reputation

Publisher
Architechpro OÜ
Verified Shopify Partner
No
Years active
8
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.