Starship
starship / search / shopify-latest-tweet

Audit report

Latest Tweet By Webkul

Broad accessReach : broad

by Webkul Software Pvt Ltd · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Display your latest tweets at your Store Front

Key insights

  • Narrow-utility tweet widget app from a large India-based publisher (Webkul) that ships hundreds of Shopify and ecommerce apps.
  • Requests staff PII (owner name/email/phone/address) plus theme write access, broader than strictly necessary for a static tweet block.
  • No 'Built for Shopify' badge, no reviews since 2015 listing, low adoption, limited community signal.
  • Publisher portfolio has multiple 2026 CVEs (RCE/SSTI/auth-bypass) in Bagisto and Krayin CRM products, secure-SDLC concern, though not directly in this app.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Display your latest tweets at your Store Front

Key insights
  • Narrow-utility tweet widget app from a large India-based publisher (Webkul) that ships hundreds of Shopify and ecommerce apps.
  • Requests staff PII (owner name/email/phone/address) plus theme write access, broader than strictly necessary for a static tweet block.
  • No 'Built for Shopify' badge, no reviews since 2015 listing, low adoption, limited community signal.
  • Publisher portfolio has multiple 2026 CVEs (RCE/SSTI/auth-bypass) in Bagisto and Krayin CRM products, secure-SDLC concern, though not directly in this app.
  • Privacy policy is generic, omits data residency, retention timelines, sub-processors, and any compliance certification.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_staff_information
Medium

Access to store owner name, email, phone, and physical address is PII; not needed to render tweets.

write_script_tags
High

Script tags inject JavaScript into the storefront on every page load; if the publisher is compromised, this becomes a Magecart-style attack surface.

write_themes
High

Theme editing allows persistent modification of storefront templates; high blast radius if abused.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
webkul.com
TLS grade
unknown
HSTS
Enabled
CSP
Missing

Cloudflare-fronted WordPress site. HSTS present (max-age 2,592,000 ~ 30 days, includeSubDomains, no preload). Only `Content-Security-Policy: upgrade-insecure-requests` set, which is not a real CSP. X-Content-Type-Options, X-Frame-Options=SAMEORIGIN, X-XSS-Protection present.

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

No explicit certifications referenced in privacy policy; no GDPR DPA link, no SOC2/ISO27001/PCI claims. Policy mentions third-party processors generically without naming them.

Privacy policy
Track record

Publisher reputation

Publisher
Webkul Software Pvt Ltd
Verified Shopify Partner
No
Years active
11
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.