Skip to content
winfunc
Industry · Shopify apps

Secure the boundaries in your Shopify app.

Review OAuth, webhook verification, App Bridge sessions, Admin API access, and shop isolation, with evidence tied to your code.

What's included
  1. acme
  2. /shopify-app
  3. /Vulnerabilities
  4. /WF-0311
High
Sourcewebhooks/gdpr.ts:14
req.body.shop_domain
1
HMAC is verified only when the header is presentif (hmac && !verify(hmac, rawBody))webhooks/verify.ts:9
2
Shop taken from the unverified payloadconst shop = payload.shop_domainwebhooks/gdpr.ts:21
Sinkservices/shops.ts:88
await shops.redact(shop)

Forged GDPR webhook redacts any shop's data

HighCVSS 8.2
Weakness
CWE-345 · Missing authenticity check
Confidence
97
Validation
Exploitable
Proof
Unsigned request redacted a test shop
Finding · source to sinkIllustrative data
The problem

Every merchant trusts you with their store.

A Shopify app holds tokens for many shops at once. A missed HMAC check or an unscoped query can hand one merchant's data to another. winfunc follows shop identity through every handler and API call to prove the boundaries hold.

Included

What winfunc covers.

  • OAuth authorization-code flow, state, and scope review
  • Webhook HMAC verification across handlers
  • App Bridge session-token and JWT validation
  • Admin API authorization and shop scoping
  • App Proxy, iframe, and CSP review
  • Customer and merchant data-flow investigation
  • GDPR webhook handling review
  • Suggested patches opened as pull requests
Outcomes

What your team walks away with.

01

Shopify-specific context

Shop identity, scopes, session claims, webhook payloads, and Admin API calls are connected across the app.

02

Evidence with limits

Findings show affected code, prerequisites, and proof, with anything untested clearly labeled.

03

Reviewable fixes

Patches for state handling, signature checks, authorization, or shop scoping follow your code's conventions.

04

Review-ready

Evidence supports App Store preparation, customer reviews, and PCI or SOC 2 work.

FAQ

Common questions.

01What can a Shopify app security review include?

The agreed scope can include OAuth state and access scopes, App Bridge session tokens, webhook HMAC verification, Admin API authorization, App Proxy endpoints, iframe and CSP behavior, and custom backends that handle merchant or customer data. Findings identify the affected code and supporting evidence; reproduction material and suggested patches depend on the available environment and remain subject to engineering review.

02Can this help with Shopify App Store preparation?

A focused review can investigate selected security requirements and likely review concerns before submission, such as OAuth state handling, access scopes, webhook verification, and tenant boundaries. Shopify's requirements vary by app and can change, so your team should confirm the current official documentation. Your team remains responsible for submission and approval.

03How does Winfunc complement a SAST scanner?

Winfunc uses Shopify-specific context such as shop identity, access scopes, App Bridge claims, and webhook payloads to investigate related code paths and business rules. That context can help assess issues such as cross-shop access or missing authorization checks, with assumptions and unresolved questions preserved in the report.

04Can Winfunc investigate webhook HMAC validation?

Winfunc can trace how a handler obtains the raw request body, reads the HMAC header, computes the digest, and compares values. When the code and a suitable test environment are available, validation can include scoped reproduction steps. Suggested changes are prepared for your engineers to review and test against the current Shopify guidance.

05How does this relate to a manual penetration test?

Winfunc supports source-code investigation, security hypotheses, and repeatable evidence between scoped assessments. It complements rather than replaces a penetration tester's runtime coverage, environmental access, and professional judgment.

06How long does an initial review take?

Turnaround depends on repository size, agreed scope, framework support, build requirements, and access to a suitable test environment. The expected workflow and deliverables should be agreed during scoping rather than assumed from a fixed timeline.

07Can custom or merchant-specific Shopify apps be reviewed?

The same security questions can apply to custom and merchant-specific apps that use access tokens, webhooks, the Admin API, App Bridge, Hydrogen, or checkout extensions. Support depends on the application's stack, repository access, and review boundaries; confirm compatibility during scoping.

08Can the findings support SOC 2 or PCI DSS work?

Reports can organize scope, methodology, finding evidence, and remediation status for a compliance or customer-review workflow. For applications that touch payment or cardholder-data paths, relevant evidence can be mapped to the questions your assessor identifies. The report does not establish compliance or certification, and the relevant reviewer decides how to assess it.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.