Starship
starship / search / orderify

Audit report

Orderify

WatchReach : broad

by Customer First focus · Orders and shipping · Shopify App Store

Orders and shipping
Risk level
Watch
Executive summary

Let customers edit, cancel and reorder instantly

Key insights

  • Order self-service implies elevated write scopes (orders, customers, refunds), review Shopify install screen carefully before approving.
  • Publisher infrastructure is fronted by Cloudflare + Heroku (Express), a common stack; no HSTS and only minimal CSP on the marketing site.
  • Privacy policy URL is not machine-readable (403), which blocks third-party compliance attestation tooling.
  • No known CVEs or public breaches attributable to Orderify or 'Customer First focus' at audit time.

Top findingsview all

  • High
    Write access to customer orders without explicit scope disclosure
Synthesis

Analysis summary

Let customers edit, cancel and reorder instantly

Key insights
  • Order self-service implies elevated write scopes (orders, customers, refunds), review Shopify install screen carefully before approving.
  • Publisher infrastructure is fronted by Cloudflare + Heroku (Express), a common stack; no HSTS and only minimal CSP on the marketing site.
  • Privacy policy URL is not machine-readable (403), which blocks third-party compliance attestation tooling.
  • No known CVEs or public breaches attributable to Orderify or 'Customer First focus' at audit time.
  • Rating 4.8 with 71 reviews suggests an established but small-mid scale app; no Built for Shopify badge.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

write_orders
High

Required to cancel/edit/refund orders; high blast radius if abused.

read_orders
High

Order history including PII and financial summaries.

write_customers
High

Customer account self-service implies write access to customer records.

read_customers
High

Reads names, emails, addresses, geolocation, IP per listing.

write_script_tags
High

Storefront script injection, supply-chain XSS risk.

write_themes
High

Theme modification capability declared in listing.

read_products
Medium

Used to surface reorder options.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
customerfirstfocus.com
TLS grade
unknown
HSTS
Missing
CSP
Enabled

Only frame-ancestors 'none' set; no default-src/script-src. Cloudflare in front of Heroku Express origin.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL returns HTTP 403 to standard fetches; could not verify GDPR/SOC2/ISO/PCI claims.

Privacy policy
Track record

Publisher reputation

Publisher
Customer First focus
Verified Shopify Partner
No
Years active
0
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.