Starship
starship / search / nofraud-chargeback-prevention-and-protection

Audit report

NoFraud Fraud Prevention

Broad accessReach : broadSensitive Access

by NoFraud Fraud Prevention · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Broad access
Executive summary

Prevent Fraud Chargebacks, Accept More Orders

Key insights

  • Built for Shopify badge present; 4.9 rating across 146 reviews
  • Publisher rebranded from NoFraud to Wyllo (Wyllo, LLC)
  • Publishes a dedicated security page claiming PCI L1 and SOC 2 Type II
  • AWS-hosted with intrusion detection and annual pentesting

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Prevent Fraud Chargebacks, Accept More Orders

Key insights
  • Built for Shopify badge present; 4.9 rating across 146 reviews
  • Publisher rebranded from NoFraud to Wyllo (Wyllo, LLC)
  • Publishes a dedicated security page claiming PCI L1 and SOC 2 Type II
  • AWS-hosted with intrusion detection and annual pentesting
  • Privacy policy is generic and omits sub-processor list specifics, data residency, and concrete retention windows
  • No public CVEs or confirmed breaches surfaced in web search

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
High

Required to screen orders for fraud signals

write_orders
High

Needed to cancel/refund fraudulent orders automatically

read_customers
High

Identity signal scoring relies on customer profile data

read_checkouts
High

Behavioral analysis at checkout for bot/reseller detection

read_fulfillments
Medium

Used for return-fraud and post-order abuse analysis

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
wyllo.ai
TLS grade
A
HSTS
Missing
CSP
Enabled

Cloudflare-fronted, CSP limited to frame-ancestors; no HSTS header observed

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Pass
ISO 27001 Fail
PCI DSS Pass

Publisher claims PCI DSS Level 1 and SOC 2 Type II on security page; GDPR/CCPA not explicitly enumerated though privacy policy covers cross-border transfers

Privacy policy
Track record

Publisher reputation

Publisher
NoFraud Fraud Prevention
Verified Shopify Partner
Yes
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.