Audit report
Header + Announcement Bar
WatchReach : limitedby POWr.io · Store design · Shopify App Store
FREE promotions, discount, shipping, announcement header bar!
Key insights
- ◆App listing page resolves to 'POWR Email Signup' (4.7/5, 9 reviews) under same notification-bar URL slug, likely consolidated listing under POWr.io publisher
- ◆Publisher POWr.io operates 60+ Shopify apps, indicating large multi-app surface area
- ◆Confirmed 2019 backup exposure incident; no public CVEs assigned
- ◆US-hosted data; no AI/LLM usage disclosed in privacy policy
Top findingsview all
- HighConfirmed 2019 publisher data breach
Analysis summary
FREE promotions, discount, shipping, announcement header bar!
- ◆App listing page resolves to 'POWR Email Signup' (4.7/5, 9 reviews) under same notification-bar URL slug, likely consolidated listing under POWr.io publisher
- ◆Publisher POWr.io operates 60+ Shopify apps, indicating large multi-app surface area
- ◆Confirmed 2019 backup exposure incident; no public CVEs assigned
- ◆US-hosted data; no AI/LLM usage disclosed in privacy policy
- ◆Cloudflare-fronted publisher domain with valid TLS
- ◆Privacy policy explicitly names Google and Facebook as third-party integration recipients
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
undisclosed_on_listing | Info | App listing page did not surface a machine-parseable scope block; scopes only revealed at install. Notification bar / email signup apps typically request write_themes or script_tags plus minimal read scopes. |
undisclosed_on_listingApp listing page did not surface a machine-parseable scope block; scopes only revealed at install. Notification bar / email signup apps typically request write_themes or script_tags plus minimal read scopes.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- powr.io
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS valid via Cloudflare; HSTS and CSP headers absent on root response. X-Content-Type-Options, X-XSS-Protection, Referrer-Policy present.
Compliance & certifications
GDPR/CCPA-style data subject rights described; no formal third-party security certifications mentioned. ~12-month residual backup retention disclosed.
Privacy policyPublisher reputation
- Publisher
- POWr.io
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 60
- ●Dec 2019 backup data exposure (form CSV/XLS exports and uploaded files), https://help.powr.io/hc/en-us/articles/360041404013-Dec-2019-Security-Breach