Audit report
Osaria Audio Player
Broad accessReach : broadby Osaria · Store design · Shopify App Store
Add player for each product
Key insights
- ◆Small French publisher (Osaria, Nantes) with a niche audio-player app launched Nov 2017; 17 reviews, 4.9 rating.
- ◆Privacy policy is a minimal template hosted on a separate domain (dawtemplatesmaster.com) with weak technical hygiene (PHP 7.1 EOL, no HSTS/CSP).
- ◆Scopes include write_themes and write_script_tags, necessary for the audio player's storefront injection but a supply-chain risk vector.
- ◆No public CVE, breach, or security incident found for Osaria or the Audio Player app.
Top findings
Analysis summary
Add player for each product
- ◆Small French publisher (Osaria, Nantes) with a niche audio-player app launched Nov 2017; 17 reviews, 4.9 rating.
- ◆Privacy policy is a minimal template hosted on a separate domain (dawtemplatesmaster.com) with weak technical hygiene (PHP 7.1 EOL, no HSTS/CSP).
- ◆Scopes include write_themes and write_script_tags, necessary for the audio player's storefront injection but a supply-chain risk vector.
- ◆No public CVE, breach, or security incident found for Osaria or the Audio Player app.
- ◆No AI/LLM usage; functionality is straightforward MP3 hosting and player rendering.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_products | Low | Required to list products for player attachment. |
write_products | Medium | App states product/collection editing; broad write scope on catalog data. |
write_themes | High | Theme write allows arbitrary JS/HTML injection into storefront, high blast radius if compromised. |
write_script_tags | High | Permits injecting persistent scripts into storefront pages, supply-chain risk. |
read_store_information | Low | Standard store metadata for onboarding. |
read_productsRequired to list products for player attachment.
write_productsApp states product/collection editing; broad write scope on catalog data.
write_themesTheme write allows arbitrary JS/HTML injection into storefront, high blast radius if compromised.
write_script_tagsPermits injecting persistent scripts into storefront pages, supply-chain risk.
read_store_informationStandard store metadata for onboarding.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- dawtemplatesmaster.com
- TLS grade
- unknown
- HSTS
- Missing
- CSP
- Missing
HTTP/2 served, but X-Powered-By: PHP/7.1 (EOL) exposed; no HSTS, no CSP headers observed.
Compliance & certifications
Generic privacy policy, no certs, no DPA mention. EU publisher so GDPR applies de facto but no explicit statement.
Privacy policyPublisher reputation
- Publisher
- Osaria
- Verified Shopify Partner
- No
- Years active
- 9
- Other apps
- 0