Audit report
Latest Tweet By Webkul
Broad accessReach : broadby Webkul Software Pvt Ltd · Sales and conversion optimization · Shopify App Store
Display your latest tweets at your Store Front
Key insights
- ◆Narrow-utility tweet widget app from a large India-based publisher (Webkul) that ships hundreds of Shopify and ecommerce apps.
- ◆Requests staff PII (owner name/email/phone/address) plus theme write access, broader than strictly necessary for a static tweet block.
- ◆No 'Built for Shopify' badge, no reviews since 2015 listing, low adoption, limited community signal.
- ◆Publisher portfolio has multiple 2026 CVEs (RCE/SSTI/auth-bypass) in Bagisto and Krayin CRM products, secure-SDLC concern, though not directly in this app.
Top findings
Analysis summary
Display your latest tweets at your Store Front
- ◆Narrow-utility tweet widget app from a large India-based publisher (Webkul) that ships hundreds of Shopify and ecommerce apps.
- ◆Requests staff PII (owner name/email/phone/address) plus theme write access, broader than strictly necessary for a static tweet block.
- ◆No 'Built for Shopify' badge, no reviews since 2015 listing, low adoption, limited community signal.
- ◆Publisher portfolio has multiple 2026 CVEs (RCE/SSTI/auth-bypass) in Bagisto and Krayin CRM products, secure-SDLC concern, though not directly in this app.
- ◆Privacy policy is generic, omits data residency, retention timelines, sub-processors, and any compliance certification.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_staff_information | Medium | Access to store owner name, email, phone, and physical address is PII; not needed to render tweets. |
write_script_tags | High | Script tags inject JavaScript into the storefront on every page load; if the publisher is compromised, this becomes a Magecart-style attack surface. |
write_themes | High | Theme editing allows persistent modification of storefront templates; high blast radius if abused. |
read_staff_informationAccess to store owner name, email, phone, and physical address is PII; not needed to render tweets.
write_script_tagsScript tags inject JavaScript into the storefront on every page load; if the publisher is compromised, this becomes a Magecart-style attack surface.
write_themesTheme editing allows persistent modification of storefront templates; high blast radius if abused.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- webkul.com
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Missing
Cloudflare-fronted WordPress site. HSTS present (max-age 2,592,000 ~ 30 days, includeSubDomains, no preload). Only `Content-Security-Policy: upgrade-insecure-requests` set, which is not a real CSP. X-Content-Type-Options, X-Frame-Options=SAMEORIGIN, X-XSS-Protection present.
Compliance & certifications
No explicit certifications referenced in privacy policy; no GDPR DPA link, no SOC2/ISO27001/PCI claims. Policy mentions third-party processors generically without naming them.
Privacy policyPublisher reputation
- Publisher
- Webkul Software Pvt Ltd
- Verified Shopify Partner
- No
- Years active
- 11
- Other apps
- 0