Starship
starship / search / orders-map

Audit report

Orders Map

Broad accessReach : moderateSensitive Access

by Webyze · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

View Orders on a Map to know who are your customers!

Key insights

  • Simple analytics app that visualizes order locations on a map; low inherent data sensitivity beyond customer addresses already present in the store.
  • Long-standing publisher (Webyze, active since 2015 per listing) with no public breach or CVE history.
  • Privacy policy is a template with placeholders, not a finalized legal document, the largest concrete weakness.
  • Customer geolocation data (derived from order addresses) is processed; this is PII under GDPR and should have clearer retention and sub-processor disclosure.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

View Orders on a Map to know who are your customers!

Key insights
  • Simple analytics app that visualizes order locations on a map; low inherent data sensitivity beyond customer addresses already present in the store.
  • Long-standing publisher (Webyze, active since 2015 per listing) with no public breach or CVE history.
  • Privacy policy is a template with placeholders, not a finalized legal document, the largest concrete weakness.
  • Customer geolocation data (derived from order addresses) is processed; this is PII under GDPR and should have clearer retention and sub-processor disclosure.
  • No declared use of LLMs or AI providers.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

Order data including customer shipping addresses is required to plot orders on a map; inferred from app function, not explicitly declared on listing.

read_customers
Medium

Likely needed to resolve customer location details; inferred from app function.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webyze.com
TLS grade
A
HSTS
Missing
CSP
Missing

Cloudflare-fronted with valid TLS but no HSTS or CSP headers observed on root response.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy exists but contains template placeholders and does not mention any compliance certifications, retention period, sub-processors, or data residency.

Privacy policy
Track record

Publisher reputation

Publisher
Webyze
Verified Shopify Partner
No
Years active
11
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.