Starship
starship / search / notification-bar

Audit report

Header + Announcement Bar

WatchReach : limited

by POWr.io · Store design · Shopify App Store

Store design
Risk level
Watch
Executive summary

FREE promotions, discount, shipping, announcement header bar!

Key insights

  • App listing page resolves to 'POWR Email Signup' (4.7/5, 9 reviews) under same notification-bar URL slug, likely consolidated listing under POWr.io publisher
  • Publisher POWr.io operates 60+ Shopify apps, indicating large multi-app surface area
  • Confirmed 2019 backup exposure incident; no public CVEs assigned
  • US-hosted data; no AI/LLM usage disclosed in privacy policy

Top findingsview all

  • High
    Confirmed 2019 publisher data breach
Synthesis

Analysis summary

FREE promotions, discount, shipping, announcement header bar!

Key insights
  • App listing page resolves to 'POWR Email Signup' (4.7/5, 9 reviews) under same notification-bar URL slug, likely consolidated listing under POWr.io publisher
  • Publisher POWr.io operates 60+ Shopify apps, indicating large multi-app surface area
  • Confirmed 2019 backup exposure incident; no public CVEs assigned
  • US-hosted data; no AI/LLM usage disclosed in privacy policy
  • Cloudflare-fronted publisher domain with valid TLS
  • Privacy policy explicitly names Google and Facebook as third-party integration recipients

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

undisclosed_on_listing
Info

App listing page did not surface a machine-parseable scope block; scopes only revealed at install. Notification bar / email signup apps typically request write_themes or script_tags plus minimal read scopes.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
powr.io
TLS grade
A
HSTS
Missing
CSP
Missing

HTTPS valid via Cloudflare; HSTS and CSP headers absent on root response. X-Content-Type-Options, X-XSS-Protection, Referrer-Policy present.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR/CCPA-style data subject rights described; no formal third-party security certifications mentioned. ~12-month residual backup retention disclosed.

Privacy policy
Track record

Publisher reputation

Publisher
POWr.io
Verified Shopify Partner
No
Years active
0
Other apps
60
Past incidents
  • Dec 2019 backup data exposure (form CSV/XLS exports and uploaded files), https://help.powr.io/hc/en-us/articles/360041404013-Dec-2019-Security-Breach
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.