Starship
starship / search / stamped-reviews

Audit report

Stamped Product Reviews & UGC

Broad accessReach : broadSensitive Access

by Stamped.io · Reviews · Shopify App Store

Reviewsv8.3.2
Risk level
Broad access
Executive summary

Stamped est une suite reviews + loyalty + NPS. Risque Medium dû à l'étendue de la suite et à un scope qui en découle, mitigé par une posture conformité correcte.

Key insights

  • Suite reviews + UGC + NPS + loyalty.
  • Risque Medium, surface élargie quand toute la suite est activée.
  • Éditeur Singapour, GDPR + CCPA.
  • Pas de badge Built for Shopify.

Top findings

No critical or high findings detected.
Synthesis

Analysis summary

Stamped est une suite reviews + loyalty + NPS. Risque Medium dû à l'étendue de la suite et à un scope qui en découle, mitigé par une posture conformité correcte.

Key insights
  • Suite reviews + UGC + NPS + loyalty.
  • Risque Medium, surface élargie quand toute la suite est activée.
  • Éditeur Singapour, GDPR + CCPA.
  • Pas de badge Built for Shopify.
  • Note 4,6 sur 6 210 avis.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Permissions

OAuth scopes requested

These are the access permissions this app asks for during install. The sensitivity column reflects PII exposure and merchant impact.

read_orders
Medium

Trigger demandes d'avis.

read_customers
High

Loyalty + NPS.

write_customers
High

Tags VIP loyalty.

read_products
Low

Mapping.

write_themes
High

Widgets storefront.

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started

This section is available to signed-in users

Sign up free to unlock findings, data flow and theme code analysis for every Shopify app.

Get started
Attack surface

Network surface

Primary domain
stamped.io
TLS grade
A
HSTS
Enabled
CSP
Missing

TLS moderne, HSTS, pas de CSP stricte.

Posture

Compliance & certifications

GDPR webhooks Pass
SOC 2 Type II Fail
ISO 27001 Fail
PCI DSS Fail

GDPR + CCPA. DPA sur demande.

Privacy policy
Track record

Publisher reputation

Publisher
Stamped.io
Verified Shopify Partner
Yes
Years active
10
Other apps
1
Past incidents
No past incidents on record.
LLM exposure

AI / LLM usage

LLM providers
OpenAI
Data shared with providers

Texte des avis pour résumés et analyse de sentiment.

Retention policy

Standard API OpenAI.