Starship
starship / search / shopkeeper-branded-gift-card

Audit report

Shopkeeper Branded Gift Cards

Broad accessReach : broadSensitive Access

by Shopkeeper Tools · Sales and conversion optimization · Shopify App Store

Sales and conversion optimization
Risk level
Broad access
Executive summary

Replace the default gift card design with your own design

Key insights

  • Long-standing app (live since 2016) with modest review volume (~16 reviews) and 4.5/5 rating.
  • Sensitive scope footprint: theme script tags + gift card write, combination that warrants change-monitoring on merchant side.
  • Data is transferred to/stored in US and Canada; no EU data residency option declared.
  • No named sub-processors beyond Google Analytics; reliance on a single small vendor for a money-adjacent surface (gift cards).

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Replace the default gift card design with your own design

Key insights
  • Long-standing app (live since 2016) with modest review volume (~16 reviews) and 4.5/5 rating.
  • Sensitive scope footprint: theme script tags + gift card write, combination that warrants change-monitoring on merchant side.
  • Data is transferred to/stored in US and Canada; no EU data residency option declared.
  • No named sub-processors beyond Google Analytics; reliance on a single small vendor for a money-adjacent surface (gift cards).
  • No SOC2/ISO27001/PCI-DSS attestations and no Built for Shopify badge, typical of a small ISV.
  • No public breach, CVE, or security incident history found for Shopkeeper Tools.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_customers
High

Access to store owner identifying info (name, email, phone, address) declared in listing.

write_products
High

Product editing capability; can modify catalog content.

write_gift_cards
Critical

Gift cards are monetary instruments; write access enables creation/modification of stored value.

write_script_tags
High

Allows injecting JavaScript into storefront pages, supply-chain risk vector.

write_themes
High

Theme file modification can persist arbitrary frontend code in checkout-adjacent surfaces.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
shopkeepertools.com
TLS grade
unknown
HSTS
Enabled
CSP
Missing

HSTS max-age=31536000 present; X-Frame-Options SAMEORIGIN and X-Content-Type-Options nosniff set; no Content-Security-Policy header observed. WordPress-backed marketing site (wp-json endpoints exposed).

Posture

Compliance & certifications

GDPR webhooks Fail
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

Privacy policy acknowledges EU deletion rights but declares no formal certifications. Data transferred to US/Canada.

Privacy policy
Track record

Publisher reputation

Publisher
Shopkeeper Tools
Verified Shopify Partner
No
Years active
10
Other apps
0
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

No LLM usage detected. This app does not appear to forward any customer or merchant data to large-language-model providers.