Starship
starship / search / nudgify

Audit report

Nudgify Social Proof, FOMO...

Broad accessReach : broadSensitive Access

by Convertize · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Social Proof, Urgency & Sales pop notifications

Key insights

  • Social proof / FOMO notification app with 4.5 rating and 66 reviews; not Built for Shopify certified
  • Publisher Convertize is UK-based; data hosted in EU/UK per policy
  • Publisher has a public CSRF CVE on their WordPress plugin (CVE-2024-31239) - signals weaker secure-coding hygiene
  • Broad write_customers / write_orders / write_products scopes requested though core feature is display-only social proof

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Social Proof, Urgency & Sales pop notifications

Key insights
  • Social proof / FOMO notification app with 4.5 rating and 66 reviews; not Built for Shopify certified
  • Publisher Convertize is UK-based; data hosted in EU/UK per policy
  • Publisher has a public CSRF CVE on their WordPress plugin (CVE-2024-31239) - signals weaker secure-coding hygiene
  • Broad write_customers / write_orders / write_products scopes requested though core feature is display-only social proof
  • Privacy policy is generic - does not name sub-processors or list compliance certifications

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Customer PII access for social proof notifications

write_customers
High

Write access not needed for read-only notification display

read_orders
High

Needed to display recent purchase notifications

write_orders
Critical

Write access to orders is excessive for a notification display app

read_products
Medium

Needed to associate notifications with products

write_products
High

Write access to products not justified by core feature

read_online_store
Medium

Theme/storefront read for widget injection

write_online_store
High

Storefront write enables theme code modification

read_users
Medium

Staff/contributor visibility - unusual scope for social proof

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
www.nudgify.com
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted WordPress site; missing HSTS and CSP headers; valid TLS

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR-aligned (EU/UK hosted, retention disclosed); no SOC2/ISO27001/PCI certifications stated; no named sub-processors

Privacy policy
Track record

Publisher reputation

Publisher
Convertize
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
  • CVE
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.