Audit report
Nudgify Social Proof, FOMO...
Broad accessReach : broadSensitive Accessby Convertize · Sales and conversion optimization · Shopify App Store
Social Proof, Urgency & Sales pop notifications
Key insights
- ◆Social proof / FOMO notification app with 4.5 rating and 66 reviews; not Built for Shopify certified
- ◆Publisher Convertize is UK-based; data hosted in EU/UK per policy
- ◆Publisher has a public CSRF CVE on their WordPress plugin (CVE-2024-31239) - signals weaker secure-coding hygiene
- ◆Broad write_customers / write_orders / write_products scopes requested though core feature is display-only social proof
Top findings
Analysis summary
Social Proof, Urgency & Sales pop notifications
- ◆Social proof / FOMO notification app with 4.5 rating and 66 reviews; not Built for Shopify certified
- ◆Publisher Convertize is UK-based; data hosted in EU/UK per policy
- ◆Publisher has a public CSRF CVE on their WordPress plugin (CVE-2024-31239) - signals weaker secure-coding hygiene
- ◆Broad write_customers / write_orders / write_products scopes requested though core feature is display-only social proof
- ◆Privacy policy is generic - does not name sub-processors or list compliance certifications
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Customer PII access for social proof notifications |
write_customers | High | Write access not needed for read-only notification display |
read_orders | High | Needed to display recent purchase notifications |
write_orders | Critical | Write access to orders is excessive for a notification display app |
read_products | Medium | Needed to associate notifications with products |
write_products | High | Write access to products not justified by core feature |
read_online_store | Medium | Theme/storefront read for widget injection |
write_online_store | High | Storefront write enables theme code modification |
read_users | Medium | Staff/contributor visibility - unusual scope for social proof |
read_customersCustomer PII access for social proof notifications
write_customersWrite access not needed for read-only notification display
read_ordersNeeded to display recent purchase notifications
write_ordersWrite access to orders is excessive for a notification display app
read_productsNeeded to associate notifications with products
write_productsWrite access to products not justified by core feature
read_online_storeTheme/storefront read for widget injection
write_online_storeStorefront write enables theme code modification
read_usersStaff/contributor visibility - unusual scope for social proof
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- www.nudgify.com
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
Cloudflare-fronted WordPress site; missing HSTS and CSP headers; valid TLS
Compliance & certifications
GDPR-aligned (EU/UK hosted, retention disclosed); no SOC2/ISO27001/PCI certifications stated; no named sub-processors
Privacy policyPublisher reputation
- Publisher
- Convertize
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0
- ●CVE