Starship
starship / search / facturama

Audit report

Facturama

Broad accessReach : moderateSensitive Access

by EXPRESION EN SOFTWARE SAPI DE CV · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

App for electronic invoice management

Key insights

  • Mexican CFDI/e-invoicing app by EXPRESION EN SOFTWARE SAPI DE CV (facturama.mx).
  • Listed since January 2017 with 4.2/5 rating across 31 reviews; no Built for Shopify badge.
  • Privacy policy exists but is a Spanish-only PDF on Azure CDN with limited extractable detail.
  • No public CVEs, breaches, or incidents attributable to Facturama or its publisher.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

App for electronic invoice management

Key insights
  • Mexican CFDI/e-invoicing app by EXPRESION EN SOFTWARE SAPI DE CV (facturama.mx).
  • Listed since January 2017 with 4.2/5 rating across 31 reviews; no Built for Shopify badge.
  • Privacy policy exists but is a Spanish-only PDF on Azure CDN with limited extractable detail.
  • No public CVEs, breaches, or incidents attributable to Facturama or its publisher.
  • Publisher website is reachable over HTTPS/HTTP2 but exposes no security hardening headers.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

Required to read purchase data to generate Mexican CFDI invoices.

read_customers
High

Customer PII (RFC, fiscal address) needed to issue valid CFDI invoices.

read_checkouts
Medium

Self-invoicing at checkout requires checkout context.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
facturama.mx
TLS grade
unknown
HSTS
Missing
CSP
Missing

Root returns HTTP 415 via nginx with no HSTS/CSP/X-Frame-Options observed.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Spanish-language Aviso de Privacidad PDF; no certifications discoverable. Mexican LFPDPPP applies but not publicly mapped to GDPR/SOC2.

Privacy policy
Track record

Publisher reputation

Publisher
EXPRESION EN SOFTWARE SAPI DE CV
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.