Starship
starship / search / osaria-audio-player

Audit report

Osaria Audio Player

Broad accessReach : broad

by Osaria · Store design · Shopify App Store

Store design
Risk level
Broad access
Executive summary

Add player for each product

Key insights

  • Small French publisher (Osaria, Nantes) with a niche audio-player app launched Nov 2017; 17 reviews, 4.9 rating.
  • Privacy policy is a minimal template hosted on a separate domain (dawtemplatesmaster.com) with weak technical hygiene (PHP 7.1 EOL, no HSTS/CSP).
  • Scopes include write_themes and write_script_tags, necessary for the audio player's storefront injection but a supply-chain risk vector.
  • No public CVE, breach, or security incident found for Osaria or the Audio Player app.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Add player for each product

Key insights
  • Small French publisher (Osaria, Nantes) with a niche audio-player app launched Nov 2017; 17 reviews, 4.9 rating.
  • Privacy policy is a minimal template hosted on a separate domain (dawtemplatesmaster.com) with weak technical hygiene (PHP 7.1 EOL, no HSTS/CSP).
  • Scopes include write_themes and write_script_tags, necessary for the audio player's storefront injection but a supply-chain risk vector.
  • No public CVE, breach, or security incident found for Osaria or the Audio Player app.
  • No AI/LLM usage; functionality is straightforward MP3 hosting and player rendering.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_products
Low

Required to list products for player attachment.

write_products
Medium

App states product/collection editing; broad write scope on catalog data.

write_themes
High

Theme write allows arbitrary JS/HTML injection into storefront, high blast radius if compromised.

write_script_tags
High

Permits injecting persistent scripts into storefront pages, supply-chain risk.

read_store_information
Low

Standard store metadata for onboarding.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
dawtemplatesmaster.com
TLS grade
unknown
HSTS
Missing
CSP
Missing

HTTP/2 served, but X-Powered-By: PHP/7.1 (EOL) exposed; no HSTS, no CSP headers observed.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Generic privacy policy, no certs, no DPA mention. EU publisher so GDPR applies de facto but no explicit statement.

Privacy policy
Track record

Publisher reputation

Publisher
Osaria
Verified Shopify Partner
No
Years active
9
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.