Audit report
OrderLogic ‑ Min & Max Limits
Broad accessReach : broadby Oiizes · Store design · Shopify App Store
Simple min and max order limits
Key insights
- ◆Low-surface-area utility app: enforces min/max cart limits, does not appear to require write access to customer PII, payments, or orders beyond product/cart metadata.
- ◆Publisher policy site (orderlogicapp.com) is misconfigured at TLS layer (Cloudflare 525), blocking privacy policy retrieval, moderate transparency issue.
- ◆No public breach history, no CVEs, no incident reports tied to Oiizes or OrderLogic.
- ◆Not a 'Built for Shopify' app; 4.1/5 rating with 48 reviews suggests modest install base.
Top findingsview all
- HighPublisher domain returns HTTP 525 (TLS handshake failure)
Analysis summary
Simple min and max order limits
- ◆Low-surface-area utility app: enforces min/max cart limits, does not appear to require write access to customer PII, payments, or orders beyond product/cart metadata.
- ◆Publisher policy site (orderlogicapp.com) is misconfigured at TLS layer (Cloudflare 525), blocking privacy policy retrieval, moderate transparency issue.
- ◆No public breach history, no CVEs, no incident reports tied to Oiizes or OrderLogic.
- ◆Not a 'Built for Shopify' app; 4.1/5 rating with 48 reviews suggests modest install base.
- ◆Default risk posture: medium, limited declared scopes plus inaccessible policy.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to enumerate products for min/max rule configuration. |
write_script_tags | Medium | Typical for cart-limit apps to inject storefront JS; broad write capability that could be abused if compromised. |
read_themes | Low | Likely needed to detect theme compatibility for cart enforcement. |
read_productsRequired to enumerate products for min/max rule configuration.
write_script_tagsTypical for cart-limit apps to inject storefront JS; broad write capability that could be abused if compromised.
read_themesLikely needed to detect theme compatibility for cart enforcement.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- orderlogicapp.com
- TLS grade
- F
- HSTS
- Missing
- CSP
- Missing
Cloudflare returned HTTP 525 (SSL handshake failed between Cloudflare and origin). No HSTS or CSP headers observed. Indicates broken origin TLS configuration.
Compliance & certifications
Privacy policy URL declared but unreachable at audit time (HTTP 525). No public compliance attestations found.
Privacy policyPublisher reputation
- Publisher
- Oiizes
- Verified Shopify Partner
- No
- Years active
- 10
- Other apps
- 0