Audit report
NoFraud Fraud Prevention
Broad accessReach : broadSensitive Accessby NoFraud Fraud Prevention · Orders and shipping · Shopify App Store
Prevent Fraud Chargebacks, Accept More Orders
Key insights
- ◆Built for Shopify badge present; 4.9 rating across 146 reviews
- ◆Publisher rebranded from NoFraud to Wyllo (Wyllo, LLC)
- ◆Publishes a dedicated security page claiming PCI L1 and SOC 2 Type II
- ◆AWS-hosted with intrusion detection and annual pentesting
Top findings
Analysis summary
Prevent Fraud Chargebacks, Accept More Orders
- ◆Built for Shopify badge present; 4.9 rating across 146 reviews
- ◆Publisher rebranded from NoFraud to Wyllo (Wyllo, LLC)
- ◆Publishes a dedicated security page claiming PCI L1 and SOC 2 Type II
- ◆AWS-hosted with intrusion detection and annual pentesting
- ◆Privacy policy is generic and omits sub-processor list specifics, data residency, and concrete retention windows
- ◆No public CVEs or confirmed breaches surfaced in web search
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to screen orders for fraud signals |
write_orders | High | Needed to cancel/refund fraudulent orders automatically |
read_customers | High | Identity signal scoring relies on customer profile data |
read_checkouts | High | Behavioral analysis at checkout for bot/reseller detection |
read_fulfillments | Medium | Used for return-fraud and post-order abuse analysis |
read_ordersRequired to screen orders for fraud signals
write_ordersNeeded to cancel/refund fraudulent orders automatically
read_customersIdentity signal scoring relies on customer profile data
read_checkoutsBehavioral analysis at checkout for bot/reseller detection
read_fulfillmentsUsed for return-fraud and post-order abuse analysis
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- wyllo.ai
- TLS grade
- A
- HSTS
- Missing
- CSP
- Enabled
Cloudflare-fronted, CSP limited to frame-ancestors; no HSTS header observed
Compliance & certifications
Publisher claims PCI DSS Level 1 and SOC 2 Type II on security page; GDPR/CCPA not explicitly enumerated though privacy policy covers cross-border transfers
Privacy policyPublisher reputation
- Publisher
- NoFraud Fraud Prevention
- Verified Shopify Partner
- Yes
- Years active
- 0
- Other apps
- 0