Audit report
Offective
Broad accessReach : moderateSensitive Accessby Webwinkelfacturen · Finances · Shopify App Store
Your webshop orders effortlessly in Offective
Key insights
- ◆Offective is a Dutch accounting integration that ships Shopify orders daily to Silvasoft administration software (publisher Webwinkelfacturen).
- ◆Listing shows 0 reviews and no Built for Shopify badge, indicating very low adoption / unverified maturity.
- ◆Publisher website lacks HSTS and CSP headers; TLS itself terminates cleanly (nginx, HTTP/2).
- ◆No CVEs, breaches or security incidents found for Webwinkelfacturen or Offective in public sources.
Top findings
Analysis summary
Your webshop orders effortlessly in Offective
- ◆Offective is a Dutch accounting integration that ships Shopify orders daily to Silvasoft administration software (publisher Webwinkelfacturen).
- ◆Listing shows 0 reviews and no Built for Shopify badge, indicating very low adoption / unverified maturity.
- ◆Publisher website lacks HSTS and CSP headers; TLS itself terminates cleanly (nginx, HTTP/2).
- ◆No CVEs, breaches or security incidents found for Webwinkelfacturen or Offective in public sources.
- ◆Privacy disclosure is a thin AVG/GDPR FAQ page; no enumerated sub-processors, retention or hosting region.
- ◆No evidence the app uses any LLM/AI processing of merchant data.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_orders | High | Required to export daily orders into Silvasoft; inferred from product description, not declared on listing. |
read_customers | High | Order details sync to accounting typically requires customer billing identity (PII). |
read_products | Medium | Needed to map SKUs and line items in accounting entries. |
read_transactions | High | Transaction transfer feature implies read access to financial transactions. |
read_ordersRequired to export daily orders into Silvasoft; inferred from product description, not declared on listing.
read_customersOrder details sync to accounting typically requires customer billing identity (PII).
read_productsNeeded to map SKUs and line items in accounting entries.
read_transactionsTransaction transfer feature implies read access to financial transactions.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- webwinkelfacturen.nl
- TLS grade
- A
- HSTS
- Missing
- CSP
- Missing
HTTPS terminates cleanly with nginx/HTTP2 but no Strict-Transport-Security or Content-Security-Policy headers observed; PHP session cookie returned without visible Secure/HttpOnly attributes.
Compliance & certifications
Publisher is EU/NL based and references AVG (Dutch GDPR). No SOC2, ISO27001 or PCI DSS attestations found. Privacy content is sparse and Dutch-only.
Privacy policyPublisher reputation
- Publisher
- Webwinkelfacturen
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0