Audit report
Shopkeeper Branded Gift Cards
Broad accessReach : broadSensitive Accessby Shopkeeper Tools · Sales and conversion optimization · Shopify App Store
Replace the default gift card design with your own design
Key insights
- ◆Long-standing app (live since 2016) with modest review volume (~16 reviews) and 4.5/5 rating.
- ◆Sensitive scope footprint: theme script tags + gift card write, combination that warrants change-monitoring on merchant side.
- ◆Data is transferred to/stored in US and Canada; no EU data residency option declared.
- ◆No named sub-processors beyond Google Analytics; reliance on a single small vendor for a money-adjacent surface (gift cards).
Top findings
Analysis summary
Replace the default gift card design with your own design
- ◆Long-standing app (live since 2016) with modest review volume (~16 reviews) and 4.5/5 rating.
- ◆Sensitive scope footprint: theme script tags + gift card write, combination that warrants change-monitoring on merchant side.
- ◆Data is transferred to/stored in US and Canada; no EU data residency option declared.
- ◆No named sub-processors beyond Google Analytics; reliance on a single small vendor for a money-adjacent surface (gift cards).
- ◆No SOC2/ISO27001/PCI-DSS attestations and no Built for Shopify badge, typical of a small ISV.
- ◆No public breach, CVE, or security incident history found for Shopkeeper Tools.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedOAuth scopes requested
These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.
| Scope | Sensitivity | Why we flag it |
|---|---|---|
read_customers | High | Access to store owner identifying info (name, email, phone, address) declared in listing. |
write_products | High | Product editing capability; can modify catalog content. |
write_gift_cards | Critical | Gift cards are monetary instruments; write access enables creation/modification of stored value. |
write_script_tags | High | Allows injecting JavaScript into storefront pages, supply-chain risk vector. |
write_themes | High | Theme file modification can persist arbitrary frontend code in checkout-adjacent surfaces. |
read_customersAccess to store owner identifying info (name, email, phone, address) declared in listing.
write_productsProduct editing capability; can modify catalog content.
write_gift_cardsGift cards are monetary instruments; write access enables creation/modification of stored value.
write_script_tagsAllows injecting JavaScript into storefront pages, supply-chain risk vector.
write_themesTheme file modification can persist arbitrary frontend code in checkout-adjacent surfaces.
This section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedThis section is available to signed-in users
Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.
Get startedNetwork surface
- Primary domain
- shopkeepertools.com
- TLS grade
- unknown
- HSTS
- Enabled
- CSP
- Missing
HSTS max-age=31536000 present; X-Frame-Options SAMEORIGIN and X-Content-Type-Options nosniff set; no Content-Security-Policy header observed. WordPress-backed marketing site (wp-json endpoints exposed).
Compliance & certifications
Privacy policy acknowledges EU deletion rights but declares no formal certifications. Data transferred to US/Canada.
Privacy policyPublisher reputation
- Publisher
- Shopkeeper Tools
- Verified Shopify Partner
- No
- Years active
- 10
- Other apps
- 0