Audit report
Orderify
WatchReach : broadby Customer First focus · Orders and shipping · Shopify App Store
Let customers edit, cancel and reorder instantly
Key insights
- ◆Order self-service implies elevated write scopes (orders, customers, refunds), review Shopify install screen carefully before approving.
- ◆Publisher infrastructure is fronted by Cloudflare + Heroku (Express), a common stack; no HSTS and only minimal CSP on the marketing site.
- ◆Privacy policy URL is not machine-readable (403), which blocks third-party compliance attestation tooling.
- ◆No known CVEs or public breaches attributable to Orderify or 'Customer First focus' at audit time.
Top findingsview all
- HighWrite access to customer orders without explicit scope disclosure
Analysis summary
Let customers edit, cancel and reorder instantly
- ◆Order self-service implies elevated write scopes (orders, customers, refunds), review Shopify install screen carefully before approving.
- ◆Publisher infrastructure is fronted by Cloudflare + Heroku (Express), a common stack; no HSTS and only minimal CSP on the marketing site.
- ◆Privacy policy URL is not machine-readable (403), which blocks third-party compliance attestation tooling.
- ◆No known CVEs or public breaches attributable to Orderify or 'Customer First focus' at audit time.
- ◆Rating 4.8 with 71 reviews suggests an established but small-mid scale app; no Built for Shopify badge.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
write_orders | High | Required to cancel/edit/refund orders; high blast radius if abused. |
read_orders | High | Order history including PII and financial summaries. |
write_customers | High | Customer account self-service implies write access to customer records. |
read_customers | High | Reads names, emails, addresses, geolocation, IP per listing. |
write_script_tags | High | Storefront script injection, supply-chain XSS risk. |
write_themes | High | Theme modification capability declared in listing. |
read_products | Medium | Used to surface reorder options. |
write_ordersRequired to cancel/edit/refund orders; high blast radius if abused.
read_ordersOrder history including PII and financial summaries.
write_customersCustomer account self-service implies write access to customer records.
read_customersReads names, emails, addresses, geolocation, IP per listing.
write_script_tagsStorefront script injection, supply-chain XSS risk.
write_themesTheme modification capability declared in listing.
read_productsUsed to surface reorder options.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- customerfirstfocus.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Enabled
Only frame-ancestors 'none' set; no default-src/script-src. Cloudflare in front of Heroku Express origin.
Compliance & certifications
Privacy policy URL returns HTTP 403 to standard fetches; could not verify GDPR/SOC2/ISO/PCI claims.
Privacy policyPublisher reputation
- Publisher
- Customer First focus
- Verified Shopify Partner
- No
- Years active
- 0
- Other apps
- 0