Starship
starship / search / news-ticker-1

Audit report

News Ticker

Broad accessReach : broadSensitive Access

by Appsonrent · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Frequently posting news on your website dynamic way

Key insights

  • Publisher of record: Appsonrent (appsonrent.com reachable over HTTPS, HSTS preload enabled, CSP frame-ancestors set).
  • App store listing returns 3.3/5 with ~39 reviews and is not Built-for-Shopify certified.
  • Privacy policy linked from the listing is hosted on autods.com (not appsonrent.com) - third-party policy or rebranding inconsistency.
  • No public CVEs, breaches, or incidents found for Appsonrent or this app via web search.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Frequently posting news on your website dynamic way

Key insights
  • Publisher of record: Appsonrent (appsonrent.com reachable over HTTPS, HSTS preload enabled, CSP frame-ancestors set).
  • App store listing returns 3.3/5 with ~39 reviews and is not Built-for-Shopify certified.
  • Privacy policy linked from the listing is hosted on autods.com (not appsonrent.com) - third-party policy or rebranding inconsistency.
  • No public CVEs, breaches, or incidents found for Appsonrent or this app via web search.
  • Declared data access spans customers, orders, products, store analytics, theme, navigation - broader than a news ticker utility typically requires.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII access; not needed for a news ticker.

read_orders
High

Order data access not justified by a ticker/page-enhancement use case.

read_products
Medium

Could support product-related ticker content.

read_analytics
Medium

Store analytics; sensitive business metrics.

read_themes
Medium

Required to inject ticker into theme.

write_themes
High

Likely needed for ticker injection but write access to theme is sensitive.

read_locations
Low

Location data access; limited risk.

read_online_store_navigation
Low

Navigation read; low sensitivity.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
appsonrent.com
TLS grade
A
HSTS
Enabled
CSP
Enabled

appsonrent.com serves HTTPS via Cloudflare with HSTS (max-age=63072000; preload) and CSP frame-ancestors 'self'; X-Content-Type-Options nosniff present. WordPress backend detected (wp-json link header).

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy linked from listing is on autods.com (third-party). GDPR and CCPA mentioned; SOC2/ISO27001/PCI/HIPAA not mentioned. Data retention period not specified.

Privacy policy
Track record

Publisher reputation

Publisher
Appsonrent
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.