Starship
starship / search / orderlogic

Audit report

OrderLogic ‑ Min & Max Limits

Broad accessReach : broad

by Oiizes · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Simple min and max order limits

Key insights

  • Low-surface-area utility app: enforces min/max cart limits, does not appear to require write access to customer PII, payments, or orders beyond product/cart metadata.
  • Publisher policy site (orderlogicapp.com) is misconfigured at TLS layer (Cloudflare 525), blocking privacy policy retrieval, moderate transparency issue.
  • No public breach history, no CVEs, no incident reports tied to Oiizes or OrderLogic.
  • Not a 'Built for Shopify' app; 4.1/5 rating with 48 reviews suggests modest install base.

Top findingsview all

  • High
    Publisher domain returns HTTP 525 (TLS handshake failure)
Synthesis

Analysis summary

Simple min and max order limits

Key insights
  • Low-surface-area utility app: enforces min/max cart limits, does not appear to require write access to customer PII, payments, or orders beyond product/cart metadata.
  • Publisher policy site (orderlogicapp.com) is misconfigured at TLS layer (Cloudflare 525), blocking privacy policy retrieval, moderate transparency issue.
  • No public breach history, no CVEs, no incident reports tied to Oiizes or OrderLogic.
  • Not a 'Built for Shopify' app; 4.1/5 rating with 48 reviews suggests modest install base.
  • Default risk posture: medium, limited declared scopes plus inaccessible policy.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to enumerate products for min/max rule configuration.

write_script_tags
Medium

Typical for cart-limit apps to inject storefront JS; broad write capability that could be abused if compromised.

read_themes
Low

Likely needed to detect theme compatibility for cart enforcement.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
orderlogicapp.com
TLS grade
F
HSTS
Missing
CSP
Missing

Cloudflare returned HTTP 525 (SSL handshake failed between Cloudflare and origin). No HSTS or CSP headers observed. Indicates broken origin TLS configuration.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy URL declared but unreachable at audit time (HTTP 525). No public compliance attestations found.

Privacy policy
Track record

Publisher reputation

Publisher
Oiizes
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.