Shopify-specific context
Shop identity, scopes, session claims, webhook payloads, and Admin API calls are connected across the app.
Review OAuth, webhook verification, App Bridge sessions, Admin API access, and shop isolation, with evidence tied to your code.
if (hmac && !verify(hmac, rawBody))webhooks/verify.ts:9const shop = payload.shop_domainwebhooks/gdpr.ts:21Forged GDPR webhook redacts any shop's data
A Shopify app holds tokens for many shops at once. A missed HMAC check or an unscoped query can hand one merchant's data to another. winfunc follows shop identity through every handler and API call to prove the boundaries hold.
Shop identity, scopes, session claims, webhook payloads, and Admin API calls are connected across the app.
Findings show affected code, prerequisites, and proof, with anything untested clearly labeled.
Patches for state handling, signature checks, authorization, or shop scoping follow your code's conventions.
Evidence supports App Store preparation, customer reviews, and PCI or SOC 2 work.
Continue the evaluation
The agreed scope can include OAuth state and access scopes, App Bridge session tokens, webhook HMAC verification, Admin API authorization, App Proxy endpoints, iframe and CSP behavior, and custom backends that handle merchant or customer data. Findings identify the affected code and supporting evidence; reproduction material and suggested patches depend on the available environment and remain subject to engineering review.
A focused review can investigate selected security requirements and likely review concerns before submission, such as OAuth state handling, access scopes, webhook verification, and tenant boundaries. Shopify's requirements vary by app and can change, so your team should confirm the current official documentation. Your team remains responsible for submission and approval.
Winfunc uses Shopify-specific context such as shop identity, access scopes, App Bridge claims, and webhook payloads to investigate related code paths and business rules. That context can help assess issues such as cross-shop access or missing authorization checks, with assumptions and unresolved questions preserved in the report.
Winfunc can trace how a handler obtains the raw request body, reads the HMAC header, computes the digest, and compares values. When the code and a suitable test environment are available, validation can include scoped reproduction steps. Suggested changes are prepared for your engineers to review and test against the current Shopify guidance.
Winfunc supports source-code investigation, security hypotheses, and repeatable evidence between scoped assessments. It complements rather than replaces a penetration tester's runtime coverage, environmental access, and professional judgment.
Turnaround depends on repository size, agreed scope, framework support, build requirements, and access to a suitable test environment. The expected workflow and deliverables should be agreed during scoping rather than assumed from a fixed timeline.
The same security questions can apply to custom and merchant-specific apps that use access tokens, webhooks, the Admin API, App Bridge, Hydrogen, or checkout extensions. Support depends on the application's stack, repository access, and review boundaries; confirm compatibility during scoping.
Reports can organize scope, methodology, finding evidence, and remediation status for a compliance or customer-review workflow. For applications that touch payment or cardholder-data paths, relevant evidence can be mapped to the questions your assessor identifies. The report does not establish compliance or certification, and the relevant reviewer decides how to assess it.
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.